Close Menu
  • Home
  • Finance News
  • Personal Finance
  • Investing
  • Cards
    • Credit Cards
    • Debit
  • Insurance
  • Loans
  • Mortgage
  • More
    • Save Money
    • Banking
    • Taxes
    • Crime
What's Hot

What a federal trade court block on Trump tariffs means for consumers

June 1, 2025

Stocks making the biggest moves premarket: ULTA, ABNB, GAP, AEO

June 1, 2025

The Road to the “Seven-Figure Club”

May 31, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Smart SpendingSmart Spending
Subscribe
  • Home
  • Finance News
  • Personal Finance
  • Investing
  • Cards
    • Credit Cards
    • Debit
  • Insurance
  • Loans
  • Mortgage
  • More
    • Save Money
    • Banking
    • Taxes
    • Crime
Smart SpendingSmart Spending
Home»Banking»OCC unsure if breached bank data was sold on dark web after hack
Banking

OCC unsure if breached bank data was sold on dark web after hack

April 16, 2025No Comments4 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
OCC unsure if breached bank data was sold on dark web after hack
Share
Facebook Twitter LinkedIn Pinterest Email

Over a month after the Office of the Comptroller of the Currency discovered it was hacked by illicit actors the agency said it is still working to understand what specific sensitive bank data was compromised and whether any of it has been publicly or criminally disseminated, according to a letter the agency sent Tuesday to banks it supervises.

“The OCC and one of its contractors are currently working to review the content of all compromised email communications and attachments, including determining whether any of the compromised information has been found on the dark web,” Acting Comptroller Rodney Hood said in the letter. “Information that was accessed includes financial supervision information provided by OCC-supervised institutions and non-public OCC information. Efforts to determine if any bank customer information was compromised are ongoing.”

Last week, the OCC — which oversees nationally chartered firms, some of the largest in the world — notified Congress of a major cybersecurity incident involving its internal email system, in which a high-level user account with administrative privileges over the OCC’s email system was breached, revealing highly sensitive information about one of the banks regulated by the agency.

Following the OCC’s disclosure of the breach, banks have reportedly been concerned that continued data exchange could expose their own networks to risk.

JPMorgan Chase and BNY Mellon reportedly paused electronic information sharing with the OCC after discovering that hackers broke into an OCC administrator’s account. The breach allowed hackers to monitor emails from over a hundred officials for over a year according to Bloomberg, siphoning off over 150,000 messages containing sensitive financial data. 

See also  Bank of America (BAC) earnings Q3 2024

According to Tuesday’s letter, the breach was first flagged by Microsoft’s Microsoft Global Hunting Oversight and Strategic Triage team in February, after the vendor detected unusual access patterns between a service account in Microsoft’s Azure office automation environment and OCC user mailboxes, which the Microsoft team tracked back to a virtual private network service. Virtual private networks, also known as VPNs, are a tool that allows users to browse anonymously by routing their internet activity through an encrypted server, making it harder to trace their location or identity.

OCC said in its Tuesday correspondence it confirmed the activity was unauthorized the next day and began its response: disabling the account, initiating third-party forensic reviews by Mandiant and CrowdStrike and reporting the incident to the Cybersecurity and Infrastructure Security Agency. Weeks later, the OCC determined the incident qualified as a major breach and informed Congress of the hack the next day. 

Despite securing the compromised account and resetting all credentials tied to its Microsoft environment, the OCC acknowledged that sensitive bank data — including non-public supervisory information from regulated financial institutions — had been accessed. The OCC partnered with leading cybersecurity firms, which OCC says helped to rule out the possibility of further intrusions or lateral movement within its data systems.

The OCC says going forward it will share technical details of the breach through the Treasury’s Treasury’s Office of Cybersecurity and Critical Infrastructure, the Project Fortress Threat Feed and the industry consortium the Financial Services Information Sharing and Analysis Center. The agency is also bringing in outside counsel to review its IT security policies and procedures and says it will act on all resulting recommendations.

See also  Here Are The 25 Most Expensive ZIP Codes In Ohio, Per Zillow Data

The letter also noted the OCC will hold regular briefings with supervised institutions to share updates on the breach and ongoing remediation. The agency says it also will notify any institution whose data was specifically accessed.

“We recognize regulated institutions may have questions about their provision of requested supervisory information for OCC examinations,” Hood wrote. “OCC examiners are available to work with individual institutions to answer their questions and ensure the secure exchange of required supervisory information.”

Source link

Bank breached dark data Hack OCC sold unsure web
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
Previous ArticleNew Small Currency Transaction Rules Are Aimed At Drug Cartels
Next Article Stocks making the biggest moves after hours: UAL, JBHT, IBKR

Related Posts

How to save $1,000 in a month: 10 strategies

May 31, 2025

Here’s what banks must do to secure open banking data

May 31, 2025

How banks are getting their data ready for open banking

May 31, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Should Gold Be A Part Of Your Portfolio? (Part 3)

October 12, 2024

Is Credit Card Debt Consolidation a Good Idea? Pros & Cons

April 24, 2025

Judy Dimon, wife of JPMorgan CEO, knocks on doors for Kamala Harris

November 5, 2024
Ads Banner

Subscribe to Updates

Subscribe to Get the Latest Financial Tips and Insights Delivered to Your Inbox!

Stay informed with our finance blog! Get expert insights, money management tips, investment strategies, and the latest financial news to help you make smart financial decisions.

We're social. Connect with us:

Facebook X (Twitter) Instagram YouTube
Top Insights

What a federal trade court block on Trump tariffs means for consumers

June 1, 2025

Stocks making the biggest moves premarket: ULTA, ABNB, GAP, AEO

June 1, 2025

The Road to the “Seven-Figure Club”

May 31, 2025
Get Informed

Subscribe to Updates

Subscribe to Get the Latest Financial Tips and Insights Delivered to Your Inbox!

© 2025 Smartspending.ai - All rights reserved.
  • Contact
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.