Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

JP Morgan Chase admits 76 million user details were breached

by The Gurus
October 14, 2020
in Editor's News
Share on FacebookShare on Twitter

JP Morgan Chase has admitted that a breach that it suffered in August may affect up to 76 million households and seven million small businesses.

The breach saw user contact information, such as names, addresses, phone numbers and email addresses, as well as internal JPMorgan Chase information relating to such users, compromised.

In a securities filing issued yesterday, the firm said that there is no evidence that bank account information for such affected customers was compromised during this attack, and it said it has seen no unusual customer fraud related to this incident.

“The firm continues to vigilantly monitor the situation and is continuing to investigate the matter,” it said. “In addition, the firm is fully cooperating with Government agencies in connection with their investigations.”

Eduard Meelhuysen, VP EMEA at Netskope, suspected that the attackers used a virtual private network (VPN) connection to get into the organisation. Alert Logic’s chief security evangelist, Stephen Coty, said that the data suggested that the attacker gained access to a server that was used for marketing purposes.

“There was mention that the data was organised by category of customer (Banking, Credit, Mortgage) with only name, address, telephone numbers and email addresses. This sounds like the credit card and banking information was secured and untouched by hackers. This type of data is stolen and sold on the underground for use of spam campaigned and url redirects to malicious sites,” he said.

Tim Erlin, director of IT security and risk strategy at Tripwire, said: “It remains unclear whether this is a second, separate incident, or simply further discovery of how far the first compromise reaches. The initial identified scope of a breach is hardly ever the full picture.

“While there’s little doubt that JP Morgan has taken action since the original incident was reported, the size and complexity of their network means they are unlikely to have rolled out new protections comprehensively by now. In situations like this, time is always the enemy.”

Ken Westin, security analyst at Tripwire, said: “This second compromise shows that even companies that invest heavily in security tools and people there can still be compromised if the attacker is persistent and well-resourced. Other financial services firms beware.”

John Zurawski, vice president for Authentify, said that while none of the news is good, the affected seven million small businesses must take immediate action. “Many small businesses are often no better protected, from an IT perspective, than the average home computer,” he said.

“On the other hand, there could be considerably more money involved including payroll accounts. Adding employees to a payroll account and paying them usually doesn’t trigger an alarm. In addition, small businesses often have a varying number of suppliers. It’s hard to create a profile of legitimate payees for electronic payment accounts to trigger risk alarms. The businesses affected should consent to any additional authentication factors the bank may offer.”

Tags: data breachinformation securityJPMorgan Chase
ShareTweet
Previous Post

Silk Road witness believes that FBI is giving implausible explanations

Next Post

17,000 enslaved in botnet which used Reddit server

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol