2014 JPMorgan Chase data breach explained
2014 JP Morgan Data Breach |
Time: | 2011 – May 2015 |
Duration: | c. 3 Years 6 Months |
Location: | New York City |
Type: | Data breach |
Patrons: | --> |
Organizers: | --> |
Arrests: | 4 |
Suspects: | 4 |
Accused: | 4 |
Convictions: | 4 |
Blank1 Data: | --> |
Blank2 Data: | --> |
The 2014 JPMorgan Chase data breach was a cyberattack against American bank JPMorgan Chase that is believed to have compromised data associated with over 83 million accounts—76 million households (approximately two out of three households in the country) and 7 million small businesses.[1] The data breach is considered one of the most serious intrusions into an American corporation's information system and one of the largest data breaches in history.[2] [3]
The cyberattack
The attack—disclosed in September 2014—was discovered by the bank's security team in late July 2014, but not completely halted until the middle of August.[4] [5] The bank declared that financial and login information associated with the accounts (such as social security numbers or passwords) were not compromised but names, email, postal addresses, and phone numbers of account holders were obtained by hackers, raising concerns of potential phishing attacks.[6] The hackers obtained a list of JPMorgan's applications and programs, using it to identify vulnerabilities and gain entry.
The attack targeted nine other major financial institutions alongside JPMorgan Chase.[7] As of October 9, the only other company believed to have had data stolen is Fidelity Investments[8], but investigators reported that the attack attempted to infiltrate the networks of banks and financial companies such as Citigroup, HSBC Holdings, E*Trade, Regions Financial Corporation and payroll-service firm Automatic Data Processing (ADP).[9]
The breach occurred at a time when consumer trust in digital security was already fragile due to recent breaches at major retailers.[10]
Indictments and extradition
US federal indictments were issued against four hackers in the massive fraud in November 2015.[11] Two Israelis indicted, Gery Shalon and Ziv Orenstein, were arrested in Israel and will be extradited to the U.S. according to Israel's Justice Ministry.[12] American hacker Joshua Samuel Aaron had also been part of the indictments.[13] They were charged with 23 counts of computer hacking affecting over 100 million customers.[14] Shalon and Orenstein pled guilty. Joshua Samuel Aaron was arrested in Dec 2016.[15] A fourth individual, Andrei Tyurin, was extradited to the US from the Republic of Georgia to face charges in 2018.[16]
JPMorgan Chase's Response
In response to the breach, JPMorgan Chase took several measures, such as doubling its annual security spending from $250 million in 2014 to $500 million within five years.[17] Also, the firm applied software updates to restrict unauthorized access and prevent further exposure of sensitive information.
External links
- https://www.justice.gov/opa/file/792651/download
- https://www.justice.gov/opa/file/792656/download
- https://www.justice.gov/usao-sdny/file/632156/download
- https://www.justice.gov/usao-sdny/press-release/file/1092376/download
- https://www.justice.gov/usao-sdny/press-release/file/1092381/download
Notes and References
- News: Siegel Bernard. Tara. Ways to Protect Yourself After the JPMorgan Hacking. 5 October 2014. The New York Times. 3 October 2014. 4 October 2014. https://web.archive.org/web/20141004222614/http://www.nytimes.com/2014/10/04/your-money/jpmorgan-chase-hack-ways-to-protect-yourself.html. live.
- News: JPMorgan hack exposed data of 83 million, among biggest breaches in history. 5 October 2014. Reuters. 2 October 2014. 29 December 2015. https://web.archive.org/web/20151229202224/http://www.reuters.com/article/us-jpmorgan-cybersecurity-idUSKCN0HR23T20141003. live.
- News: Rushe. Dominic. JP Morgan Chase reveals massive data breach affecting 76m households. 5 October 2014. The Guardian. 2 October 2014. 4 October 2014. https://web.archive.org/web/20141004221840/http://www.theguardian.com/business/2014/oct/02/jp-morgan-76m-households-affected-data-breach. live.
- Web site: Goldstein . Matthew . Perlroth . Nicole . Sanger . David E. . Hackers' Attack Cracked 10 Financial Firms in Major Assault . The New York Times . 2014-10-03 . 2014-10-04 . 2020-12-16 . https://web.archive.org/web/20201216231326/https://dealbook.nytimes.com/2014/10/03/hackers-attack-cracked-10-banks-in-major-assault/ . live .
- Web site: Chan . Cathy . Hackers' Attack on JPMorgan Chase Affects Millions . The New York Times . 2014-10-02 . 2014-10-02 . 2021-02-12 . https://web.archive.org/web/20210212103949/https://dealbook.nytimes.com/2014/10/02/jpmorgan-discovers-further-cyber-security-issues/?_php=true&_type=blogs&_r=0 . live .
- Web site: Santus. Rex. What You Need to Know About the JPMorgan Chase Cyberattack. Mashable. 3 October 2014. 5 October 2014. 5 October 2014. https://web.archive.org/web/20141005164423/http://mashable.com/2014/10/03/need-to-know-jpmorgan-chase/. live.
- News: Woodyard. Chris. Report: Russian hackers behind JPMorgan Chase attack. 5 October 2014. USA Today. 4 October 2014. 4 October 2014. https://web.archive.org/web/20141004234935/http://www.usatoday.com/story/money/business/2014/10/04/jpmorgan-chase-cyberattack-russians/16717499/. live.
- News: J.P. Morgan Hackers Also Stole Fidelity Data, Investigators Think. Barrett. Devlin. 9 October 2014. The Wall Street Journal. 9 October 2014. 8 January 2015. https://web.archive.org/web/20150108071735/http://www.wsj.com/articles/state-attorneys-general-weigh-group-to-examine-jpm-cyberattack-1412879567. live.
- News: JPMorgan Hackers Said to Probe 13 Financial Firms. Riley. Michael. 9 October 2014. Bloomberg. 10 October 2014. 10 October 2014. https://web.archive.org/web/20141010030221/http://www.bloomberg.com/news/2014-10-09/jpmorgan-hackers-said-to-probe-13-financial-firms.html. live.
- Web site: Perlroth . Jessica Silver-Greenberg, Matthew Goldstein and Nicole . 2014-10-02 . JPMorgan Chase Hacking Affects 76 Million Households . 2024-11-03 . DealBook . en.
- Four Indicted in Massive JP Morgan Chase Hack. 10 November 2015. WIRED. Zetter. Kim. 4 March 2017. 31 December 2016. https://web.archive.org/web/20161231155701/https://www.wired.com/2015/11/four-indicted-in-massive-jp-morgan-chase-hack/. live.
- News: 2 Israelis in JPMorgan Chase cyber fraud case to be extradited . 23 March 2023 . Jewish Telegraphic Agency . 9 May 2016 . 17 February 2018 . https://web.archive.org/web/20180217202756/https://www.jta.org/2016/05/09/news-opinion/united-states/2-israelis-in-jpmorgan-chase-cyber-fraud-case-to-be-extradited . live .
- News: Suspected JP Morgan hacker arrested after returning from Moscow . 23 March 2023 . CBS News . 14 December 2016 . 23 March 2023 . https://web.archive.org/web/20230323181200/https://www.cbsnews.com/news/joshua-samuel-aaron-suspected-jp-morgan-hacker-arrested-after-returning-from-moscow/ . live .
- Web site: Crowe . Portia . Nov 10, 2015 . JPMorgan fell victim to the largest theft of customer data from a financial institution in US history . businessinsider.com.
- Web site: Whitehouse . Kaja . Dec 15, 2016 . Accused bank hacker claims Russia offered him asylum . nypost.com.
- Web site: Kosman . Josh . 2018-09-10 . Hacker behind largest breach in US history appears in court . 2024-08-24 . en-US.
- Web site: What happened in the JP Morgan Chase data breach? Twingate . 2024-11-03 . www.twingate.com . en.