JPMorgan Chase , one of the world's largest banks, recently announced that it was the victim of a cyberattack and warned of the possible exposure of personal information for approximately 465,000 holders of its prepaid credit cards.
The security breach that occurred on the bank's website www.ucard.chase.com in July put about 465,000 accounts at risk, or 2% of the total 25 million UCard users. JPMorgan confirmed that there is no risk to holders of debit cards, credit cards or prepaid Liquid cards.
They notified police in September, and so far there is no information about how the attackers carried out their attack.
JPMorgan spokesman Michael Fusco said that their investigation so far has enabled them to find the victims' accounts and the data that has been stolen, and the bank has already notified cardholders of the incident.
The JPMorgan spokesperson also noted that the hackers did not steal money from any user's account, and that's because the company does not issue replacement cards, but only offers cardholders free credit monitoring services.
" The bank typically keeps its customers' personal data encrypted as a security precaution. However, during the breach, personal data belonging to those customers had temporarily appeared in plain text format in files that computers use to record activity ," Reuters reported .
The above statement literally made the hairs on the bank's head stand on end, horrified by what this could mean: "customers had temporarily appeared in plain text in files that computers use to record activity." Especially when you're talking about perhaps the largest bank in the world.
Banking experts say only “a small amount” of data was exposed during the data breach, and the information, according to the company, did not include Social Security numbers and other personal information such as dates of birth and email addresses that could be used by cybercriminals for financial fraud and identity theft.
At the moment there is a silence about the names of the victims and no idea about the origin of the attack. Cybercriminals consider the type of information obtained as a valuable commodity to sell on the underground market.
Security experts Mr. Stewart from Dell SecureWorks and independent researcher Mr. David Shearhave recently published a study on the online underground market for stolen data, and their analysis showed that it is quite easy to buy a credit card's details for a little over ten dollars.
📧
Subscribe to the SecNews Newsletter

