HomeSecurityOCC USA: Hackers gained access to emails

OCC US: Hackers gained access to emails

In June 2023, hackers managed to breach the Office of the Comptroller of the Currency (OCC) of the US Treasury Department, and according to Bloomberg sources, they gained access to more than 150,000 emails.

OCC US: Hackers gained access to emails

The OCC oversees banks and federal savings associations and ensures that they comply with applicable laws, treat customers fairly, and provide equitable access to financial services.

As the OCC revealed in February 2025, attackers were able to monitor employee emails after the account of an email system administrator was compromised. At the time, the OCC reported the attack to CISA as a “cybersecurity incident” involving the email system and multiple email accounts, with no financial sector implications.

See also: Hackers targeted major Australian pension funds

“ The Office of the Comptroller of the Currency (OCC) has identified, isolated, and addressed a security incident involving a management account in the email system OCC’s ,” the U.S. banking regulator said

“The OCC investigation analyzed all email logs from 2022. The OCC identified a limited number of affected email accounts that have since been disabled“.

While the OCC initially said the breach affected only a limited number of accounts, people familiar with the investigation told Bloomberg that the attackers had access to more email accounts than previously thought and about 100 emails from banking regulators.

OCC: Major security breach

On Tuesday, April 8, the OCC also informed the US Congress about the “major security incident” discovered on February 11. The regulator said the compromised account was deactivated a day after the discovery, on February 12.

See also: Ivanti fixes vulnerability used by hackers

The OCC added that “unauthorized access to certain emails of its officers and employees included highly sensitive information about the financial condition of federally regulated financial institutions used in examinations and supervisory processes.”

How can organizations protect themselves from breaches?

1. Strong Password Policy

  • Mandatory use of complex codes (letters, numbers, symbols, more than 12 characters).
  • Regularly change passwords (e.g. every 3 months).
  • Prohibition of reuse of old passwords.

2. Enable multi-factor authentication (MFA)

  • MFA on all accounts (email, cloud, ERP, CRM, etc.).
  • It can be with a code + verification app (e.g. Google Authenticator or SMS).

3. Systems Update & Monitoring

  • Automatic updates for operating systems, applications and security software.
  • Daily monitoring for unusual activity or intrusions (e.g. via SIEM).

4. Personnel Training

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Train staff in:

  • Phishing emails (how to recognize them).
  • Secure use of email & cloud tools.
  • Social engineering.

5. Minimize Access Rights

  • “ Least Privilege ” rule : each employee should only have as much access as needed .
  • Admin accounts should be limited and monitored.

See also: Hackers exploit critical vulnerability in CrushFTP

OCC emails breach hackers
OCC US: Hackers gained access to emails

6. Data Backup & Recovery

  • Regular backups (also offline).
  • Data recovery tests to ensure the plan is operational in the event of a cyberattack (e.g. ransomware).

7. Use Firewall & Endpoint Protection

  • Installation of a professional firewall.
  • Antivirus / EDR (Endpoint Detection & Response) on every endpoint (computer, server, mobile).

8. Security Event Recording (Logs)

  • Enable event logging (e.g. login attempts, permission changes).
  • Store logs for a sufficient period of time.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS