Hackers have obtained customer data from a third-party company used by major Wall Street banks including JPMorgan Chase and Citi. The revelation comes just days after a Doordash data breach exposed names, addresses, phone numbers and more.
See also: JPMorgan urges redefinition of SaaS security

SitusAMC applications for mortgages and other real estate loans and says its accounting records and legal agreements have been affected by the breach.
The company’s statement is vague and does not name specific banking customers. They have acknowledged an incident that resulted in some information being compromised from their systems. Corporate data related to certain customers’ relationships with SitusAMC, such as accounting records and legal agreements, has been impacted. Some customer-related data may also have been impacted. The scope, nature, and extent of this impact remains under investigation by the company and third-party advisors.
After being notified of the incident, they launched an investigation with the help of leading experts, notified federal law enforcement, and began taking steps to assess and contain the incident. The incident has now been contained and their services are fully operational. No encryption malware was involved.
See also: Chinese hackers APT31 target Russian IT companies

They are in direct, regular contact with their customers on this matter and remain focused on analyzing any potentially affected data, providing updates directly to customers as the investigation progresses.
An article in The New York Times reports that the company works with hundreds of banks, specifically naming JPMorgan Chase and Citi. CNN reports that the FBI is investigating.
“While we are working closely with affected organizations and our partners to understand the extent of the potential impact, we have not identified any operational impact to banking services,” FBI Director Kash Patel in a statement. “We remain committed to identifying those responsible and ensuring the security of our critical infrastructure.”
See also: Australia: Chinese hackers target critical infrastructure

A security expert quoted by CNN says the data breach is a stark reminder that security is only as good as its weakest link.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
