Bank of America is warning customers of a data breach exposing their personal information after one of its service providers was hacked last year.
Customer personally identifiable information exposed in the security breach includes the affected individuals' names, addresses, social security numbers, dates of birth, and financial information, including account and credit card numbers, according to details shared with the Attorney General of Texas.
While Bank of America has yet to disclose how many customers were impacted by the data breach, Infosys McCamish Systems, the vendor that had its systems compromised, revealed in a recent filing with the Attorney General of Maine that 57,028 had their data exposed in the incident.
Infosys, IMS' parent company, is a multinational IT consulting giant with over 300,000 employees and clients in over 56 countries.
Bank of America serves approximately 69 million clients at over 3,800 retail financial centers and through approximately 15,000 ATMs in the United States, its territories, and more than 35 countries.
On November 4th, the LockBit ransomware gang claimed responsibility for the IMS attack, saying that its operators encrypted over 2,000 systems during the breach.
The LockBit ransomware-as-a-service operation came to light in September 2019 and has since targeted many high-profile organizations, including the UK Royal Mail, the Continental automotive giant, the City of Oakland, and the Italian Internal Revenue Service.
In June, cybersecurity authorities in the United States and partners worldwide released a joint advisory estimating that the LockBit gang has extorted at least $91 million from U.S. organizations following roughly 1,700 attacks since 2020.
A Bank of America spokesperson was not immediately available for comment when contacted by BleepingComputer earlier today.
Verizon insider data breach hits over 63,000 employees.
HPE investigates new breach after data for sale on hacking forum.
FTC orders Blackbaud to boost security after massive data breach.
Johnson Controls says ransomware attack cost $27 million, data stolen.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Mon, 12 Feb 2024 23:35:13 +0000