DisclosureLens
MisuseFinancial ServicesFinancePrivilege AbuseDelayed DiscoveryCustomer Data InvolvedIdentity (basic)Government IDFinancial accountMediumContained

J.P. Morgan

bd_09225cde6e124c67 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 26, 2024

Filed

May 6, 2024

To disclose

10 weeks

Affected

Not disclosed

Confidence

65%
Full breach record for J.P. Morgan3 incidents on file

J.P. Morgan notified South Carolina residents of a data breach where three authorized system users, employed by J.P. Morgan customers or agents, ran reports between August 2021 and February 2024 that included unauthorized plan participant information. Data exposed included names, addresses, SSNs, and bank account numbers. J.P. Morgan addressed the issue and applied a software update. Affected individuals were offered two years of credit monitoring.

Incident timeline

undetected · 914 days
discovery → filing · 10 weeks / 70 days

Aug 26, 2021

Begins

Feb 26, 2024

Discovered

May 6, 2024

Filed

vs. sector median

+2 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

J.P. Morgan — State AG breach notification · DisclosureLens