AccidentalMisconfigurationCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumResolved
JP Morgan Chase & Co
bd_17c628b4b6b443e3 · schema v1 · pii pii-v1
Full breach record for JP Morgan Chase & Co →J.P. Morgan disclosed a software issue causing unauthorized access to plan participant data by three authorized system users from August 26, 2021, to February 23, 2024. The incident, discovered on February 26, 2024, exposed names, addresses, Social Security numbers, and bank account details. J.P. Morgan applied a software update to fix the issue and offered two years of credit monitoring to affected individuals.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_5db5795a826bccefOregon State AGfiled 2024-04-28(1d gap)Verified
- bd_2c75438adc27bcc8Vermont State AGfiled 2024-04-18(9d gap)Verified
- bd_7f9042b5f1648a92Delaware State AGfiled 2024-04-18(9d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-584558
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 27, 2024
- Raw hash
- 69dff664a6cca06f272f83eec214b98942276120bc900aba60a0e2165edbd8be
Reporting entity
- Name
- JP Morgan Chase & Conorm: jp morgan chase
Victim entity
- Name
- JP Morgan Chase & Conorm: jp morgan chase
Incident
- Discovered
- Feb 26, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unknown
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.