HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
JPMorgan Chase Bank, National Association
bd_1d6fdc652ca663ce · schema v1 · pii pii-v1
Full breach record for JPMorgan Chase Bank, National Association →J.P. Morgan Chase Bank, N.A. disclosed a data breach affecting plan participants of {{PlanClientName}}. Between August 26, 2021, and February 23, 2024, three authorized system users accessed reports containing names, addresses, SSNs, and bank account numbers. The incident was discovered on February 26, 2024, and remediated via a software update. Affected individuals were offered two years of credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_2f44509a28216b33California State AGfiled 2024-04-29(11d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/05/J.P.-Morgan-Privacy-Breach-Template.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 18, 2024
- Raw hash
- b9c666a58a1e63defc00effe6718e087c5b8d74010e65aa12f9046c56475408a
Reporting entity
- Name
- JPMorgan Chase Bank, National Associationnorm: jpmorgan chase bank national
Victim entity
- Name
- JPMorgan Chase Bank, National Associationnorm: jpmorgan chase bank national
Incident
- Discovered
- Feb 26, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(52 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.