HackingIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
JP Morgan Chase & Co
bd_7f9042b5f1648a92 · schema v1 · pii pii-v1
Full breach record for JP Morgan Chase & Co →J.P. Morgan disclosed a data breach involving a software issue that allowed three authorized system users to view plan participant information. The incident occurred between August 26, 2021, and February 23, 2024. Affected data included names, addresses, Social Security numbers, payment amounts, and bank routing/account numbers for individuals with direct deposit. J.P. Morgan applied a software update to fix the access issue and offered two years of free credit monitoring via Experian. No indication of misuse was found.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_2c75438adc27bcc8Vermont State AGfiled 2024-04-18Verified
- bd_17c628b4b6b443e3California State AGfiled 2024-04-27(9d gap)Candidate
- bd_5db5795a826bccefOregon State AGfiled 2024-04-28(10d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/05/J.P.-Morgan-Privacy-Breach-Template.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 18, 2024
- Raw hash
- 0ed711b78f8c37187af506ffea11de59d4b3fb17bdbd6779f77a228e5e128462
Reporting entity
- Name
- JPMorgan Chase Bank, National Associationnorm: jpmorgan chase bank national
Victim entity
- Name
- JP Morgan Chase & Conorm: jp morgan chase
Incident
- Discovered
- Feb 26, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(52 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.