Breach report
Financial ServicesJPMorgan Chase
JPMorgan Chase says hacking affected 76 million households
Hackers who gained a foothold through a poorly secured server reached contact data for 76 million households and 7 million businesses at JPMorgan Chase, the largest U.S. bank, as part of a wider stock-fraud scheme.
Reported by Fortune
Records exposed
83M
76 million households and 7 million small businesses
Scale vs. largest on file
- When
- 2014
- How they got in
- Stolen employee credentials on a server lacking two-factor authentication
- Sector
- Financial Services
On October 2, 2014, JPMorgan Chase disclosed in a regulatory filing that a cyberattack earlier that summer had compromised contact information for 76 million households and 7 million small businesses. The bank had acknowledged in August that it was investigating an intrusion, but the new figures showed the breach was far larger than first understood, reaching users of Chase.com, JPMorgan Online and the bank's mobile apps.
Investigators later reported that the attackers began their intrusion around June 2014 and were detected in late July. According to press accounts of the bank's internal findings, they got in by using stolen employee login credentials on a server that had not been upgraded to require two-factor authentication. From there they obtained high-level access to dozens of servers. The episode embarrassed a bank that was spending about $250 million a year on cybersecurity.
JPMorgan said the stolen data included names, addresses, phone numbers and email addresses, as well as internal information about customers. It said it had found no evidence that account numbers, passwords, user IDs, dates of birth or Social Security numbers were compromised, and no unusual customer fraud tied to the incident. Even so, the scale of exposed contact data raised concerns about phishing campaigns aimed at the bank's customers.
The case took an unusual turn in 2015, when federal prosecutors in Manhattan charged Israeli nationals Gery Shalon and Ziv Orenstein and U.S. citizen Joshua Samuel Aaron with running a sprawling criminal enterprise that hacked JPMorgan and other financial firms. Prosecutors said the group used stolen customer contact lists to promote penny stocks in pump-and-dump schemes, alongside illegal online casinos and payment processing. A Russian man, Andrei Tyurin, was later extradited and sentenced in 2021 to 12 years in prison for his role in the hacks.
The breach is often cited as a turning point for Wall Street cybersecurity. It showed that even a heavily resourced institution can be undone by a single overlooked system, and it prompted regulators and banks to push harder on multi-factor authentication and privileged-access controls. It also revealed that stolen contact data, though less sensitive than account numbers, can still be monetized at scale.