Skip to main content
Breach Signal

Breach report

Financial Services

JPMorgan Chase

JPMorgan Chase says hacking affected 76 million households

Hackers who gained a foothold through a poorly secured server reached contact data for 76 million households and 7 million businesses at JPMorgan Chase, the largest U.S. bank, as part of a wider stock-fraud scheme.

Reported by Fortune

Records exposed

83M

76 million households and 7 million small businesses

Scale vs. largest on file

When
2014
How they got in
Stolen employee credentials on a server lacking two-factor authentication
Sector
Financial Services

On October 2, 2014, JPMorgan Chase disclosed in a regulatory filing that a cyberattack earlier that summer had compromised contact information for 76 million households and 7 million small businesses. The bank had acknowledged in August that it was investigating an intrusion, but the new figures showed the breach was far larger than first understood, reaching users of Chase.com, JPMorgan Online and the bank's mobile apps.

Investigators later reported that the attackers began their intrusion around June 2014 and were detected in late July. According to press accounts of the bank's internal findings, they got in by using stolen employee login credentials on a server that had not been upgraded to require two-factor authentication. From there they obtained high-level access to dozens of servers. The episode embarrassed a bank that was spending about $250 million a year on cybersecurity.

JPMorgan said the stolen data included names, addresses, phone numbers and email addresses, as well as internal information about customers. It said it had found no evidence that account numbers, passwords, user IDs, dates of birth or Social Security numbers were compromised, and no unusual customer fraud tied to the incident. Even so, the scale of exposed contact data raised concerns about phishing campaigns aimed at the bank's customers.

The case took an unusual turn in 2015, when federal prosecutors in Manhattan charged Israeli nationals Gery Shalon and Ziv Orenstein and U.S. citizen Joshua Samuel Aaron with running a sprawling criminal enterprise that hacked JPMorgan and other financial firms. Prosecutors said the group used stolen customer contact lists to promote penny stocks in pump-and-dump schemes, alongside illegal online casinos and payment processing. A Russian man, Andrei Tyurin, was later extradited and sentenced in 2021 to 12 years in prison for his role in the hacks.

The breach is often cited as a turning point for Wall Street cybersecurity. It showed that even a heavily resourced institution can be undone by a single overlooked system, and it prompted regulators and banks to push harder on multi-factor authentication and privileged-access controls. It also revealed that stolen contact data, though less sensitive than account numbers, can still be monetized at scale.

More from the wire

More in Financial Services.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.