News

Company That Runs Back Office for American Banks Just Got Hacked

Most people have never heard of the company that keeps their local bank or credit union running behind the scenes, and that’s exactly why this week’s cybersecurity incident with Jack Henry attack might have missed attention it deserves.

Company That Runs Back Office for American Banks Just Got Hacked

​​On August 31, Jack Henry & Associates, a company that provides technology for core banking operations for many banking and credit union clients in the United States, has confirmed that a cybersecurity incident occurred in a contained section of its internal corporate environment. According to the company, none of the systems that are used to serve clients were affected by this incident, which was limited and did not impact the functioning of any of the company’s systems and services in any way. 

As per the intelligence agency SOCRadar, the hacker group ShinyHunters was behind the breach, which they claimed responsibility for on August 30.

Jack Henry doesn’t just serve a handful of banks. A research from the Federal Reserve Bank of Kansas City found the company’s core banking platforms run underneath roughly 21% of US banks and 12% of credit unions. It means the firm is one of just three companies that together power the majority of America’s community financial institutions.

What firms like Jack Henry power is a bank’s “core” – central system of record that tracks account balances, processes deposits and withdrawals, and keeps every transaction in sync. All this happens behind the scenes, but eventually client banking activities are also affected by backend operations. Most small and mid-sized banks don’t build this technology themselves, as it’s costly and human-resource-consuming. Instead, they license it from a small number of specialized vendors like Jack Henry. That’s efficient for banks, but it also means a huge share of the banking industry depends on the security of a single outside company that has just been infringed. 

Jack Henry said the incident began with a sophisticated voice-phishing scheme, sometimes called “vishing,” that tricked an employee into granting access, rather than a technical break-in. The company said personally identifiable information for fewer than 10 of its more than 7,200 clients was affected, and it is offering two years of free credit monitoring to account holders at those institutions. 

Jack Henry also said it will not pay the group behind the extortion attempt and called the incident financially immaterial to the company. SOCRadar’s analysis separately found employee login credentials tied to Jack Henry circulating in stealer-log data in the weeks before the incident was detected, a common early-warning sign in this kind of attack.

Nina Bobro

Nina Bobro

2186 Posts

https://payspacemagazine.com/author/nb/

Nina is passionate about financial technologies and environmental issues, reporting on the industry news and the most exciting projects that build their offerings around the intersection of fintech and sustainability.