Tag / 9 entries / feed available

Finance Sector

9 of the 76 analyses in Data Breaches carry this tag. All 9 are scored against the four invariants; the matrix below is that evidence.

How this tag scores against the four invariants

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

075

Allianz Life Insurance Company of North America Data Breach (July 2025)

A threat actor used social engineering to access a third-party cloud-based CRM used by Allianz Life Insurance Company of North America and exfiltrated sensitive personal information. The incident affected approximately 1.5 million customers, financial professionals, and select employees, with exposed data potentially including names, addresses, dates of birth, Social Security numbers, email addresses, and phone numbers. The responsible threat actor or group was not confirmed, although the breach was linked in reporting to a broader campaign associated with ShinyHunters, Scattered Spider, and UNC6040.

068

American Express Data Breach March 2024

Prevented by: EGR

In March 2024, American Express disclosed a data breach caused by unauthorized access to a third-party merchant processor, exposing customer names, account numbers, and expiration dates. The breach resulted from a point-of-sale attack, impacting vendor management systems, without directly compromising American Express’s internal databases. While the specific threat actors remain unidentified, the breach underscores potential risks to customer data integrity.

056

MOVEit Data Breach June 2023

Contained by: PEC

The June 2023 MOVEit data breach began with the exploitation of a zero-day SQL injection vulnerability (CVE-2023-34362) in the MOVEit Transfer software; over 200 organizations were confirmed affected within the first weeks, a toll that climbed to more than 2,700 organizations and over 95 million individuals as disclosures continued into 2024. The Clop ransomware group was responsible, utilizing web shell deployment and data exfiltration methods to access and steal personal and sensitive information, highlighting substantial risks in application security and third-party systems.

048

Consumer Financial Protection Bureau Data Breach

The Consumer Financial Protection Bureau experienced a data breach in February 2023 caused by an employee transferring sensitive records to a personal email account, exposing the personally identifiable information of approximately 256,000 individuals. This breach involved data exfiltration from government systems, highlighting severe insider threat risks and deficiencies in internal data protection protocols. The compromised data originated from several financial institutions, posing potential privacy risks, although no misuse has been confirmed.

046

NCB Management Services Data Breach February 2023

In February 2023, NCB Management Services experienced a major data breach compromising sensitive personal and financial information of over 1 million individuals. The breach occurred due to unauthorized access through a misconfigured database, lacking adequate security measures such as password protection and multifactor authentication. This data, including Social Security numbers and financial details, was extracted by unidentified external hackers, highlighting severe vulnerabilities in third-party vendor security.

038

Cash App Data Breach - April 2022

In December 2021, the Cash App experienced a significant data breach where a former employee accessed and downloaded sensitive financial information of approximately 8.2 million users. The compromised data included brokerage account numbers and details of stock trading activities, underscoring an insider threat and deficiencies in access management controls. This incident did not involve the leak of social security numbers or passwords.

030

Capital One Data Breach 2019

Prevented by: EGR

In July 2019, Capital One experienced a major breach compromising over 100 million customer records due to a misconfigured Web Application Firewall exploited by a former Amazon Web Services employee. The attack led to unauthorized access to personal information including names, addresses, Social Security Numbers, and banking details, heightening the risk of identity theft and financial fraud. The incident emphasized vulnerabilities in cloud security configurations and poor application of the least privilege principle.

029

First American Financial Corp Data Breach

In May 2019, First American Financial Corp. suffered a major data breach that exposed approximately 885 million file records due to a security flaw. The breach involved bank account details and mortgage-related documents, which were accessible through unsecured URLs without authentication. The vulnerability was attributed to insufficient security measures, and there were no specific threat actors identified.

015

JPMorgan Chase Data Breach

Prevented by: HSF, EGR

In June 2014, a data breach at JPMorgan Chase compromised the accounts of over 76 million households and 7 million small businesses. The attackers accessed names, addresses, phone numbers, and email addresses, leveraging phishing and exploiting network vulnerabilities. The breach has been linked to cybercriminals Gery Shalon, Ziv Orenstein, and Joshua Aaron, emphasizing gaps in network security and authentication procedures.

RSS feed for this tag →

Now playing Bandcamp