<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Finance Sector on Security Blueprints</title>
    <link>https://securityblueprints.io/tags/finance-sector/</link>
    <description>Recent content in Finance Sector on Security Blueprints</description>
    <generator>Hugo</generator>
    <language>en</language>
    <managingEditor>user@example.com (Niels Provos)</managingEditor>
    <webMaster>user@example.com (Niels Provos)</webMaster>
    <copyright>Security Blueprints, LLC</copyright>
    <lastBuildDate>Sun, 06 Sep 2026 23:57:45 +0000</lastBuildDate>
    <atom:link href="https://securityblueprints.io/tags/finance-sector/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Allianz Life Insurance Company of North America Data Breach (July 2025)</title>
      <link>https://securityblueprints.io/data-breaches/allianz-life-insurance-company-of-north-america-data-breach-july-2025/</link>
      <pubDate>Wed, 16 Jul 2025 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/allianz-life-insurance-company-of-north-america-data-breach-july-2025/</guid>
      <description>Executive Summary Incident summary On July 16, 2025, a threat actor used social engineering to access a third-party, cloud-based customer relationship management (CRM) system used by Allianz Life Insurance Company of North America. Allianz Life’s official account states that it became aware of suspicious activity on July 17 at 12:17 p.m. CDT and terminated access to accounts associated with that activity at 2:17 p.m. CDT. (agportal-s3bucket.s3.amazonaws.com ) The company reported no indication that the threat actor accessed its company network or systems outside the CRM; this does not establish that the CRM was deliberately isolated.</description>
    </item>
    <item>
      <title>American Express Data Breach March 2024</title>
      <link>https://securityblueprints.io/data-breaches/american-express-data-breach-march-2024/</link>
      <pubDate>Mon, 04 Mar 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/american-express-data-breach-march-2024/</guid>
      <description>Executive Summary On March 4, 2024, American Express announced a data breach resulting from unauthorized access through a third-party merchant processor. This incident compromised customer information, including names, account numbers, and expiration dates, due to a point-of-sale attack affecting systems associated with American Express Travel Related Services Company. It highlights the vulnerabilities within third-party vendor systems in the financial sector. Source Severity of Impact The breach presented significant risks, potentially compromising critical cardholder information.</description>
    </item>
    <item>
      <title>MOVEit Data Breach June 2023</title>
      <link>https://securityblueprints.io/data-breaches/moveit-data-breach-june-2023/</link>
      <pubDate>Thu, 01 Jun 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/moveit-data-breach-june-2023/</guid>
      <description>Executive Summary In June 2023, a significant data breach involving the MOVEit Transfer software began; within its first weeks it had affected over 200 organizations globally, a toll that continued climbing for more than a year afterward (Axios ). This breach was triggered by exploiting a zero-day vulnerability, CVE-2023-34362, within the MOVEit Transfer tool by Progress Software Corporation. The Clop ransomware group, using its Ransomware as a Service (RaaS) model, claimed responsibility for the data theft operations.</description>
    </item>
    <item>
      <title>Consumer Financial Protection Bureau Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/consumer-financial-protection-bureau-data-breach/</link>
      <pubDate>Tue, 14 Feb 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/consumer-financial-protection-bureau-data-breach/</guid>
      <description>Executive Summary In 2023, the Consumer Financial Protection Bureau (CFPB) experienced a significant data breach due to internal security lapses. An employee transferred confidential records via email to a personal account, compromising the data of approximately 256,000 individuals. This incident underscores critical deficiencies in CFPB&amp;rsquo;s data protection protocols and has raised considerable concerns over internal security measures. Source Severity of Impact The breach affected records from seven financial institutions; however, some reports suggest this number could be higher.</description>
    </item>
    <item>
      <title>NCB Management Services Data Breach February 2023</title>
      <link>https://securityblueprints.io/data-breaches/ncb-management-services-data-breach-february-2023/</link>
      <pubDate>Wed, 01 Feb 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/ncb-management-services-data-breach-february-2023/</guid>
      <description>Executive Summary In February 2023, NCB Management Services experienced a significant data breach due to an unauthorized system compromise, exposing sensitive personal and financial information. The breach was detected on February 4, 2023, affecting clients associated with major financial institutions including Capital One, Bank of America, and TD Bank.&#xA;Severity of the Impact The breach compromised data for over 1 million individuals, with specific numbers varying by institution: approximately 16,779 Capital One customers and nearly 495,000 Bank of America customers were directly impacted.</description>
    </item>
    <item>
      <title>Cash App Data Breach - April 2022</title>
      <link>https://securityblueprints.io/data-breaches/cash-app-data-breach/</link>
      <pubDate>Fri, 10 Dec 2021 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/cash-app-data-breach/</guid>
      <description>Executive Summary In April 2022, Block, the parent company of Cash App, disclosed a significant data breach involving unauthorized access by a former employee, who downloaded sensitive financial information from approximately 8.2 million users. This exposure included brokerage account details and stock trading activities. The breach was publicly announced on April 4, 2022 (source ). Despite the breadth of affected data, no personally identifiable information such as usernames, passwords, or Social Security numbers was compromised (source ).</description>
    </item>
    <item>
      <title>Capital One Data Breach 2019</title>
      <link>https://securityblueprints.io/data-breaches/capital-one-data-breach-2019/</link>
      <pubDate>Wed, 17 Jul 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/capital-one-data-breach-2019/</guid>
      <description>Executive Summary In July 2019, Capital One experienced a significant data breach that compromised over 100 million customer records. This breach occurred due to a server-side request forgery (SSRF) exploiting a misconfigured Web Application Firewall (WAF) in their systems. The attack was orchestrated by Paige A. Thompson, a former software engineer at Amazon Web Services (AWS), leveraging insider knowledge and scanning for vulnerabilities using the misconfigured AWS resources.&#xA;Key Dates Attack Period: March 22-23, 2019 Discovery Date: July 19, 2019 Public Disclosure: July 29, 2019 Severity of Impact This breach ranks among the largest in history, affecting approximately 100 million individuals in the United States and around 6 million in Canada, approximately 106 million individuals combined.</description>
    </item>
    <item>
      <title>First American Financial Corp Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/first-american-financial-corp-data-breach/</link>
      <pubDate>Fri, 24 May 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/first-american-financial-corp-data-breach/</guid>
      <description>Executive Summary In May 2019, a data breach at First American Financial Corp. resulted in the exposure of approximately 885 million file records due to inadequate security measures on their web portal. The breach came to light when a real estate developer discovered the vulnerability, and cybersecurity journalist Brian Krebs publicly disclosed it on May 24, 2019. The exposed records included sensitive financial documents such as bank account numbers, mortgage-related documents, and Social Security numbers, with records dating back to 2003.</description>
    </item>
    <item>
      <title>JPMorgan Chase Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/jpmorgan-chase-data-breach/</link>
      <pubDate>Sun, 01 Jun 2014 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/jpmorgan-chase-data-breach/</guid>
      <description>Executive Summary In June 2014, JPMorgan Chase became the target of a significant data breach, compromising data from over 76 million households and 7 million small businesses. The breach, discovered in July and publicly disclosed in September 2014, highlighted substantial deficiencies in the bank’s cybersecurity framework (source ).&#xA;Severity of Impact Approximately 83 million accounts were affected, with exposed data including names, addresses, phone numbers, and email addresses. However, no financial data or Social Security numbers were compromised, reducing the risk of direct financial fraud, yet increasing chances for phishing and identity theft (source ).</description>
    </item>
  </channel>
</rss>
