Bank of America notified 57,028 customers after Infosys McCamish breach

Organization
Bank of America
Exploit
Third-Party Data Breach
Industry
Financial Services

Bank of America began notifying 57,028 customers in early February 2024 that their personal information had been exposed in a breach at one of its service providers. The affected customers were enrolled in deferred compensation plans administered by Infosys McCamish Systems, a US subsidiary of Infosys that handles insurance and retirement plan processing.

According to the bank's notification, Infosys McCamish was compromised on November 3, 2023, and told Bank of America on November 24 that customer data may have been taken. The exposed fields included first and last names, addresses, business email addresses, dates of birth, Social Security numbers and account information. Bank of America said its own systems were not involved and that it was unlikely to be able to determine with certainty what information had been accessed.

The LockBit ransomware operation claimed the intrusion on November 4, 2023, saying it had encrypted more than 2,000 systems at the provider. Infosys McCamish retained an outside forensic firm, which reported finding no evidence of continued attacker access, tooling or persistence in its environment.

Bank of America filed breach notices with state regulators, including the Texas attorney general, and offered affected customers two years of identity theft protection. The bank declined to comment in detail and referred questions to Infosys McCamish.

Sources