Software flaw at J.P. Morgan exposed data on 451,000 retirement savers

Organization
JPMorgan Chase
Exploit
Misconfiguration
Industry
Financial Services

JPMorgan Chase began notifying about 451,000 retirement plan participants in late April 2024 that their personal information had been visible to parties who should not have been able to see it. The bank disclosed the incident to the Maine Attorney General's Office on 29 April 2024, and trade publications reported the notification that week.

The exposure did not stem from an intrusion. J.P. Morgan said a flaw in software supplied by a vendor allowed three system users, described as being linked to J.P. Morgan customers or their agents, to generate reports containing plan participant data they were not entitled to view. The bank identified the problem on 26 February 2024 and said the improper access ran from 26 August 2021 through 23 February 2024.

The information involved included names, addresses, Social Security numbers and payment and deduction amounts. Participants who had set up direct deposit also had bank routing and account numbers included in the exposed reports.

J.P. Morgan applied a software update to close the flaw and said it had no indication the information had been misused. It offered affected participants two years of identity theft protection through Experian IdentityWorks and opened a call centre to field questions. The bank did not name the vendor whose software contained the defect.

Sources