U.S. bank regulator OCC discloses year-long email system breach

Organization
Office of the Comptroller of the Currency
Exploit
Hacking
Industry
Government

The Office of the Comptroller of the Currency, the U.S. Treasury bureau that charters and supervises national banks, notified Congress on April 8, 2025 that a breach of its email system met the threshold for a major incident under the Federal Information Security Modernization Act.

The OCC said it was alerted on February 11, 2025 to unusual interactions involving an administrative account, after Microsoft reported the activity, and confirmed the following day that the access was unauthorized. It disabled the affected accounts, reported the matter to the Cybersecurity and Infrastructure Security Agency and opened an internal review alongside an independent third-party investigation.

Investigators established that the intruders had held access since May 2023 and had read approximately 150,000 emails drawn from roughly 103 executive and employee mailboxes. According to the agency, the messages and attachments contained highly sensitive information on the financial condition of federally regulated financial institutions used in its examinations and supervisory oversight processes.

The OCC said it identified no direct impact on the broader financial sector. Acting Comptroller Rodney E. Hood attributed the incident to long-held organizational and structural deficiencies and said there would be full accountability for the vulnerabilities identified. On April 15 the agency published a letter to the institutions it supervises setting out what had happened.

Sources