A sophisticated supply chain attack targeting a third-party payment processor has compromised 8 million accounts at a major US bank, exposing names, account numbers, and transaction histories.

How the Attack Happened

Attackers injected malicious code into a software update from the banks payment processing vendor. The compromised update ran undetected for 6 weeks, siphoning data from internal systems.

What Was Exposed

What to Do If Affected

The bank is offering 2 years of free credit monitoring through Experian. Additionally, affected customers should freeze their credit at all three bureaus, monitor accounts daily, and set up fraud alerts. Change passwords for all financial accounts immediately.