A sophisticated supply chain attack targeting a third-party payment processor has compromised 8 million accounts at a major US bank, exposing names, account numbers, and transaction histories.
How the Attack Happened
Attackers injected malicious code into a software update from the banks payment processing vendor. The compromised update ran undetected for 6 weeks, siphoning data from internal systems.
What Was Exposed
- Full names and Social Security numbers
- Bank account and routing numbers
- 12 months of transaction history
- Email addresses and phone numbers
What to Do If Affected
The bank is offering 2 years of free credit monitoring through Experian. Additionally, affected customers should freeze their credit at all three bureaus, monitor accounts daily, and set up fraud alerts. Change passwords for all financial accounts immediately.