Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
mass-credential-exposurefinancial-sector-threatbreach-disclosure-notificationenforcement-action

JPMorgan Chase Breach Exposed Contact Data for 76 Million Households

Updated 28d agoFirst seen May 25, 20267 sources

JPMorgan Chase disclosed that attackers breached its network and accessed customer contact information tied to 76 million households and 7 million small businesses, making it one of the largest publicly reported compromises of a U.S. financial institution. The bank said the stolen data included names, email addresses, phone numbers, and physical addresses, while account numbers, passwords, Social Security numbers, dates of birth, and debit or credit card data were not exposed. The intrusion reportedly began in June, went undetected for weeks, and involved access to more than 90 servers before the company contained it and notified customers using services such as Chase.com and its mobile banking platforms.

U.S. investigators examined possible Russian links early in the case, and later authorities charged Gery Shalon, Joshua Samuel Aaron, and Ziv Orenstein in connection with a broader hacking campaign tied to the JPMorgan intrusion and other attacks on financial firms and publishers. Prosecutors described the operation as part of a multi-year scheme that stole data from more than 100 million customers across victims, while security experts warned that the JPMorgan data set remained highly valuable for phishing and fraud because it provided a large, current list of bank customers and small businesses. JPMorgan said it had not seen unusual fraud directly tied to the breach and urged customers to be wary of unsolicited emails and text messages.

Share:
JPMorgan Chase Breach Exposed Contact Data for 76 Million Households
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Dec 14, 201610y ago

Suspected JPMorgan hacker Joshua Samuel Aaron is arrested in New York

In December 2016, U.S. citizen Joshua Samuel Aaron, suspected of involvement in the JPMorgan hack, was arrested in New York City after returning from Moscow. His arrest marked a significant law-enforcement step in the case.

Nov 10, 201511y ago

U.S. authorities charge three men over JPMorgan-linked hacking campaign

In November 2015, U.S. prosecutors charged Gery Shalon, Joshua Samuel Aaron, and Ziv Orenstein in connection with a broad hacking scheme tied to the 2014 JPMorgan breach and other intrusions. Authorities described it as the largest theft of customer data from a U.S. financial institution, affecting roughly 83 million customers.

Oct 3, 201412y ago

JPMorgan says attack was contained and warns customers about phishing

Following disclosure, JPMorgan said it had stopped the attack, had not observed unusual fraud linked to the breach, and warned customers it would never ask for personal information by email or text. Security experts noted the stolen contact data could be used for long-term phishing and scam campaigns.

Oct 2, 201412y ago

JPMorgan discloses breach affecting 76 million households

On October 2, 2014, JPMorgan Chase revealed that hackers had obtained customer contact information tied to 76 million households and about 7 million small businesses. The bank said names, email addresses, phone numbers, and physical addresses were exposed, but not account numbers, passwords, Social Security numbers, dates of birth, or debit and credit card data.

Aug 28, 201412y ago

FBI investigates possible Russian links to JPMorgan hack

By late August 2014, U.S. investigators were examining whether Russian hackers were connected to the JPMorgan breach and related attacks on other banks. The case drew federal attention as a major financial-sector cyber incident.

JPMorgan detects the breach about a month after it began

The bank discovered the intrusion in July 2014 after it had gone undetected for roughly a month. Early understanding reportedly suggested the attack affected about one million accounts.

Attackers begin infiltrating JPMorgan systems

The JPMorgan intrusion began in June 2014, with attackers ultimately accessing more than 90 servers. Reporting indicated the compromise may have started through an employee's computer.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

JPMorgan Chase Breach Exposed Contact Data for 76 Million Households | Mallory