Back to the archive

The encyclopedia · Software & IT · Operational decision · 2014

JPMorgan's 2014 breach hit 76M households — and the bank didn't detect it for months

In 2014, hackers stole data on 76M households and 7M businesses from JPMorgan Chase. The breach went undetected for months. The bank's stock fell 5%.

JPMorgan Chase · 2014-08

What happened

In August 2014, JPMorgan Chase, the largest bank in the US, disclosed that hackers had stolen data on approximately 76 million households and 7 million small businesses. The stolen data included names, addresses, phone numbers and email addresses.

The breach had begun in June 2014 and went undetected for approximately two months. The hackers gained access through a compromised employee account and exploited vulnerabilities in JPMorgan's network. The bank's $250 million annual cybersecurity budget was not sufficient to prevent the breach.

The case illustrated that even the most well-funded cybersecurity programs can be breached through basic vulnerabilities (compromised credentials, unpatched servers), and that the size of the security budget is less important than the quality of the implementation. JPMorgan's $250M budget was the largest in the industry; the breach was caused by a failure to apply basic security hygiene.

Why it happened

  • Hackers stole data on 76M households and 7M businesses from JPMorgan.
  • The breach went undetected for approximately two months.
  • The hackers exploited a compromised employee account and unpatched servers.
  • JPMorgan's $250M annual cybersecurity budget did not prevent the breach.
What it cost76M households; 7M businesses; stock fell 5%costly

The lesson

The size of the security budget matters less than the quality of the implementation. JPMorgan spent $250M; the breach was a compromised login and unpatched servers.

Aftermath

JPMorgan overhauled its security infrastructure and increased its cybersecurity spending. The case prompted the financial industry to strengthen credential management and patch management practices.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →