57K Bank of America accounts impacted by massive data breach

February 14, 2024
1 min read

TLDR:

A data breach at a financial software provider called Infosys McCamish has compromised the personally identifiable information of 57,028 deferred compensation customers whose accounts were serviced by Bank of America. The breach, which occurred on November 3, 2023, was attributed to an unauthorized party, known as LockBit, accessing the customers’ information through Infosys McCamish’s system. The affected customers have been provided with two-year identity theft protection by Bank of America. Many states, including Maine, require companies to notify affected individuals within 30 days of a data breach, but the notification came 90 days later. It is unclear whether any law enforcement investigations into the breach delayed the notification.

Key points:

  • A data breach at Infosys McCamish compromised the personal information of 57,028 Bank of America customers with deferred compensation plans.
  • The breach occurred on November 3, 2023, and was attributed to the ransomware group LockBit.
  • Bank of America provided affected customers with two-year identity theft protection.
  • Notification of the breach came 90 days after it occurred, potentially in violation of state laws requiring timely notification.
  • Infosys McCamish provides marketing, plan design, enrollment, and administration services for deferred compensation plans to financial institutions, including Bank of America.

The breach of personal information at a financial software provider, Infosys McCamish, has impacted 57,028 Bank of America customers with deferred compensation plans. The breach, which occurred on November 3, 2023, allowed an unauthorized party access to the customers’ information through Infosys McCamish’s system. The responsible party is believed to be the ransomware group LockBit. Bank of America provided affected customers with two-year identity theft protection as a result of the breach.

Notification of the breach occurred 90 days after it took place, potentially in violation of state laws requiring timely notification. It is unclear whether any law enforcement investigations into the breach delayed the notification. Infosys McCamish provides marketing, plan design, enrollment, and administration services for deferred compensation plans to financial institutions, including Bank of America.

Latest from Blog

Bridging the cyber talent gap: tips for CISOs

TLDR: – Global cyber threats have increased twofold in recent years, leading to a talent gap of nearly 4 million cyber professionals worldwide. – Existing cyber staff are under strain, with vacancies

North Korean hackers pivot to ransomware attacks

TLDR: North Korean hackers from APT45 have shifted from cyber espionage to ransomware attacks APT45 has targeted critical infrastructure and is linked to ransomware families SHATTEREDGLASS and Maui A North Korea-linked threat