57K Bank of America accounts impacted by massive data breach

February 14, 2024
1 min read

TLDR:

A data breach at a financial software provider called Infosys McCamish has compromised the personally identifiable information of 57,028 deferred compensation customers whose accounts were serviced by Bank of America. The breach, which occurred on November 3, 2023, was attributed to an unauthorized party, known as LockBit, accessing the customers’ information through Infosys McCamish’s system. The affected customers have been provided with two-year identity theft protection by Bank of America. Many states, including Maine, require companies to notify affected individuals within 30 days of a data breach, but the notification came 90 days later. It is unclear whether any law enforcement investigations into the breach delayed the notification.

Key points:

  • A data breach at Infosys McCamish compromised the personal information of 57,028 Bank of America customers with deferred compensation plans.
  • The breach occurred on November 3, 2023, and was attributed to the ransomware group LockBit.
  • Bank of America provided affected customers with two-year identity theft protection.
  • Notification of the breach came 90 days after it occurred, potentially in violation of state laws requiring timely notification.
  • Infosys McCamish provides marketing, plan design, enrollment, and administration services for deferred compensation plans to financial institutions, including Bank of America.

The breach of personal information at a financial software provider, Infosys McCamish, has impacted 57,028 Bank of America customers with deferred compensation plans. The breach, which occurred on November 3, 2023, allowed an unauthorized party access to the customers’ information through Infosys McCamish’s system. The responsible party is believed to be the ransomware group LockBit. Bank of America provided affected customers with two-year identity theft protection as a result of the breach.

Notification of the breach occurred 90 days after it took place, potentially in violation of state laws requiring timely notification. It is unclear whether any law enforcement investigations into the breach delayed the notification. Infosys McCamish provides marketing, plan design, enrollment, and administration services for deferred compensation plans to financial institutions, including Bank of America.

Latest from Blog

Janet L Rathod is the new CISO at Johns Hopkins

TLDR: Janet L. Rathod named chief information security officer at Johns Hopkins, bringing over two decades of experience in cybersecurity. Rathod has previously worked at Citigroup, Capital One, and the FBI, and