PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

Year-Long Breach at U.S. OCC Exposed Thousands of Emails, Sensitive Data

By Wesley Grant
April 9, 2025
in Analysts Coverage, Cybersecurity, Fraud & Security
0
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
occ breach

The U.S. Office of the Comptroller of the Currency (OCC) confirmed that a breach of its email systems in February was a significant incident that exposed highly sensitive information.

An independent bureau of the Treasury Department, the OCC monitors the activities of all U.S. banks, including federal savings associations and agencies of foreign banks. In addition to safeguarding trillions of dollars in assets, these institutions also hold substantial stockpiles of private data belonging to consumers and businesses.

According to Bloomberg, hackers gained access to the mailboxes of 103 OCC officials, including senior deputy comptrollers and international banking supervisors. The breach went undetected for over a year, until a Microsoft security team noticed unusual network behavior.

All told, the bad actors were able to access over 150,000 emails during the they had access to the OCC’s systems. These communications included information about the condition of banks under federal oversight.

A Threat of National Proportions

According to a Bloomberg source, the cybercriminals were able to breach the OCC’s systems after hacking into an administrator’s account. It is unclear how the threat actors gained access, who they are, or what their motivations were.

However, it is clear that the emergence of new technologies has elevated cybercriminals to a threat of national security proportions. The U.S. National Security Administration (NSA) recently issued a cybersecurity advisory about fast flux—a tactic that allows bad actors to rapidly change the IP address associated with a domain name.

The NSA stated that because fast flux enables cybercriminals and nation-state actors to build command-and-control infrastructures that conceal nefarious activities, the technique poses a threat to national security.

Harm to Public Confidence

As fraud and scams have spiraled out of control, the extent of financial losses and data breaches has reached new heights. In addition to these losses, the constant barrage of fraud attacks could have even greater impacts—such as the loss of consumer confidence in critical aspects of the country’s essential infrastructure.

“The analysis concluded that the highly sensitive bank information contained in the emails and attachments is likely to result in demonstrable harm to public confidence,” wrote Kristen Baldwin, Chief Information Officer at the OCC, in a draft letter to Congress.

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Tags: CybercriminalsData Breachfast fluxFraudhackersNSAOCCScam

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    open banking

    Open Banking Has Begun to Intrude on Banks’ Customer Relationships

    December 5, 2025
    conversational payments

    Conversational Payments: The Next Big Shift in Financial Services  

    December 4, 2025
    embedded finance

    Inside the Embedded Finance Shift Transforming SMB Software

    December 3, 2025
    metal cards

    Metal Card Magnitude: How a Premium Touch Can Enthrall High-Value Customers

    December 2, 2025
    digital gift cards

    How Nonprofits Can Leverage Digital Gift Cards to Help Those in Need

    December 1, 2025
    stored-value prepaid

    How Stored-Value Accounts Are the Next Iteration of Prepaid Payments

    November 26, 2025
    google crypto wallet, crypto regulation

    Crypto Heads Into 2026 Awaiting Its ‘Rocketship Point’

    November 25, 2025
    Merchants Real-Time Payments, swipe fees, BNPL

    The 3 Key Trends That Will Shape Merchant Payments in 2026

    November 24, 2025

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2024 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result