Ever since the JPMorgan Chase breach was made public, companies have been watching closely to see the aftermath, the bank's course of action, and any best practices that may be developed as a result.
In this post, I've highlighted some of the most notable details of the breach, explaining why they're important and why they matter even outside of the Financial Services industry.
The Attack
The News:
Even after the breach was mentioned in the media it wasn't immediately known exactly who the culprits were, or why they targeted JPMC. The breach lasted two months, before a hacker's mistake allowed a vendor to notice it:
“The bank learned hackers stole contact information for 76 million households and 7 million small businesses that dealt with J.P. Morgan because the intruders had used some of the same offshore servers to hack both the bank and the website of the J.P. Morgan Corporate Challenge, according to people familiar with the matter… Hackers were in the bank’s network for about two months undetected, only revealing themselves because of an apparent slip-up by the hackers and a report by a security vendor in early August.”
This breach was the second in as many summers for JPMC, after the UCard infiltration lasted from mid-July to mid-August in 2013.
Why it Matters:
The longer a breach goes undetected, the easier it is for hackers to dig deeper into the enterprise and access sensitive information. This highlights why it’s important for organizations to adopt security intelligence tools that allow them to detect and respond to threats in real time, across the business ecosystem. Acting fast to minimize damage is essential.
The Response
The News:
JPMC will have to physically change much of its IT infrastructure because of the hack.
“The bank, which reports that hackers gained access to root access to many of its servers, will have to essentially strip out and replace much of its internal IT infrastructure, a process that Edwards estimates could take "months at the least."”
Why it Matters:
There are high costs both in breach prevention and resolution, and that will never change.
The threat landscape is constantly evolving, and at a pace that can be difficult for even the most resourced organizations to keep up with. The key to staying ahead of attackers is knowing where your vulnerabilities lie and how they can be exploited. This includes being aware of security risks across your entire digital supply chain, as you are only as secure as the weakest link.
The News:
Not directly related to the breach, but in response to attacks leveraged against the industry, many large banks are joining forces to form Soltra Edge software to protect against hackers.