2026 Jack Henry — ShinyHunters vishing; non-prod corporate env; PII for <10 clients; no ransom paid
Data compromised
Personally identifiable information associated with fewer than 10 financial-institution clients (accountholder impact via those clients; exact elements TBD in client notices)
Technical writeup
Verified company investor statement — August 31, 2026. Jack Henry & Associates said it detected a cybersecurity incident in a limited portion of its internal, non-production corporate environment. No client-facing systems, core platforms, or daily processing were accessed or disrupted. Investigation attributed the start to sophisticated vishing by ShinyHunters. PII for fewer than 10 clients was impacted; more than 7,200 clients were notified an incident occurred; two years of credit monitoring offered for impacted institutions to provide to accountholders. Extortion attempt; no payment. Not financially material per company. recordsAffected 0 (no national individual tally); companyConfirmed true.
Root cause
Social-engineering vishing attributed to ShinyHunters against a limited internal non-production corporate environment; client-facing/core systems not accessed; company refused extortion payment