2014 Cyber intrusion — 83M accounts (76M households, 7M businesses)
Data compromised
Names, email addresses, postal addresses, phone numbers
Technical writeup
One of the largest data breaches in history. Hackers gained access to JPMorgan's systems between 2011 and May 2015; the breach was discovered in late July 2014 and disclosed in September 2014. Attackers obtained a list of JPMorgan's applications to identify vulnerabilities; the bank had not installed two-factor authentication on an overlooked server. Names, email addresses, postal addresses, and phone numbers of account holders were stolen. Financial information, account numbers, passwords, SSNs, and birth dates were not compromised.
Root cause
Missing two-factor authentication on overlooked server; attackers exploited application inventory to find vulnerabilities.