2025 SitusAMC — non-ransomware exfiltration; bank clients notified (JPMorgan, Citi, Morgan Stanley)
Data compromised
Mortgage and loan servicing documents, SSNs and financial fields per breach notifications
Technical writeup
On November 12, 2025, mortgage-technology and loan-servicing vendor SitusAMC disclosed a cyberattack characterized in company and press narratives as data exfiltration without ransomware encryption. Coverage (CSO Online, Cybersecurity Dive, Reuters via NYT, FINRA alert) described accounting records, legal agreements, and sensitive customer files tied to mortgage workflows, with major U.S. banks including JPMorgan Chase, Citigroup, and Morgan Stanley assessing downstream client exposure. FBI investigation was noted publicly.
Root cause
Unauthorized access to vendor file and collaboration systems; simple file-share path cited in some reporting
References
- https://www.situsamc.com/databreach
- https://www.csoonline.com/article/4095182/jpmorgan-citi-morgan-stanley-assess-fallout-from-situsamc-data-breach.html
- https://www.cybersecuritydive.com/news/bank-vendor-cyberattack-supply-chain/806293/
- https://www.nytimes.com/2025/11/22/business/bank-data-hack.html
- https://www.finra.org/rules-guidance/guidance/finra-cybersecurity-alert-situsamc-security-incident