JPMorgan data breach entry point identified


  • TECH
  • Tuesday, 23 Dec 2014

LAX SECURITY: The JPMorgan Chase bank was vulnerable to hackers as it did not use a double authentication scheme.

A computer breach at JPMorgan Chase & Co earlier this year could have been avoided if the bank had installed a simple security fix to an overlooked server in its network, the New York Times reported, citing people briefed on investigations.

In October, JPMorgan Chase revealed that names, addresses, phone numbers and e-mail addresses of the holders of some 83 million accounts were exposed when the bank's computer systems were compromised by hackers, making it one of the biggest data breaches in history.

The weak spot at the bank appears to have been a very basic one – the bank did not use a double authentication scheme, known as two-factor authentication, the paper reported.

JPMorgan's security team had apparently neglected upgrading one of its network servers with the dual password scheme, the newspaper said, citing people who did not want to be identified because the investigation into the attack was incomplete.

Officials at JP Morgan were not immediately available for comment outside regular US business hours.

Earlier this month, US regulators said they were stepping up efforts to examine financial institutions' defences to ward off cyber attacks, as a top FBI official warned of new "increasingly complex" threats to the financial sector. — Reuters

Win a prize this Mother's Day by subscribing to our annual plan now! T&C applies.

Monthly Plan

RM13.90/month

Annual Plan

RM12.33/month

Billed as RM148.00/year

1 month

Free Trial

For new subscribers only


Cancel anytime. No ads. Auto-renewal. Unlimited access to the web and app. Personalised features. Members rewards.
Follow us on our official WhatsApp channel for breaking news alerts and key updates!
   

Next In Tech News

In an online world, a new generation of protesters chooses anonymity
After two winsome Ori games, a pivot into dark fantasy
Teenager in China dies of heart attack after teacher forces her to exercise, insists illness is ‘fake’, delays first aid, enrages mainland social media
NoSpace is Gen Z’s answer to MySpace
What if customers were rewarded for tipping their meal delivery drivers?
Reddit CEO beneficially owns 61.5% of class A shares, regulatory filing shows
Exclusive-Stanford AI leader Fei-Fei Li building 'spatial intelligence' startup
Tech platforms make pitch for ad deals as TikTok is roiled by politics
Intesa targets new digital-only clients after antitrust blow
Paramount will let exclusive talks with Skydance lapse

Others Also Read