Bank of America at gunpoint: Infosys opens the door to cybercriminals

Teacher

Professional
Messages
2,670
Reaction score
814
Points
113
Hackers were especially interested in retirement savings…

In November 2023, the Indian company Infosys, one of the world's largest software vendors, caused a large-scale data leak affecting Bank of America customers. According to an official statement released on November 3 , Infosys ' U.S. division, Infosys McCamish Systems LLC (IMS), experienced a major incident that temporarily disabled critical systems and applications.

In official reports, the problem is designated as an "external security breach", which confirms the fact of a hacker attack. From a notice filed with the Maine state Administration, it became known that hackers managed to gain access to data including the names, social security numbers and other personal identifiers of almost 60 thousand people.

The incident attracted particular attention, as it also affected deferred compensation plans serviced by Bank of America. At the same time, it is emphasized that the bank's own systems were not directly hacked.

In other words, the leak covered almost everything a fraudster might need to commit identity theft – a highly likely outcome of this event, since the term "deferred compensation plan" describes private pensions, savings, and incentive stock options.

The term also refers to payments under death insurance policies, with IMS serving as Infosys ' key center of expertise in life insurance software solutions and services in the United States.

The situation became more complicated after reports emerged that a well-known group of cybercriminals using the LockBit extortion software may be behind the attack. This assumption added to the severity of the incident, given the power and danger of this type of malware.

Victims were offered standard security measures, including password changes and account monitoring, as well as a two-year identity theft protection program from Experian. The situation once again underlines the importance of cybersecurity and the need for a comprehensive approach to personal data protection.

Infosys has not yet provided official comments on the incident.
 
Top