FinAi News

No products in the cart.

Subscribe
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
Log In
No Result
View All Result
  • Banking
  • Lending
  • Payments
  • Risk & Security
  • Strategy
FinAi News
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
BAN PLUS
Log In
No Result
View All Result
FinAi News
No Result
View All Result

US bank regulator didn’t have safeguard on hacked email account

Attackers spied on more than 100 bank regulators’ emails

Bloomberg NewsbyBloomberg News
April 11, 2025
in Risk & Security
Reading Time: 2 mins read
0
Share on Facebook

The U.S. Office of the Comptroller of the Currency didn’t have a basic protection enabled on an email account hackers exploited to spy on the messages of more than 100 bank regulators for over a year, according to two people familiar with the matter.

If multifactor authentication had been turned on it likely would have stopped the attackers, who accessed roughly 150,000 emails from May 2023 until they were discovered and ousted earlier this year, the people said. They asked not to be identified because the information about the hack isn’t public.

email
(Courtesy/Al Drago/Bloomberg)

Multifactor authentication is a basic cybersecurity tool that requires users to verify their identity in two or more ways before accessing an account. In 2022, the U.S. Cybersecurity and Infrastructure Security Agency urged organizations to implement multifactor authentication for all users and services.

An OCC spokesperson, Carrie Moore, declined to comment.

The OCC is an independent bureau of the Treasury Department that regulates and supervises all national banks, federal savings associations, and the federal branches and agencies of foreign banks — together holding trillions of dollars in assets. The agency on Tuesday notified Congress about the compromise, describing it as a “major information security incident,” Bloomberg News previously reported.

The hackers broke into the agency’s emails by guessing the password of an administrator’s account in a technique called a password spray attack, the people said. That account was left over from when the agency changed its emails to a cloud-based Microsoft Corp. system, they said.

David P. Weber, who spent a decade as special counsel for enforcement at OCC, said the agency has required multifactor authentication on its systems since about 2005.

“It is shocking that they did not have it enabled for this administrative account,” said Weber, a professor of fraud and forensic accounting at Salisbury University. He said the OCC’s emails would be an attractive target for hackers with a foreign government that has state-owned banks operating in the US.

It’s unclear who is responsible for the breach at OCC. The hackers penetrated the mailboxes of senior deputy comptrollers, international banking supervisors and other staff, Bloomberg previously reported.

“The OCC is also launching an immediate and thorough evaluation of its current IT security policies and procedures to improve its ability to prevent, detect and remediate potential security incidents going forward,” OCC Chief Information Officer Kristen Baldwin wrote in the draft letter to Congress that was seen by Bloomberg News.

Tags: PremiumU.S. Cybersecurity and Infrastructure Security Agency (CISA)U.S. Office of the Comptroller of the Currency (OCC)
Previous Post

Citi, Valley Bank tap fintechs for innovation

Next Post

CommerzBank ups efficiency 66% with admin gen AI tool

Related Posts

Cisco logo on a wall of lights
Risk & Security

Cisco clients spend more on security to prepare for Mythos, quantum

August 13, 2026
digital globe surrounded by interconnected data streams
Risk & Security

FIs cannot rely solely on legacy systems for cybersecurity

August 12, 2026
Cybersecurity locks among multiple data points
Risk & Security

AI forges ‘double-edged sword’ in bank cybersecurity

August 11, 2026
Next Post
(Courtesy/Bloomberg)

CommerzBank ups efficiency 66% with admin gen AI tool

EMERGING FINTECH DIRECTORY

Emerging Fintech Directory

FinAi Podcast

SPONSORED

Build an Antifragile Strategy to Outperform the Market

July 14, 2026

How AI and Product Experts Turn Fuzzy Requirements Into Focused Dev-ready Roadmaps

April 19, 2026

Is Your Technology Supplier There for You?

April 1, 2026

  • About Us
  • Help Center
  • Contact Us
  • Privacy Terms
  • ADA Compliance
  • Advertise

Connect

twitter linkedin podcast podcast podcast podcast
© 2026 Royal Media
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Unlock This Article

Create your free FinAi News account to access this article and stay informed on how AI is transforming financial services including banking, lending, payments, and risk.

Yes, I'd like to receive FinAi News updates, breaking news, and exclusive AI insights for financial services leaders.

Continue Reading with FinAi News Premium - Less than $2/Day

Upgrade to FinAi News Premium for unlimited access to news, insights, trends, and intelligence on how AI is transforming financial services including banking, lending, payments, and risk.
Upgrade to FinAi News Premium Subscription
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account