The U.S. Office of the Comptroller of the Currency didn’t have a basic protection enabled on an email account hackers exploited to spy on the messages of more than 100 bank regulators for over a year, according to two people familiar with the matter.
If multifactor authentication had been turned on it likely would have stopped the attackers, who accessed roughly 150,000 emails from May 2023 until they were discovered and ousted earlier this year, the people said. They asked not to be identified because the information about the hack isn’t public.

Multifactor authentication is a basic cybersecurity tool that requires users to verify their identity in two or more ways before accessing an account. In 2022, the U.S. Cybersecurity and Infrastructure Security Agency urged organizations to implement multifactor authentication for all users and services.
An OCC spokesperson, Carrie Moore, declined to comment.
The OCC is an independent bureau of the Treasury Department that regulates and supervises all national banks, federal savings associations, and the federal branches and agencies of foreign banks — together holding trillions of dollars in assets. The agency on Tuesday notified Congress about the compromise, describing it as a “major information security incident,” Bloomberg News previously reported.
The hackers broke into the agency’s emails by guessing the password of an administrator’s account in a technique called a password spray attack, the people said. That account was left over from when the agency changed its emails to a cloud-based Microsoft Corp. system, they said.
David P. Weber, who spent a decade as special counsel for enforcement at OCC, said the agency has required multifactor authentication on its systems since about 2005.
“It is shocking that they did not have it enabled for this administrative account,” said Weber, a professor of fraud and forensic accounting at Salisbury University. He said the OCC’s emails would be an attractive target for hackers with a foreign government that has state-owned banks operating in the US.
It’s unclear who is responsible for the breach at OCC. The hackers penetrated the mailboxes of senior deputy comptrollers, international banking supervisors and other staff, Bloomberg previously reported.
“The OCC is also launching an immediate and thorough evaluation of its current IT security policies and procedures to improve its ability to prevent, detect and remediate potential security incidents going forward,” OCC Chief Information Officer Kristen Baldwin wrote in the draft letter to Congress that was seen by Bloomberg News.






