started · updated
Jack Henry suffers ransomware attack via voice phishing
Jack Henry, a major US provider of technological infrastructure for the banking sector, has experienced a ransomware attack initiated through social engineering and voice phishing (vishing). The hacking group responsible for the breach has been identified as ShinyHunters, a group active since 2019 known for large-scale attacks.
While the company's core banking systems and client-facing platforms remain secure and uninterrupted, the attackers successfully stole personal data related to ten of the company's 7,200 client banks. The intrusion was achieved by deceiving employees via fraudulent phone calls rather than through a technical software vulnerability.
Jack Henry stated that it has not paid a ransom to the attackers and is currently working with law enforcement and conducting investigations. The company is offering two years of credit monitoring to those affected by the data theft.