Click to Skip Ad
Closing in...

This might be the most important thing hackers stole during massive JPMorgan Chase attack

Published Oct 6th, 2014 6:50AM EDT
BGR

If you buy through a BGR link, we may earn an affiliate commission, helping support our expert product labs.

JPMorgan Chase last week confirmed that hackers managed to access personal data for more than 83 million customers, including 76 million households and seven million small-business online accounts, but The New York Times reveals that the largest bank in the U.S. isn’t the only one to have been hit. It appears that other nine, unnamed, financial institutions have also been targeted by the same mysterious hackers group, which also managed to steal some critical security data from JPMorgan on top of personal data.

FROM EARLIER: Massive JPMorgan Chase hack impacted more than 80 million accounts

Hackers were apparently able to access only names, addresses, phone numbers and email addresses for compromised accounts, but did not get actual financial information, or social security numbers. Furthermore, they were able to determine whether the accounts were private bank accounts or fell in other business categories such as mortgages.

The Times also says that it’s not clear why hackers chose to hunt for customer information rather than go for financial data, with JPMorgan revealing that it has not received any reports related to the massive data breach detailing fraudulent use of customers’ data.

What’s clear is that hackers were apparently able to access 90 servers in JPMorgan’s computer network completely undetected for several weeks. In addition to personal customer data, hackers gained access to something more valuable — a list of every application and program the bank uses to protect its servers — which could let them perform similar attacks in the future by taking advantage of potential security flaws in those programs.

“It’s as if they stole the schematics to the Capitol — they can’t just switch out every single door and window pane overnight,” one former employee said.

For JPMorgan, “swapping out those programs is costly and time-consuming, people say, because the bank would have to renegotiate licensing deals with technology suppliers and swap out programs and applications for hundreds of thousands of bank employees,” as the Times reports.

Chris Smith Senior Writer

Chris Smith has been covering consumer electronics ever since the iPhone revolutionized the industry in 2008. When he’s not writing about the most recent tech news for BGR, he brings his entertainment expertise to Marvel’s Cinematic Universe and other blockbuster franchises.

Outside of work, you’ll catch him streaming almost every new movie and TV show release as soon as it's available.