美国银行争分夺秒评估数据盗窃事件,此前黑客攻击了一家金融科技公司。
US banks scramble to assess data theft after hackers breach financial tech firm

原始链接: https://techcrunch.com/2025/11/24/us-banks-scramble-to-assess-data-theft-after-hackers-breach-financial-tech-firm/

金融科技公司SitusAMC近期在11月12日遭遇数据泄露,可能影响到包括摩根大通、花旗银行和摩根士丹利在内的多家美国大型银行。黑客据称窃取了与SitusAMC银行客户相关的数据,包括会计记录和法律协议,重点是数据*外泄*,而非系统破坏。 虽然此次泄露的完整范围仍在调查中,目前数据泄露量尚不清楚,但SitusAMC表示事件已得到控制,系统正在运行。该公司为超过一千家金融机构提供服务,每年处理数十亿份贷款文件,使其成为金融系统至关重要但常常不为人所见的组成部分。 联邦调查局正在调查此案,确认目前对银行服务没有运营影响,并正在努力确定责任人。受影响的银行正在评估客户数据泄露的程度。

## 美国银行面临数据盗窃恐慌 金融科技公司SitusAMC最近的一次数据泄露,引发了包括摩根大通、花旗银行和摩根士丹利在内的美国银行评估潜在数据盗窃的紧急行动。该事件凸显了金融行业持续存在的安全漏洞问题。 Hacker News上的讨论显示,用户对许多银行提供的有限安全选项感到沮丧。用户报告称,银行的密码要求较低(长度短、字符受限),并且依赖于不安全的短信多因素认证(MFA),而更安全的选项,如硬件令牌(YubiKey、FIDO),很少得到支持。 虽然这次泄露可能针对的是核心基础设施而非个人账户,但过去泄露事件积累的个人数据,引发了对账户安全的担忧。最近的法规*要求*使用MFA,但允许使用较不安全的电子邮件/短信等方式。一些机构,如先锋集团和某些信用社,正在率先采用更好的选项,如TOTP,但更广泛的应用仍然是必要的。一种观点是,银行优先考虑避免欺诈,而不是主动提高安全性,并且目前依赖于容易获取的个人信息的身份验证方法存在根本缺陷。
相关文章

原文

Several U.S. banking giants and mortgage lenders are reportedly scrambling to assess how much of their customers’ data was stolen during a cyberattack on a New York financial technology company earlier this month.

SitusAMC, which provides technology for over a thousand commercial and real estate financiers, confirmed in a statement over the weekend that it had identified a data breach on November 12.

The company said that unspecified hackers had stolen corporate data associated with its banking customers’ relationship with SitusAMC, as well as “accounting records and legal agreements” during the cyberattack. 

The statement added that the scope and nature of the cyberattack “remains under investigation.” SitusAMC said that the incident is “now contained,” and that its systems are operational. The company said that no encrypting malware was used, suggesting that the hackers were focused on exfiltrating data from the company’s systems rather than causing destruction.

According to Bloomberg and CNN, citing sources, SitusAMC sent data breach notifications to several financial giants, including JPMorgan Chase, Citigroup, and Morgan Stanley. SitusAMC also counts pension funds and state governments as customers, according to its website.

It’s unclear how much data was taken, or how many U.S. banking consumers may be affected by the breach. Companies like SitusAMC may not be widely known outside of the financial world, but provide the mechanisms and technologies for its banking and real estate customers to comply with state and federal rules and regulations. In its role as a middleman for financial clients, the company handles vast amounts of non-public banking information on behalf of its customers. 

According to SitusAMC’s website, the company processes billions of documents related to loans annually. 

When reached by TechCrunch, Citi spokesperson Patricia Tuma declined to comment on the breach. Tuma would not say if the bank has received any communications from the hackers, such as a demand for money.

Representatives for JPMorgan Chase, and Morgan Stanley did not immediately respond to a request for comment Monday. SitusAMC chief executive Michael Franco also did not respond to our email when contacted for comment Monday.

A spokesperson for the FBI told TechCrunch that the bureau is aware of the breach.

“While we are working closely with affected organizations and our partners to understand the extent of potential impact, we have identified no operational impact to banking services,” said FBI director Kash Patel in a statement shared with TechCrunch. “We remain committed to identifying those responsible and safeguarding the security of our critical infrastructure.”

Do you know more about the SitusAMC data breach? Do you work at a bank or financial institution affected by the breach? We would love to hear from you. To securely contact this reporter, you can reach out using Signal via the username: zackwhittaker.1337

联系我们 contact @ memedata.com