A US banking regulator says sensitive financial oversight data was accessed by one or more system intruders for more than a year in what's been described as "a major information security incident." The Office of the Comptroller of the Currency (OCC), the Treasury Department bureau that oversees US and foreign banks, said one of its administrative email accounts - with access to user inboxes and internal systems - was compromised, leading to data falling into the wrong hands. The security breach came to light on February 11, when Microsoft tipped off the OCC about suspicious activity within its email accounts. The agency confirmed the next day someone had gained unauthorized access. A public notice followed weeks later, and only now is the scale of the intrusion beginning to surface. According to the bureau, snoops accessed "highly sensitive information relating to the financial condition of federally regulated financial institutions used in its examinations and supervisory oversight processes." The compromised admin account was disabled on February 12, the day the security breach was confirmed, and third-party forensics teams have been brought in to assess the fallout. "The OCC learned of the unauthorized access to its email system on February 11, the day after Acting Comptroller Rodney Hood was sworn into office," a spokesperson told The Register Wednesday. "The agency then moved quickly to determine the breadth of the access. "On February 25, Acting Comptroller Hood receive...
Someone compromised US bank watchdog to access sensitive financial files
The Register
·Iain Thomson
·Published Apr 9, 2025
·Updated
Affected Software
2 affected components
Microsoft Email system
Microsoft Email
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a major security incident involving the compromise of a US banking regulator's email system, leading to unauthorized access to sensitive financial files.
2
What security implications are discussed?
The incident highlights vulnerabilities within financial regulatory oversight and raises concerns regarding the protection of sensitive financial data.
3
How long did the intruders have access to the data?
The unauthorized access to sensitive financial oversight data lasted for over a year.
4
Which software or systems were primarily affected?
The Microsoft Email system used by the Office of the Comptroller of the Currency was primarily affected by the breach.
5
What actions are being taken in response to the security incident?
The banking regulator is likely implementing enhanced security measures and conducting a thorough investigation to prevent future breaches.