• News/
  • https://www.theregister.com/2025/04/09/occ_bank_email_hack/

Someone compromised US bank watchdog to access sensitive financial files

The Register
·
Iain Thomson
·
Published Apr 9, 2025
·
Updated

A US banking regulator says sensitive financial oversight data was accessed by one or more system intruders for more than a year in what's been described as "a major information security incident." The Office of the Comptroller of the Currency (OCC), the Treasury Department bureau that oversees US and foreign banks, said one of its administrative email accounts - with access to user inboxes and internal systems - was compromised, leading to data falling into the wrong hands. The security breach came to light on February 11, when Microsoft tipped off the OCC about suspicious activity within its email accounts. The agency confirmed the next day someone had gained unauthorized access. A public notice followed weeks later, and only now is the scale of the intrusion beginning to surface. According to the bureau, snoops accessed "highly sensitive information relating to the financial condition of federally regulated financial institutions used in its examinations and supervisory oversight processes." The compromised admin account was disabled on February 12, the day the security breach was confirmed, and third-party forensics teams have been brought in to assess the fallout. "The OCC learned of the unauthorized access to its email system on February 11, the day after Acting Comptroller Rodney Hood was sworn into office," a spokesperson told The Register Wednesday. "The agency then moved quickly to determine the breadth of the access. "On February 25, Acting Comptroller Hood receive...

Read full article

Affected Software

2 affected components
Microsoft Email system
Microsoft Email
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a major security incident involving the compromise of a US banking regulator's email system, leading to unauthorized access to sensitive financial files.

2

What security implications are discussed?

The incident highlights vulnerabilities within financial regulatory oversight and raises concerns regarding the protection of sensitive financial data.

3

How long did the intruders have access to the data?

The unauthorized access to sensitive financial oversight data lasted for over a year.

4

Which software or systems were primarily affected?

The Microsoft Email system used by the Office of the Comptroller of the Currency was primarily affected by the breach.

5

What actions are being taken in response to the security incident?

The banking regulator is likely implementing enhanced security measures and conducting a thorough investigation to prevent future breaches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203