← Case Files · The Breach Files
JPMorgan Chase, 2014: one server without two-factor authentication
- People affected
- 76 million households and 7 million small businesses
- When it happened
- June – August 2014
- Made public
- 2 October 2014
- How they got in
- Stolen employee credentials used against a server that had not been upgraded to two-factor authentication
- Attributed to
- Gery Shalon, Ziv Orenstein and Joshua Samuel Aaron, indicted in 2015; guilty pleas followed in 2020
- What it cost
- No customer financial losses reported; the intrusion supported a securities fraud scheme prosecutors valued in the hundreds of millions
What was exposed: Names · Addresses · Phone numbers · Email addresses · Internal customer categorisation
JPMorgan Chase spent around a quarter of a billion dollars a year on cybersecurity and employed roughly a thousand people to do it. In 2014, attackers walked in through a server that had been missed during the rollout of two-factor authentication, and left with contact details for 83 million households and businesses.
What happened
The bank had been extending two-factor authentication across its remote access infrastructure — a programme every large financial institution was running at the time and precisely the right control for the threat. The programme was essentially complete.
One server had not been upgraded. It still accepted a username and password alone.
Attackers obtained the credentials of a JPMorgan employee, found the server that would accept them without a second factor, and were inside. Between June and August 2014 they moved through the internal network, reaching more than ninety servers and eventually a database holding customer contact information. The bank detected the intrusion in July and August and disclosed it in a regulatory filing on 2 October.
The scale was unprecedented for a US bank: 76 million households and 7 million small businesses. Names, addresses, phone numbers, email addresses, and internal information about which products a customer held. No account numbers, no passwords, no Social Security numbers, no money moved.
Coverage, not capability, is the usual failure. Almost no large breach happens because a security control does not exist. They happen because a control exists in 99% of the estate. The missing 1% is a server nobody owns, a subsidiary acquired last year, a test environment that was supposed to be temporary, or a device that broke when the agent was installed and was quietly exempted. Attackers do not need to find the average state of your security. They need to find the exception, and they only have to be right once.
Why contact details were the objective
The prosecution that followed reframed the breach entirely. In November 2015 US prosecutors indicted Gery Shalon, Ziv Orenstein and Joshua Samuel Aaron, describing a sprawling criminal enterprise that included illegal online casinos, unlicensed payment processing, and a large securities fraud operation.
The stock fraud is where JPMorgan fits. The scheme worked by buying thinly traded shares, promoting them aggressively to retail investors, and selling into the price rise. The limiting factor in that business is the quality of the mailing list. A random list is mostly wasted. A list of people confirmed to hold accounts at America's largest bank, with real names and real addresses, converts at a rate that makes the whole operation viable.
Prosecutors characterised it as one of the largest thefts of customer data from a US financial institution, carried out to support market manipulation. The data was not the crime. It was the tooling.
The timeline
- June 2014 — Attackers use stolen employee credentials against a server lacking two-factor authentication.
- June – August 2014 — Movement through the internal network; contact data for 83 million households and businesses is taken.
- July – August 2014 — JPMorgan detects the intrusion and begins remediation.
- 2 October 2014 — The bank files an 8-K disclosing the scale.
- November 2015 — Three men are indicted; prosecutors describe the wider fraud enterprise.
- 2016 – 2018 — Extradition and proceedings run in the US and Israel.
- 2020 — Guilty pleas are entered in the Southern District of New York.
What it changed
Financial regulators stopped treating security as an IT matter. New York's Department of Financial Services introduced its cybersecurity regulation in 2017, requiring named accountability, multi-factor authentication, and annual certification by a senior officer. JPMorgan is not the only reason, but a breach of this size at this institution made the political case unanswerable.
Asset inventory became a regulated control rather than good housekeeping. "How do you know the control is deployed everywhere" turned into a question examiners ask, with evidence expected. Continuous configuration monitoring — checking that every server still has the agent, the patch and the authentication requirement — grew directly out of failures of this shape.
It complicated the story about spending. The bank's security budget had been cited publicly as evidence of seriousness. After 2014 that argument was much harder to make anywhere, and attention moved towards demonstrating coverage and effectiveness instead of investment.
Breached data got understood as an input to other crimes. The prosecution laid out a full pipeline: steal the list, run the fraud, launder the proceeds. It is now the default assumption. Data taken in one breach reliably shows up as the targeting material for the next scheme.
What to take from it
- Audit for the exception, not the rule. The security question worth asking is not "do we require MFA" but "list every system that currently accepts a password alone".
- Contact data is not low-sensitivity data. Knowing where someone banks, alongside their name and address, is enough to make a fraudulent approach credible.
- Unsolicited investment tips that arrive by post, email or message are a documented crime pattern. The list you are on was probably assembled from a breach.
- Your bank will never ask you to verify details on a call it initiated. Attackers holding a list like this one make exactly that call.
Questions people ask
Was any money stolen from JPMorgan customers?
No. The bank stated that account numbers, passwords, dates of birth and Social Security numbers were not taken and that it saw no unusual fraud against customer accounts. What was taken was contact information for 83 million households and businesses — which was, for these particular attackers, the more valuable asset.
Why would criminals want contact details from a bank?
Because prosecutors said they were running pump-and-dump stock fraud. A list of people known to hold accounts at a major bank, complete with names and addresses, is a pre-qualified target list for investment spam — vastly more effective than a random mailing list. The breach was an input to a securities fraud operation rather than an end in itself.
How did one missed server cause this?
JPMorgan had been rolling out two-factor authentication across its remote access infrastructure. One server was overlooked. When attackers obtained an employee's credentials, that server accepted the password alone, and from that foothold they moved through the internal network over roughly two months. Security controls are only as good as their coverage, and coverage gaps are the normal state of any large estate.
Did JPMorgan face a fine?
No significant regulatory penalty followed in the US, where there was then no general federal breach standard covering this kind of contact data. The consequence was reputational and political: the bank's chief executive had publicly described its security spending, which made the single missed server an uncomfortable illustration that budget is not the constraint.
Sources
- JPMorgan Chase & Co. Form 8-K, 2 October 2014
- US Department of Justice — indictment of Gery Shalon, Joshua Samuel Aaron and Ziv Orenstein, November 2015
- Securities and Exchange Commission complaint in the related securities fraud matter, 2015
- Guilty pleas entered in the Southern District of New York, 2020
Read next
Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.