Jack Henry Contains Cyberattack by ShinyHunters, Limits PII Exposure

  • Jack Henry detected a cybersecurity incident in a non-production corporate environment, with PII data for fewer than 10 clients impacted.
  • The attack, attributed to threat actor ShinyHunters, began with a vishing (voice phishing) social engineering scheme.
  • No client-facing systems or core platforms were compromised, and the company is offering two years of credit monitoring to affected clients.
  • Jack Henry is not making any payment to the extortionist and has deemed the incident financially immaterial.

The incident underscores the growing threat of social engineering attacks in the fintech sector, particularly vishing schemes targeting internal systems. While Jack Henry's containment efforts appear robust, the broader challenge remains managing client trust amid an escalating cyber threat landscape. The company's ability to sustain operational integrity will be critical as financial institutions increasingly rely on third-party tech providers for core services.

Incident Containment
How Jack Henry's rapid response framework will be tested in preventing future breaches.
Regulatory Scrutiny
Whether the incident will attract heightened oversight from financial regulators.
Client Trust
The pace at which Jack Henry can restore full confidence among its 7,200+ clients.