Citi Says 360,000 Card Accounts — Not 200,000 — Were Hacked

Citigroup Inc. clarified the timeline and updated the number of accounts breached in a recent hacker attack that put an estimated 1% of its North American Citi-branded credit card base at risk.

Citi said that 360,083 credit card accounts were affected, and that it re-issued cards to 217,657 of those accounts. The others had been closed or were already in the process of having cards reissued for other reasons. The open accounts that did not get new cards are receiving enhanced monitoring, Citi said.

Citi previously indicated only about 200,000 accounts were impacted, and that those affected were 1% of its total North American card base, cited as 21 million on June 9, when Citi announced the break in. Citi said Thursday that it actually has 23.5 million card accounts in North America.

Citi also countered claims that it waited too long before responding to the break-in. Citi said the breach occurred on May 10, and that it discovered the intrusion as part of routine maintenance.

Citi said it identified the majority of accounts affected within seven days, and by May 24 it confirmed the full extent of information accessed and began preparing notification packages with replacement cards, as well as informing customer service teams. It began mailing notification letters June 3, the majority of which included reissued credit cards.

Citi said in an emailed statement that it placed internal fraud alerts and enhanced monitoring on all accounts deemed at risk, while simultaneously conducting "rigorous analysis … to determine the precise accounts and type of information accessed."

This process "required analysis of millions of pieces of data," Citi said.

The bank stressed that customer names, account numbers, contact information and email addresses were viewed by hackers. Social Security numbers, dates of birth, card expiration dates and the card security codes were not.

The incident affected the Citi Account Online network, but the bank's main card processing system and its systems for consumer online banking were unaffected.

For reprint and licensing requests for this article, click here.
Bank technology
MORE FROM AMERICAN BANKER