Jack Henry refuses to pay extortionists after data theft

Stuttgart, Germany - 07-29-2023: Person holding smartphone with logo of US financial company Jack Henry Associates Inc. on screen in front of website. Focus on phone display.
Adobe Stock
  • Key insight: Jack Henry said it was extorted and that it will not pay. The hackers' deadline then passed without the stolen data appearing.
  • What's at stake: The account holder count is unknown, because "fewer than 10 clients" counts institutions rather than people.
  • Supporting data: Financial services companies paid ransomware extortionists roughly $365.6 million across 432 incidents from January 2022 through December 2024, more money than any other industry, according to Fincen.

Overview bullets generated by AI with editorial review.

Processing Content

Jack Henry suffered a data breach and recently refused to pay the criminal group that stole personal information belonging to customers of the banks and credit unions it serves.

"This incident involved an extortion attempt, and we are not making any payment to the threat actor," reads a Monday statement from the company.

ShinyHunters, the threat actor Jack Henry named in its statement, had listed the company on its data leak site days earlier. The group's post gave the company until Tuesday to make contact "before we leak along with several annoying (digital) problems that'll come your way."

That deadline passed, and as of Wednesday, ShinyHunters still had not published files.

Jack Henry runs the core account and transaction systems on which more than 1,600 banks and credit unions operate, and it sells other products to about 5,600 more clients, according to its most recent annual report.

It is one of the three largest core providers, which together served more than 70% of U.S. depository institutions in 2022, according to a request for information the Office of the Comptroller of the Currency issued in November 2025.

Personal information belonging to account holders at fewer than 10 client institutions got exposed, according to Jack Henry's Monday statement. That figure counts institutions rather than people; the company has not said how many individuals had information taken.

A Jack Henry spokesperson did not immediately answer American Banker's questions about the incident.

Jack Henry also has not said what kinds of information the intruders took, when the intrusion happened, when it discovered the breach, or whether the affected clients are banks, credit unions or both. Its statement says only that it "recently detected" the incident.

Jack Henry notified all of its more than 7,200 clients and is working directly with the affected ones, according to the Monday statement.

The company is also offering two years of credit monitoring "to impacted financial institutions to provide to their accountholders," according to the statement.

How Jack Henry got hacked

The intrusion started with a phone call, not a software flaw.

It "began with a sophisticated social engineering attack commonly known as vishing (voice phishing) initiated by a threat actor identified as ShinyHunters," according to the statement.

Vishing means a caller impersonating someone the target trusts (often internal tech support) to talk them into handing over credentials.

The intrusion reached "a limited portion of our internal, non-production corporate environment," the company said. No client-facing systems, core platforms or daily processing services were accessed or disrupted, and there were no outages, according to the statement.

ShinyHunters has run this same playbook on the financial industry for more than a year; it took data on 4.4 million people from the credit bureau TransUnion in August 2025, then it hit the robo-advisor Betterment and the lender Figure early this year.

Read more:

What banks and credit unions need to do

Jack Henry does not have to tell account holders their information got taken. Its clients do.

Where unauthorized access involves systems a service provider maintains, "it is the responsibility of the financial institution to notify the institution's customers and regulator," according to the interagency guidance carrying the Gramm-Leach-Bliley Act's information security standards.

Which federal reporting rule applies depends on whether the client is a bank or a credit union, and Jack Henry has not said which its affected clients are.

Under a 2021 rule, a bank has 36 hours to tell its primary federal regulator once it determines an incident materially disrupted or degraded its ability to carry out banking operations.

For credit unions, federal regulation defines a reportable incident as including unauthorized access to sensitive data caused by a compromise of a third-party data hosting provider — no service disruption required.

A federally insured credit union then has 72 hours to tell the National Credit Union Administration.

Jack Henry serves more than 700 credit unions, roughly one in six nationally, according to its most recent annual report.

Those clocks do not start when the breach occurs. The rules vary, but many of them start the clock when a financial institution "reasonably believes" or "determines" that a reportable incident has occurred. The clock can also start when a third party notifies the financial institution of an incident.

An institution that has been told an incident occurred but not whether its own account holders were caught in it has not necessarily reached either point. Jack Henry's statements about the incident do not indicate whether the notification clock has started for any bank or credit union.

What makes this extortion notable

In the past, ShinyHunters has followed through on threats to publish stolen data; in February, the group published data on nearly 1 million customers of the blockchain lender Figure Technology Solutions.

Few companies that disclose extortionist cyberattacks publicly acknowledge whether they paid up, making Jack Henry's public refusal notable.

The federal government discourages paying cyber-extortionists. A Treasury Department advisory says the U.S. government "strongly discourages all private companies and citizens from paying ransom or extortion demands."

Guidance jointly distributed in 2023 by the FBI and two other federal agencies warns that paying a ransom "will not ensure your data is decrypted, that your systems or data will no longer be compromised, or that your data will not be leaked."

Despite the recommendations, financial services companies paid ransomware extortionists roughly $365.6 million across 432 incidents from January 2022 through December 2024, according to a December 2025 report from the Financial Crimes Enforcement Network.

That was the most money of any industry in the report.


For reprint and licensing requests for this article, click here.
Cyber Security Data security Credit unions Regulation and compliance Core systems Technology
MORE FROM AMERICAN BANKER
Load More