- Key insight: Jack Henry said it was extorted and that it will not pay. The hackers' deadline then passed without the stolen data appearing.
- What's at stake: The account holder count is unknown, because "fewer than 10 clients" counts institutions rather than people.
- Supporting data: Financial services companies paid ransomware extortionists roughly $365.6 million across 432 incidents from January 2022 through December 2024, more money than any other industry, according to Fincen.
Overview bullets generated by AI with editorial review.
Jack Henry suffered a data breach and recently refused to pay the criminal group that stole personal information belonging to customers of the banks and credit unions it serves.
"This incident involved an extortion attempt, and we are not making any payment to the threat actor," reads
ShinyHunters, the threat actor Jack Henry named in its statement, had listed the company on its data leak site days earlier. The group's post gave the company until Tuesday to make contact "before we leak along with several annoying (digital) problems that'll come your way."
That deadline passed, and as of Wednesday, ShinyHunters still had not published files.
Jack Henry runs the core account and transaction systems on which more than 1,600 banks and credit unions operate, and it sells other products to about 5,600 more clients, according to its most recent
It is one of the
Personal information belonging to account holders at fewer than 10 client institutions got exposed, according to Jack Henry's Monday statement. That figure counts institutions rather than people; the company has not said how many individuals had information taken.
A Jack Henry spokesperson did not immediately answer American Banker's questions about the incident.
Jack Henry also has not said what kinds of information the intruders took, when the intrusion happened, when it discovered the breach, or whether the affected clients are banks, credit unions or both. Its statement says only that it "recently detected" the incident.
Jack Henry notified all of its more than 7,200 clients and is working directly with the affected ones, according to the Monday statement.
The company is also offering two years of credit monitoring "to impacted financial institutions to provide to their accountholders," according to the statement.
How Jack Henry got hacked
The intrusion started with a phone call, not a software flaw.
It "began with a sophisticated social engineering attack commonly known as vishing (voice phishing) initiated by a threat actor identified as ShinyHunters," according to the statement.
The intrusion reached "a limited portion of our internal, non-production corporate environment," the company said. No client-facing systems, core platforms or daily processing services were accessed or disrupted, and there were no outages, according to the statement.
ShinyHunters has run this same playbook on the financial industry for more than a year; it took data on 4.4 million people from the credit bureau
Read more:
OCC and FDIC finalize narrower bank supervision procedures As education costs rise, credit unions chip in for employees A $111 million scheme to keep bad merchants banked
What banks and credit unions need to do
Jack Henry does not have to tell account holders their information got taken. Its clients do.
Where unauthorized access involves systems a service provider maintains, "it is the responsibility of the financial institution to notify the institution's customers and regulator," according to the
Which federal reporting rule applies depends on whether the client is a bank or a credit union, and Jack Henry has not said which its affected clients are.
Under a
For credit unions,
A federally insured credit union then has 72 hours to tell the National Credit Union Administration.
Jack Henry serves more than 700 credit unions, roughly one in six nationally, according to its most recent annual report.
Those clocks do not start when the breach occurs. The rules vary, but many of them start the clock when a financial institution "reasonably believes" or "determines" that a reportable incident has occurred. The clock can also start when a third party notifies the financial institution of an incident.
An institution that has been told an incident occurred but not whether its own account holders were caught in it has not necessarily reached either point. Jack Henry's statements about the incident do not indicate whether the notification clock has started for any bank or credit union.
What makes this extortion notable
In the past, ShinyHunters has followed through on threats to publish stolen data; in February, the group published data on nearly 1 million customers of the blockchain lender Figure Technology Solutions.
Few companies that disclose extortionist cyberattacks publicly acknowledge whether they paid up, making Jack Henry's public refusal notable.
The federal government discourages paying cyber-extortionists. A
Despite the recommendations, financial services companies paid ransomware extortionists roughly $365.6 million across 432 incidents from January 2022 through December 2024, according to a
That was the most money of any industry in the report.











