Bank of America has alerted its customers about a recent data breach that occurred through one of its service providers, Infosys McCamish Systems (IMS), last year.
The breach has reportedly exposed personal information of individuals, including names, addresses, social security numbers, dates of birth and financial details such as account and credit card numbers.
Bank of America serves approximately 69 million clients at over 3,800 retail financial centers and through approximately 15,000 ATMs in the United States, its territories, and more than 35 countries.
The bank has not disclosed the exact number of affected customers. However, a recent notification letter from IMS to the Attorney General of Maine on behalf of Bank of America indicated that approximately 57,028 individuals were directly impacted.
IMS reported that the breach occurred around November 3 2023, when unauthorized access was gained to their systems, affecting specific applications.
IMS told Bank of America that data concerning deferred compensation plans serviced by Bank of America may have been compromised. Bank of America’s systems were not compromised.
The breach was allegedly orchestrated by the LockBit ransomware gang, who claimed responsibility in November last year for encrypting over 2000 systems during the attack.
LockBit has been active since September 2019 and has targeted numerous high-profile organizations worldwide, including governmental bodies and large corporations.
Bank of America customers’ financial account information, credit card, social security, and/or other unique government-issued identification numbers handled by leading accounting firm Ernst & Young were also exposed after the service provider’s MOVEit Transfer platform got breached in May 2023 by the Clop cybercrime gang.
However, on that occasion, Ernst & Young assured that Bank of America’s systems were not affected by the breach.















Comments