OCC announces major information security incident

Orrick, Herrington & Sutcliffe LLP
Contact

Orrick, Herrington & Sutcliffe LLP

On April 8, the OCC announced it had notified Congress of a major information security incident, as required by the Federal Information Security Modernization Act. The incident involved unauthorized access to emails and their attachments, which contained highly sensitive information about the financial condition of federally regulated financial institutions used in the OCC’s examinations and supervisory oversight processes. The agency’s findings came from independent third-party reviews of the OCC’s data.

According to the OCC, it first learned of unusual interactions between a system administrative account and OCC user mailboxes on February 11. The agency took immediate steps to disable the compromised administrative accounts and initiated an independent third-party incident assessment to address the breach and its underlying causes. The OCC confirmed the activity was unauthorized on February 12 and first reported the security incident publicly on February 26.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Orrick, Herrington & Sutcliffe LLP

Written by:

Orrick, Herrington & Sutcliffe LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Orrick, Herrington & Sutcliffe LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide