OCC provides an update on its security breach given institutional risk

Orrick, Herrington & Sutcliffe LLP
Contact

Orrick, Herrington & Sutcliffe LLP

On April 14, the OCC released a letter providing more details on the recent security breach involving its email systems. The breach — identified as a major incident under the Federal Information Security Modernization Act (FISMA) — involved a third-party who accessed several OCC user accounts through an unauthorized administrative-level account. The OCC noted it has taken steps to disable the unauthorized account and is working to determine the extent of the data compromised.

As previously covered by InfoBytes, the OCC announced on April 8 it had notified Congress of a major information security incident after noticing unusual interactions between a system administrative account and OCC user mailboxes on February 11.

The OCC will notify each regulated institution if it finds that the unauthorized user accessed information specific to that institution. Furthermore, the OCC will provide all supervised institutions with email user domains included in the compromised information, allowing them to identify any data they may have sent to OCC users during the breach period. The OCC is engaging with industry chief information security officers to discuss best practices for enhancing system security. Additionally, the OCC is conducting comprehensive reviews of its communication systems to ensure future security.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Orrick, Herrington & Sutcliffe LLP

Written by:

Orrick, Herrington & Sutcliffe LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Orrick, Herrington & Sutcliffe LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide