Free tools Windows power users keep installed
One-click scans. No signup required.
This was a vendor-side breach disclosed on February 12, 2024—not evidence that Bank of America’s core banking systems were hacked. Infosys McCamish Systems (IMS), which administered some Bank of America-serviced deferred-compensation plans, reported unauthorized access around November 3, 2023. An IMS filing identified 57,028 directly affected individuals, although the notice said it could not determine with certainty exactly which information was accessed.
What happened in the Bank of America vendor breach?
IMS detected unauthorized access to its systems around November 3, 2023. Some IMS applications and systems became unavailable. On November 24, IMS told Bank of America that data connected with Bank of America-serviced deferred-compensation plans may have been compromised.
The incident later appeared in breach notifications and public reporting published February 12, 2024. The contemporaneous IMS company statement described a cybersecurity event and application or system unavailability: SEC filing. The customer notification is available through DocumentCloud.
How many people were affected?
The IMS notification identified 57,028 directly affected individuals. That is a figure from the IMS filing, not a count of all Bank of America customers. The affected population appears tied to deferred-compensation plan data serviced through IMS, rather than every checking, savings, mortgage or credit-card customer.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitches#1 Best Overall
What information may have been exposed?
The reported data categories may have included:
- Names and addresses
- Social Security numbers
- Dates of birth
- Financial information, including account numbers and credit-card numbers
- Other identifying information held in the affected plan-service systems
These are potentially exposed categories, not proof that every affected person’s records contained every item or that each item was accessed. The notification said IMS could not determine with certainty exactly what information was accessed.
Was Bank of America itself hacked?
The available notification said Bank of America’s own systems were not compromised. The intrusion occurred in IMS’s environment, making this a third-party service-provider incident. “Bank of America data breach” is shorthand used in coverage, but it should not be read as confirmation that the bank’s online-banking infrastructure was breached.
Was LockBit responsible?
The LockBit ransomware group claimed responsibility and alleged that it encrypted more than 2,000 systems. Those statements were attacker claims and were not independently confirmed in the available reporting. The evidence supports an incident affecting IMS; it does not establish that LockBit hacked Bank of America directly.
What should someone who received a notice do?
- Verify the notice. Use contact information from Bank of America’s official website or an existing statement, not a phone number or link in an unexpected message.
- Read the individual notice. Check which data categories were listed for you, enrollment deadlines and whether monitoring or identity-restoration services were offered.
- Review existing accounts. Watch Bank of America and other bank or card accounts for unauthorized transactions, new payees, changed contact details, payroll or direct-deposit changes and other unusual activity.
- Secure reused passwords. Change passwords for email, banking, brokerage, payroll and payment accounts. Use unique passwords and enable multifactor authentication.
- Choose a credit protection tool. A credit freeze is generally the stronger barrier against new-account credit fraud, but you must temporarily lift it when applying for legitimate credit. A fraud alert is easier and less restrictive, but it does not block access to your credit file.
- Use official recovery resources. Report suspected identity theft at IdentityTheft.gov and obtain credit reports through AnnualCreditReport.com.
What a freeze or alert will not stop
A credit freeze primarily addresses new credit accounts. It does not by itself prevent unauthorized withdrawals from existing bank accounts, card-not-present purchases, tax or benefits fraud, payroll changes, account takeover or social-engineering scams. Keep transaction alerts enabled and monitor existing accounts separately.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallRank #3
Watch for follow-on phishing
After a breach notice, scammers may impersonate Bank of America, IMS, a credit bureau or an identity-monitoring provider. Do not give a caller a one-time passcode, approve an unexpected login prompt, move money to a “safe account,” install remote-access software, call numbers supplied in unsolicited messages or pay a fee to receive promised monitoring.
If you did not receive a notice
Not receiving a notice does not prove that no data was involved, but it also does not prove exposure. Contact Bank of America through a verified channel and ask whether your information was included in the affected population. Third-party breach databases should not be treated as definitive confirmation.
Rank #4
How this differs from the separate E&Y/MOVEit incident
Some search results combine this event with a separate Ernst & Young MOVEit-related exposure involving 30,210 individuals. That was a different vendor incident and is not part of the IMS figure of 57,028.
What remains unknown
- Which specific individuals’ records were accessed
- Which fields, if any, were exfiltrated from each record
- Whether misuse of the information occurred
- Whether LockBit’s claims about the attack and encryption count were accurate
- The complete remediation package provided to every affected person
Readers should therefore act on the contents of their own notice and on observable account activity, rather than assume that every listed data category was stolen.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




