October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
Bank of America

Bank of America Vendor Breach Exposed Data of 57,028 People: What Customers Should Know

The February 2024 Bank of America warning concerned a breach at vendor Infosys McCamish Systems, not the bank’s core systems. IMS identified 57,028 affected people and said names, Social Security numbers, dates of birth and financial data may have been involved, but the exact accessed information was uncertain.

By TheFinanceBase Team 3 min read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This was a vendor-side breach disclosed on February 12, 2024—not evidence that Bank of America’s core banking systems were hacked. Infosys McCamish Systems (IMS), which administered some Bank of America-serviced deferred-compensation plans, reported unauthorized access around November 3, 2023. An IMS filing identified 57,028 directly affected individuals, although the notice said it could not determine with certainty exactly which information was accessed.

What happened in the Bank of America vendor breach?

IMS detected unauthorized access to its systems around November 3, 2023. Some IMS applications and systems became unavailable. On November 24, IMS told Bank of America that data connected with Bank of America-serviced deferred-compensation plans may have been compromised.

The incident later appeared in breach notifications and public reporting published February 12, 2024. The contemporaneous IMS company statement described a cybersecurity event and application or system unavailability: SEC filing. The customer notification is available through DocumentCloud.

How many people were affected?

The IMS notification identified 57,028 directly affected individuals. That is a figure from the IMS filing, not a count of all Bank of America customers. The affected population appears tied to deferred-compensation plan data serviced through IMS, rather than every checking, savings, mortgage or credit-card customer.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What information may have been exposed?

The reported data categories may have included:

  • Names and addresses
  • Social Security numbers
  • Dates of birth
  • Financial information, including account numbers and credit-card numbers
  • Other identifying information held in the affected plan-service systems

These are potentially exposed categories, not proof that every affected person’s records contained every item or that each item was accessed. The notification said IMS could not determine with certainty exactly what information was accessed.

Was Bank of America itself hacked?

The available notification said Bank of America’s own systems were not compromised. The intrusion occurred in IMS’s environment, making this a third-party service-provider incident. “Bank of America data breach” is shorthand used in coverage, but it should not be read as confirmation that the bank’s online-banking infrastructure was breached.

Was LockBit responsible?

The LockBit ransomware group claimed responsibility and alleged that it encrypted more than 2,000 systems. Those statements were attacker claims and were not independently confirmed in the available reporting. The evidence supports an incident affecting IMS; it does not establish that LockBit hacked Bank of America directly.

What should someone who received a notice do?

  1. Verify the notice. Use contact information from Bank of America’s official website or an existing statement, not a phone number or link in an unexpected message.
  2. Read the individual notice. Check which data categories were listed for you, enrollment deadlines and whether monitoring or identity-restoration services were offered.
  3. Review existing accounts. Watch Bank of America and other bank or card accounts for unauthorized transactions, new payees, changed contact details, payroll or direct-deposit changes and other unusual activity.
  4. Secure reused passwords. Change passwords for email, banking, brokerage, payroll and payment accounts. Use unique passwords and enable multifactor authentication.
  5. Choose a credit protection tool. A credit freeze is generally the stronger barrier against new-account credit fraud, but you must temporarily lift it when applying for legitimate credit. A fraud alert is easier and less restrictive, but it does not block access to your credit file.
  6. Use official recovery resources. Report suspected identity theft at IdentityTheft.gov and obtain credit reports through AnnualCreditReport.com.

What a freeze or alert will not stop

A credit freeze primarily addresses new credit accounts. It does not by itself prevent unauthorized withdrawals from existing bank accounts, card-not-present purchases, tax or benefits fraud, payroll changes, account takeover or social-engineering scams. Keep transaction alerts enabled and monitor existing accounts separately.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Watch for follow-on phishing

After a breach notice, scammers may impersonate Bank of America, IMS, a credit bureau or an identity-monitoring provider. Do not give a caller a one-time passcode, approve an unexpected login prompt, move money to a “safe account,” install remote-access software, call numbers supplied in unsolicited messages or pay a fee to receive promised monitoring.

If you did not receive a notice

Not receiving a notice does not prove that no data was involved, but it also does not prove exposure. Contact Bank of America through a verified channel and ask whether your information was included in the affected population. Third-party breach databases should not be treated as definitive confirmation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How this differs from the separate E&Y/MOVEit incident

Some search results combine this event with a separate Ernst & Young MOVEit-related exposure involving 30,210 individuals. That was a different vendor incident and is not part of the IMS figure of 57,028.

What remains unknown

  • Which specific individuals’ records were accessed
  • Which fields, if any, were exfiltrated from each record
  • Whether misuse of the information occurred
  • Whether LockBit’s claims about the attack and encryption count were accurate
  • The complete remediation package provided to every affected person

Readers should therefore act on the contents of their own notice and on observable account activity, rather than assume that every listed data category was stolen.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Money Desk

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.