October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

SitusAMC Data Breach: What JPMorgan, Citi and Morgan Stanley Customers Need to Know

The SitusAMC breach was a third-party vendor incident, not a publicly reported compromise of JPMorgan, Citi or Morgan Stanley’s core banking systems. Here is the latest on exposed data, notifications and customer precautions.
From TheFinanceBase Team8 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Bottom line: The publicly identified breach occurred at SitusAMC, a third-party real-estate finance and mortgage-services provider—not in the core banking systems of JPMorgan Chase, Citigroup or Morgan Stanley. SitusAMC said on March 17, 2026, that its forensic review and required consumer notifications were complete. The public record still does not identify how many customers of each bank were affected or confirm that particular data elements—such as Social Security numbers, account numbers or passwords—were exposed.

The short version

  • Compromised environment: SitusAMC said an unauthorized party accessed information in its systems after it detected an incident on November 12, 2025.
  • Named institutions: Reuters, citing reporting by The New York Times, said JPMorgan Chase, Citi and Morgan Stanley were among financial institutions notified that client data may have been accessed. Early reports also referred broadly to other financial institutions and mortgage lenders.
  • Potential information: SitusAMC identified corporate records, legal agreements and files connected with residential collateral and asset-management work. Some files may have contained consumer personally identifiable information or sensitive confidential information.
  • Banking operations: The FBI, according to the Reuters report, found no operational impact to banking services. SitusAMC said its own services remained operational and that the incident did not involve encrypting malware.
  • Current status: SitusAMC said its data review was complete and all required consumer notifications had been made by March 17, 2026.

That status matters. The original November 2025 story was about institutions assessing possible exposure. The current issue is what the completed review established for particular clients and customers—and what remains undisclosed publicly.

What happened at SitusAMC?

SitusAMC provides technology and services used in real-estate finance, mortgage, collateral and asset-management workflows. It detected a security incident on November 12, 2025. In a November 22 statement, the company said corporate information connected with some clients, including accounting records and legal agreements, had been compromised. It also said certain data relating to clients’ customers may have been affected.

The distinction is important: the confirmed compromised environment was SitusAMC’s. Public reporting did not establish that attackers broke into JPMorgan Chase’s, Citi’s or Morgan Stanley’s own core banking systems. The incident illustrates third-party or supply-chain risk: a company can face exposure when a service provider stores or processes records connected with its customers, even if the company’s primary systems remain available.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Veltec ID Protector Ink Roller - Identity Theft Protection Roller Stamp Set (Blue, Stamp+3 Refills)
  • SHIELD YOUR PRIVACY WITH THE ID DEFENDER ROLLER STAMP: Tired of worrying about your personal information falling into the wrong hands? The ID Defender Roller Stamp offers a simple yet effective solution. With a unique wide camouflage pattern, it quickly and easily conceals sensitive data on a variety of surfaces.
  • PRIVACY PROTECTION: useful not only as an ADDRESS BLOCKER or ID POLICE, but also keeps away preying eyes from invoices, authority documents, checks, bank statements and many more.
  • SIMPLE TO USE: Just remove the cover and swipe. The wide swipe makes it easy to cover sensitive information.
  • VERSATILE APPLICATION: Ideal for a variety of documents, including contracts, court documents, shipping labels, tax returns and more.
  • LONG-LASTING INK: The high-quality ink works on both glossy and standard paper and provides up to 330 feet of coverage.

SitusAMC’s public disclosures describe an intrusion and data compromise, not a ransomware event. The company said no encrypting malware was involved.

Which banks were connected to the incident?

Reuters, citing The New York Times, reported that JPMorgan Chase, Citigroup/Citi and Morgan Stanley were among financial institutions notified that client data may have been accessed. The early reports did not establish that all three institutions had identical files, exposure levels or affected customer populations.

Morgan Stanley separately referred to the company in its 2026 proxy statement as among financial institutions affected by a cyberattack on SitusAMC, while describing the issue as potential client-data exposure. That reference confirms the incident was relevant to Morgan Stanley, but it does not establish that every Morgan Stanley customer was affected or specify the exposed data elements.

Rank #2
Nezyo 2 Pack Identity Protection Roller Stamp 4 Pack Refill Ink,Yellow
  • Protect Your Privacy Effectively: you can use this identity protection roller stamp to flip personal information in under 2 seconds and save time and effort, effectively hiding and protecting your personal information, such as phone numbers, social security numbers, bank statements, shipping addresses, tax documents,data, billing addresses and many more
  • Ideal Replacement for Shredder: if you are still using a shredder to shred cards or papers that are printed with your personal information, this security stamper roller will be an alternative tool to block out your privacy effectively and easily
  • Refillable and Long Term Use: this confidential stamp can cover a total length of up to 100 meter/ 109 yards, approximately 3,200 prints are covered, pattern width is about 0.78 inches; When ink runs out, you can refill the security stamp with ink
  • Easy to Use: just continuous roll the address blocker roller stamp to conceal information, and roll on a second layer for maximum protection, works on paper, envelopes, folders, address labels, etc., please note that may not work on smooth surfaces
  • How to Refill the Ink: there are 4 pieces of ID stamp refills, each is about 1.5 ml, you just need to unscrew the cap of the ink bottle (not disposable, you can close the cap for next time of use), then insert it into the hole on the side of the stamp, then turn it upside down, about 5 minutes later, the most of the ink will be replenished to the security roller stamp

What each bank has publicly confirmed

  • JPMorgan Chase: Reuters reported that JPMorgan was among institutions notified about possible exposure. The cited reporting did not include substantive public details from the bank about affected customers or data categories.
  • Citi: Reuters likewise reported Citi among the institutions notified. The cited reporting did not provide a public, bank-specific account of the number of affected customers or the information involved.
  • Morgan Stanley: Morgan Stanley’s 2026 proxy statement referred to the SitusAMC cyberattack and potential client-data exposure. The document does not establish that the bank’s own core systems were breached or that all customers experienced the same exposure.

A lack of a detailed public statement should not be treated as either a denial or proof that a customer was affected. Individual notices may come from the relevant bank, mortgage lender, servicer or another SitusAMC client rather than from the bank named in news coverage.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What information may have been exposed?

Status Information What can safely be said
Identified by SitusAMC Corporate accounting records, including invoices; legal agreements and other legal records SitusAMC said certain client-related corporate information was compromised.
Potentially involved Files connected with residential Collateral and Asset Management and loan-file due diligence These business files could relate to mortgage and real-estate finance activities, but exposure varied by client and file set.
Potentially involved Consumer PII or sensitive confidential information SitusAMC said customer-related information may have been affected and later notified organizations when such information attributable to them was identified.
Not publicly confirmed in the available record Social Security numbers, driver’s-license numbers, bank-account numbers, passwords, credit histories or complete mortgage files Do not assume any particular data element was exposed unless it is listed in an individual notification or official client communication.

A client name appearing in an affected file path did not necessarily mean that every document associated with that client contained consumer PII. SitusAMC said it needed a deeper review to correlate particular documents with particular organizations and information.

Was customer information definitely stolen?

The answer depends on the customer and the records involved. SitusAMC said certain information was compromised, while some customer-related data may have been impacted. Its sample client letter used more specific language for certain clients, stating that information related to them had been acquired by an unauthorized third party.

Rank #3
Vantamo Identity Theft Protection Roller Stamp for Hiding Sensitive Information, Wide Confidential Stamp with 6 Ink Refill, Security Stamp Roller for Identity Theft Prevention, Classy Blue
  • The id defender roller is the ultimate tool for guarding your personal data at home or in the office. Prevent identity theft by quickly masking sensitive information on mail, documents, or labels, giving you confidence that your details remain private and secure with Vantamo id theft protection.
  • Effortlessly block out sensitive text with the label cover up identity protection, designed for quick, one-handed use. No more scraping off all shipping labels or doing a lot of swipes with a marker! Even first-time users will find the process intuitive and straightforward, making it a practical label eraser roller for anyone!
  • Vantamo wide rolling privacy marker is fully refillable and arrives with 6 ink refill for self inking stamps ensuring lasting performance. Don't run out when you need it the most. The ink is specially designed for hiding information.
  • Our address blackout stamp not only protects your privacy but also helps the environment. After using the roller on your documents, the paper is ready to be safely recycled, making this address eraser a smart alternative to shredding or tossing documents.
  • Here at Vantamo, we are creating products that people love! We are committed to providing excellent customer service on every black out stamp. If you ever have questions or concerns, our team is here to help, ensuring your id defender delivers reliable protection and peace of mind every time.

Those statements do not support a claim that every JPMorgan, Citi or Morgan Stanley customer had data stolen. The nature and extent of exposure varied by client and file set, and the public disclosures do not give an institution-by-institution count of affected consumers.

Were bank accounts or services disrupted?

No operational disruption to banking services was identified in the FBI statement cited by Reuters. SitusAMC also said its services remained operational. That addresses availability, not necessarily confidentiality.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Operational availability: There was no reported interruption to the banks’ ordinary services in the cited reporting.
  • Confidentiality: Information held by a third-party vendor may have been accessed by an unauthorized party.
  • Account takeover: The available public record does not establish that attackers gained direct access to customers’ bank, brokerage or credit-card accounts.
  • Fraud: It does not establish that the incident caused fraudulent transactions, identity theft or financial losses.

A vendor data breach can still create phishing or identity-fraud risk even when bank logins and payment systems continue to work normally.

Rank #4
Mimorou 4 Pack ID Security Roller Stamps, 5 Inks, Yellow
  • Personal Information Protection: there are 4 pieces of address blocker roller stamps in 2 different sizes, and 5 pieces of 1.5 ml inks, a total of 9 pieces. Mainly applied to hide information such as social security numbers, bank statements, billing addresses, shipping addresses, tax documents and so on, protecting your personal information
  • Re Inking Unlimitedly: the information blocker stamp can cover information of the length about 100 meters. And each security stamper roller has an oil hole, so you don't have to worry about you having to throw away the roller stamps when the ink runs out. They can be refilled with oil for repeated use, saving time and energy
  • Cover Fast: our identity protection rollers come in 2 different sizes, and you can choose different sizes according to different areas of information to cover large amounts of private information in a fast and clean way, avoiding identity theft and rejecting privacy disclosure harassment
  • Easy to Use: just remove the lid on the ID stamp blocker roller and open it, and then gently slide it on the place where the information needs to be covered. It is suitable for most ordinary paper with black words, and can protect your personal privacy in time
  • Save Time and Energy: compared with the shredder, the personal confidential stamp has a small size, easy to carry, can be applied anytime and anywhere. Compared to the marker, it covers a larger area and can be quickly covered with a single swipe. There is no need to worry about whether you can not protect your privacy in time

SitusAMC’s response and investigation

According to its public breach updates, SitusAMC said it:

  • Started an investigation with outside experts.
  • Notified and cooperated with federal law enforcement.
  • Took steps to contain the incident.
  • Performed forensic analysis and a file-by-file data review.
  • Used keyword searches to identify client names in affected file paths.
  • Communicated with affected clients.
  • Made data-reporting files available through an IDX portal where relevant.
  • Implemented additional hardening measures, including credential resets, disabling remote-access tools, firewall-rule updates and enhanced security settings.

On December 9, 2025, SitusAMC said it had not identified evidence of access to or attempted access of the emBTRUST or ProMerit applications for certain warehouse-finance and custody clients. That statement was limited to those applications and client contexts; it should not be read as a finding that no other information was accessed.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Timeline

  1. November 12, 2025: SitusAMC became aware of the security incident.
  2. November 22, 2025: SitusAMC disclosed that certain corporate data had been compromised and that some customer-related data may also have been affected.
  3. November 23–25, 2025: Reuters and other outlets reported that JPMorgan Chase, Citi and Morgan Stanley were among institutions notified about possible exposure.
  4. November 25, 2025: SitusAMC said some clients had received letters after initial keyword searches identified client names in affected file paths.
  5. December 9, 2025: SitusAMC said it remained operational and had not identified evidence of access to or attempted access of emBTRUST or ProMerit for certain clients.
  6. December 29, 2025: SitusAMC said its forensic investigation had concluded, the threat actor had been eradicated and there was no evidence of ongoing persistence.
  7. February 12, 2026: SitusAMC said its data review was nearing completion and that required consumer notices would be mailed over the following weeks.
  8. March 17, 2026: SitusAMC said the data review and required consumer notifications were complete.

See SitusAMC’s dated historical updates for the company’s earlier milestones.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
Mimorou 4 Pack ID Security Roller Stamps, 5 Inks, Red, Yellow, Blue, Green
  • Personal Information Protection: there are 4 pieces of address blocker roller stamps in 2 different sizes, and 5 pieces of 1.5 ml inks, a total of 9 pieces. Mainly applied to hide information such as social security numbers, bank statements, billing addresses, shipping addresses, tax documents and so on, protecting your personal information
  • Re Inking Unlimitedly: the information blocker stamp can cover information of the length about 100 meters. And each security stamper roller has an oil hole, so you don't have to worry about you having to throw away the roller stamps when the ink runs out. They can be refilled with oil for repeated use, saving time and energy
  • Cover Fast: our identity protection rollers come in 2 different sizes, and you can choose different sizes according to different areas of information to cover large amounts of private information in a fast and clean way, avoiding identity theft and rejecting privacy disclosure harassment
  • Easy to Use: just remove the lid on the ID stamp blocker roller and open it, and then gently slide it on the place where the information needs to be covered. It is suitable for most ordinary paper with black words, and can protect your personal privacy in time
  • Save Time and Energy: compared with the shredder, the personal confidential stamp has a small size, easy to carry, can be applied anytime and anywhere. Compared to the marker, it covers a larger area and can be quickly covered with a single swipe. There is no need to worry about whether you can not protect your privacy in time

What potentially affected customers should do

  1. Check official communications. Look for a notice from your bank, mortgage lender, servicer or another organization you recognize. Use a known website or the phone number on an existing statement—not a link or number in an unexpected email—to verify it.
  2. Read the notice for the actual data categories. Keep the letter or secure message. The individual notice is more useful than general coverage for determining whether identity information, financial records or other confidential information was involved.
  3. Review financial accounts. Check bank, brokerage and credit-card statements for unfamiliar transactions and report suspicious activity through the institution’s established channel.
  4. Change reused passwords. Prioritize financial accounts and email accounts, and do not reuse the new password elsewhere.
  5. Turn on multifactor authentication. Use it for email, banking, brokerage, credit-card and other important accounts wherever available.
  6. Consider a credit freeze when appropriate. If your notice indicates that identity information was exposed, a freeze with Equifax, Experian and TransUnion can help block many new-credit applications. It is generally more protective against new-account fraud than credit monitoring alone, but it is not mandatory and does not prevent every form of fraud.
  7. Use the official identity-theft process if needed. The Federal Trade Commission’s IdentityTheft.gov service provides steps for reporting and recovering from suspected identity theft.
  8. Follow the notice’s specific offer. It may explain credit monitoring, identity-restoration services, fraud alerts, reimbursement procedures or a dedicated help line.

Do not provide passwords, one-time security codes or full account credentials to someone who contacts you unexpectedly about the breach. Criminals often exploit public incident news with convincing impersonation messages.

What remains unknown

  • The aggregate number of affected individuals.
  • The number of JPMorgan Chase, Citi and Morgan Stanley customers affected individually.
  • Whether any exposed information was publicly released or used fraudulently.
  • The precise data categories involved for each institution or person.
  • Whether regulators or courts will impose additional consequences.
  • The exact division of notification and remediation responsibility between SitusAMC and each client.

Completion of SitusAMC’s review and required notifications means the company says its review phase is finished. It does not make future misuse impossible, and it does not substitute for the specific notice an affected organization may send.

Why the incident matters beyond these banks

The episode shows why cybersecurity risk in financial services extends beyond a bank’s login page and payment systems. Mortgage and real-estate finance workflows can involve vendors that handle legal agreements, accounting records, loan-file due diligence and collateral or asset-management information. A service provider can therefore become a meaningful confidentiality risk even when the financial institution remains operational.

For customers, the practical lesson is to identify the organization that actually sends a breach notice and to rely on the listed data categories rather than the headline. For financial institutions, the incident highlights the importance of vendor inventories, access controls, remote-access restrictions, logging, incident-notification contracts, file-retention limits and the ability to determine quickly which client records were present in a compromised environment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.