First Horizon Bank Online Accounts Hacked To Steal Customers’ Funds

First Horizon Bank Online Accounts Hacked To Steal Customers’ Funds

Bank holding company First Horizon Corporation disclosed the some of its customers had their online banking accounts breached by unknown attackers earlier this month.

First Horizon is a regional financial services company with $84 billion in assets that offers banking, capital market, and wealth management services.

First Horizon Bank, the company’s banking subsidiary, operates a network of hundreds of bank locations in 12 states across the Southeast.

Attackers accessed personal info, stole funds

First Horizon discovered the attack in mid-April 2021 and said that it only impacted a limited number of customers.

As discovered during the investigation, the unknown threat actors could breach the customers’ online bank accounts using previously stolen credentials and by exploiting a vulnerability in third-party software.

“Using the credentials and exploiting a vulnerability in third-party security software, the unauthorized party gained unauthorized access to under 200 on-line customer bank accounts,” First Horizon added in an 8-K form filed with the U.S. Securities and Exchange Commission (SEC) on Wednesday.

The attackers were also able to gain access to customer information stored in the breached accounts and drain funds from some of them before their intrusion was discovered.

The financial services firm revealed that they “fraudulently obtained an aggregate of less than $1 million from some of those accounts.”

Also Read: The Difference Between GDPR And PDPA Under 10 Key Issues

Customers reimbursed after breach

The bank holding firm reimbursed all the impacted customers for their stolen funds after discovering the data breach.

First Horizon also notified relevant data regulators and law enforcement agencies and opened new banking accounts for affected customers.

The company also remediated the software vulnerability exploited by the attackers during the incident and reset the passwords for impacted accounts.

“Based on its ongoing assessment of the incident to date, the Company does not believe that this event will have a material adverse effect on its business, results of operations or financial condition,” First Horizon concluded.

While First Horizon did not provide any info on the exploited third-party software, massive collections of stolen user credentials potentially reused on multiple sites have been sold or leaked for free by various threat actors for years.

The most recent examples are tens of millions of user records containing personal data and credentials belonging to ParkMobileBigBasket, and Nitro PDF customers shared for free on hacking forums.

First Horizon Bank division IBERIABANK Mortgage disclosed another data breach spanning almost two years and exposing customers’ personal info day after its parent company merged with First Horizon Bank on July 3rd, 2020.

Also Read: PDPA Compliance Singapore: 10 Areas To Work On

A First Horizon spokesperson was not available for comment when contacted by BleepingComputer earlier today for more details regarding the breach disclosed earlier this week.

Privacy Ninja

Recent Posts

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

2 weeks ago

Prioritizing Security Measures When Launching Webpage

Prioritizing Security Measures When Launching a Webpage That Every Organisation in Singapore should take note…

2 weeks ago

The Importance of Regularly Changing Passwords for Enhanced Online Security

Importance of Regularly Changing Passwords for Enhance Online Security that every Organisation in Singapore should…

3 weeks ago

Mitigating Human Errors in Organizations: A Comprehensive Approach to Data Protection and Operational Integrity

Comprehensive Approach to Data Protection and Operational Integrity that every Organsiation in Singapore should know…

3 weeks ago

The Importance of Pre-Launch Testing in IT Systems Implementation

Here's the importance of Pre-Launch Testing in IT Systems Implementation for Organisations in Singapore. The…

4 weeks ago

Understanding Liability in IT Vendor Relationships

Understanding Liability in IT Vendor Relationships that every Organisation in Singapore should look at. Understanding…

1 month ago