Cybersecurity Policy Report, OCC taking security measures following email breach, (Apr 16, 2025)
Organizations Mentioned:CrowdStrike | Mandiant | Microsoft | Office of the Comptroller of the Currency
By Nora Macaluso
The OCC told supervised institutions that it is working with cybersecurity consultants to determine what information may have been compromised.
The Office of the Comptroller of the Currency said it’s taking steps to secure its information systems following a breach of its email systems reported in February.
“The OCC is committed to taking all actions to remediate the deficiencies that contributed to this incident and to ensure full accountability for any organizational or structural deficiencies that contributed to this incident,” the agency said in a letter to its supervised institutions.
The OCC on February 26 said the incident was reported to the Cybersecurity and Infrastructure Security Agency (CISA) “this month” and involved a “limited number” of email accounts (see Banking and Finance Law Daily, Feb. 28, 2025). The letter said the agency determined on April 7 that the event “qualified as a major incident” under the Federal Information Security Modernization Act, and it notified Congress of that finding on April 8 (see Banking and Finance Law Daily, Apr. 11, 2025).
The agency disabled the compromised account, which was “a service account with administrative-level privileges,” and confirmed that the unauthorized access was stopped. The OCC also “globally reset all credentials associated with its full Microsoft tenant to eliminate the possibility of further unauthorized access by this threat actor.”
According to the letter, “Efforts to analyze the compromised email messages to determine their contents have been initiated and are ongoing. The OCC is configuring and hardening its Microsoft 365 environment” and has “enhanced oversight of the contractor-led management of the Microsoft email environment.”
The OCC is working with Microsoft GHOST, Mandiant, and CrowdStrike on a “full investigation” of the breach. “Mandiant and CrowdStrike have both reviewed all activity within OCC’s Microsoft Cloud tenant and verified there has been no indication of additional activity or lateral movement within OCC IT systems by the threat actor,” and Mandiant “confirmed the breached account existed solely in the cloud environment,” the letter said.
Mandiant, “in an abundance of caution,” is reviewing BankNet and the Large File Transfer system that many institutions use to share supervisory information, and CrowdStrike will conduct a similar review, the OCC said.
The OCC also is working with a contractor to review the content of all the compromised emails and attachments and is looking to determine whether any of the information has been found on the dark web.
The accessed information “includes financial supervision information provided by OCC supervised institutions and non-public OCC information. Efforts to determine if any bank customer information was compromised are ongoing.”
The OCC told the institutions it will inform individual banks if it determines information specific to those institutions has been compromised and will provide all supervised institutions with email user domains that were included in the compromised information. The agency is “engaging with industry Chief Information Security Officers to discuss industry best practices to further ensure the security of its systems.”
“We recognize regulated institutions may have questions about their provision of requested supervisory information for OCC examinations,” the letter said. “OCC examiners are available to work with individual institutions to answer their questions and ensure the secure exchange of required supervisory information.”
Companies: CrowdStrike; Mandiant; Microsoft
RegulatoryActivity: BankingOperations CyberPrivacyFeed DataBreach DataSecurity FinancialStability FinTech GCNNews Privacy DataPrivacy