Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • Bipartisan Senate Bill Would Reauthorize Expiring Cyber Threat Info-Sharing Law
    • S.D.N.Y.: Crypto law firm sues Phantom Technologies over meme coin cyber breach
    • CPPA, State AGs Join Forces on Privacy Enforcement
    • Comer Seeks Testimony From 23andMe’s Founder About Fate of Genetic Data
    • Connolly Seeks IG Probe of NLRB Whistleblower’s Data Breach Claims
    • FCC Hears Mixed Views on Undersea Cable Cyber Rules
    • OCC taking security measures following email breach
    • Proposal on Cybersecurity Assessments Published in Croatia
    • Recommendations on Data Protection Officers Offered in Lithuania
    • STRATEGIC PERSPECTIVES—Pryor Cashman Attorneys Discuss Privacy Issues in 23andMe Bankruptcy
    • Survey Finds Knowledge Gaps in Dutch Businesses’ Use of Algorithms to Process Personal Data
    • Views on GDPR Certification Criteria Published by EDPB
  • Articles
  • Articles
  • Organizations
  • Organizations

    Cybersecurity Policy Report, OCC taking security measures following email breach, (Apr 16, 2025)

    Organizations Mentioned:CrowdStrike | Mandiant | Microsoft | Office of the Comptroller of the Currency

    By Nora Macaluso

    The OCC told supervised institutions that it is working with cybersecurity consultants to determine what information may have been compromised.

    The Office of the Comptroller of the Currency said it’s taking steps to secure its information syste ...

    By Nora Macaluso

    The OCC told supervised institutions that it is working with cybersecurity consultants to determine what information may have been compromised.

    The Office of the Comptroller of the Currency said it’s taking steps to secure its information systems following a breach of its email systems reported in February.

    “The OCC is committed to taking all actions to remediate the deficiencies that contributed to this incident and to ensure full accountability for any organizational or structural deficiencies that contributed to this incident,” the agency said in a letter to its supervised institutions.

    The OCC on February 26 said the incident was reported to the Cybersecurity and Infrastructure Security Agency (CISA) “this month” and involved a “limited number” of email accounts (see Banking and Finance Law Daily, Feb. 28, 2025). The letter said the agency determined on April 7 that the event “qualified as a major incident” under the Federal Information Security Modernization Act, and it notified Congress of that finding on April 8 (see Banking and Finance Law Daily, Apr. 11, 2025).

    The agency disabled the compromised account, which was “a service account with administrative-level privileges,” and confirmed that the unauthorized access was stopped. The OCC also “globally reset all credentials associated with its full Microsoft tenant to eliminate the possibility of further unauthorized access by this threat actor.”

    According to the letter, “Efforts to analyze the compromised email messages to determine their contents have been initiated and are ongoing. The OCC is configuring and hardening its Microsoft 365 environment” and has “enhanced oversight of the contractor-led management of the Microsoft email environment.”

    The OCC is working with Microsoft GHOST, Mandiant, and CrowdStrike on a “full investigation” of the breach. “Mandiant and CrowdStrike have both reviewed all activity within OCC’s Microsoft Cloud tenant and verified there has been no indication of additional activity or lateral movement within OCC IT systems by the threat actor,” and Mandiant “confirmed the breached account existed solely in the cloud environment,” the letter said.

    Mandiant, “in an abundance of caution,” is reviewing BankNet and the Large File Transfer system that many institutions use to share supervisory information, and CrowdStrike will conduct a similar review, the OCC said.

    The OCC also is working with a contractor to review the content of all the compromised emails and attachments and is looking to determine whether any of the information has been found on the dark web.

    The accessed information “includes financial supervision information provided by OCC supervised institutions and non-public OCC information. Efforts to determine if any bank customer information was compromised are ongoing.”

    The OCC told the institutions it will inform individual banks if it determines information specific to those institutions has been compromised and will provide all supervised institutions with email user domains that were included in the compromised information. The agency is “engaging with industry Chief Information Security Officers to discuss industry best practices to further ensure the security of its systems.”

    “We recognize regulated institutions may have questions about their provision of requested supervisory information for OCC examinations,” the letter said. “OCC examiners are available to work with individual institutions to answer their questions and ensure the secure exchange of required supervisory information.”

    Companies: CrowdStrike; Mandiant; Microsoft

    RegulatoryActivity: BankingOperations CyberPrivacyFeed DataBreach DataSecurity FinancialStability FinTech GCNNews Privacy DataPrivacy

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use