{"id":2673,"date":"2024-03-06T22:19:52","date_gmt":"2024-03-06T22:19:52","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/first-bofa-now-fidelity-same-vendor-third-party-breaches"},"modified":"2024-03-06T22:19:52","modified_gmt":"2024-03-06T22:19:52","slug":"first-bofa-now-fidelity-same-vendor-behind-third-party-breaches","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/03\/06\/first-bofa-now-fidelity-same-vendor-behind-third-party-breaches\/","title":{"rendered":"First BofA, Now Fidelity: Same Vendor Behind Third-Party Breaches"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltf2478a613567442a\/65e8ddcd5e5a87040a84a697\/fidelity_ryanMcGinnis_alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/first-bofa-now-fidelity-same-vendor-behind-third-party-breaches.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/first-bofa-now-fidelity-same-vendor-behind-third-party-breaches.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Fidelity Investments Life Insurance Company (FILI) is notifying nearly 30,000 affected individuals of a third-party data breach that has compromised their information.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to a notice filed with the state of Maine, third-party service provider Infosys McCamish (IMS) notified Fidelity in November about a &#8220;cybersecurity event&#8221; that disrupted its services. After an investigation alongside a third-party firm, IMS discovered that its systems were breached between Oct. 29 and Nov. 2. The unauthorized actor also was able to obtain data stored on those systems.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In its <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/apps.web.maine.gov\/online\/aeviewer\/ME\/40\/0c98c6d7-c7b3-4bbf-a7fa-8005c61168d6.shtml\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">notice to 28,268 individuals<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, Fidelity reports that IMS is unable to determine what sensitive information was accessed in the breach, but based on the information IMS has provided it&#8217;s likely that it included individual names, Social Security numbers, states of residence, bank account and routing numbers, and dates of birth.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This is the second time this year alone that a company has had to tell customers that their data was compromised in a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/bofa-warns-customers-of-data-leak-in-third-party-breach\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">third-party breach<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in connection with IMS. Last month, Bank of America faced a breach after IMS experienced a ransomware attack, compromising the data of over 57,000 customers. The data accessed in that breach was of similar material that was compromised for Fidelity merchants.&nbsp;It&#8217;s unclear whether the IMS woes tie back to the same cyber incident.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Third-party security breaches continue to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/amex-customer-data-exposed-third-party-breach\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">increase in frequency and impact<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Enterprises are highly reliant on third-party service providers, who are now often the easiest vector into an enterprises most critical data,&#8221; Jeff Margolies, chief product and strategy officer&nbsp;Saviynt,&nbsp;said in an emailed statement. &#8220;Enterprises need to improve their capabilities to manage and govern their third-party access as part of their identity-security programs.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As Fidelity continues to review its records of affected individuals and engage with IMS regarding the breach, it offers 24 months of credit monitoring through TransUnion Interactive. It said that merchants should personally review their financial statements and credit reports, and report any fraudulent or suspicious activity to authorities.&nbsp;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/first-bofa-now-fidelity-same-vendor-third-party-breaches\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Fidelity Investments Life Insurance Company (FILI) is notifying nearly 30,000<\/p>\n","protected":false},"author":12,"featured_media":2674,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2673","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/first-bofa-now-fidelity-same-vendor-behind-third-party-breaches.jpg?fit=1200%2C800&ssl=1",1200,800,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/first-bofa-now-fidelity-same-vendor-behind-third-party-breaches.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/first-bofa-now-fidelity-same-vendor-behind-third-party-breaches.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/first-bofa-now-fidelity-same-vendor-behind-third-party-breaches.jpg?fit=640%2C427&ssl=1",640,427,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/first-bofa-now-fidelity-same-vendor-behind-third-party-breaches.jpg?fit=640%2C427&ssl=1",640,427,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/first-bofa-now-fidelity-same-vendor-behind-third-party-breaches.jpg?fit=1200%2C800&ssl=1",1200,800,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/first-bofa-now-fidelity-same-vendor-behind-third-party-breaches.jpg?fit=1200%2C800&ssl=1",1200,800,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/first-bofa-now-fidelity-same-vendor-behind-third-party-breaches.jpg?fit=1024%2C683&ssl=1",1024,683,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/first-bofa-now-fidelity-same-vendor-behind-third-party-breaches.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/first-bofa-now-fidelity-same-vendor-behind-third-party-breaches.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/first-bofa-now-fidelity-same-vendor-behind-third-party-breaches.jpg?fit=1200%2C800&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2673","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2673"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2673\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2674"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2673"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2673"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2673"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}