MONETT, Mo. — Jack Henry is refusing to pay hackers who stole personally identifiable information associated with fewer than 10 of the financial institutions it serves, with the attackers’ deadline for payment having passed without the stolen data being publicly released, according to the company and American Banker.
American Banker reported that the ShinyHunters hacking group had threatened to publish data stolen from Jack Henry unless the financial technology provider made contact by Tuesday. As of Wednesday, after the deadline had passed, the group had not published the files, American Banker reported.
Jack Henry has taken the relatively unusual step of publicly stating that it will not pay the hackers.
“This incident involved an extortion attempt, and we are not making any payment to the threat actor,” Jack Henry said in an Aug. 31 statement.
The company said the cyberattack compromised personally identifiable information associated with fewer than 10 clients, but it has not disclosed how many individual consumers are affected or what types of information were exposed.

American Banker reported that the figure of fewer than 10 refers to financial institutions rather than individual accountholders, meaning the total number of people whose information was compromised remains unknown.
Jack Henry also has not identified the affected institutions or disclosed whether they are banks, credit unions or both, according to American Banker.
Attack Began With Vishing
Jack Henry said its investigation determined the attack began with a sophisticated social-engineering technique known as vishing, or voice phishing, initiated by ShinyHunters.
The company said the unauthorized activity was confined to a limited portion of its internal, non-production corporate environment.
Jack Henry stressed that its client-facing systems, operating systems, core platforms and daily processing services were not accessed or disrupted. The company said it experienced no system outages and that those systems remain secure and fully operational.
According to Jack Henry, its security controls detected and contained the unauthorized activity, after which the company deployed additional security protocols, isolated affected systems and increased safeguards.
Jack Henry said it also retained an independent cyber-forensics firm to assist with the investigation and is working with federal law enforcement.
The company said it has determined the incident is not financially material.
More Than 7,200 Clients Notified
Jack Henry said it has notified all of its more than 7,200 clients about the incident and is working directly with the institutions whose information was affected.
The company also said it is offering two years of credit-monitoring services to affected financial institutions for them to provide to their accountholders.
Jack Henry has not disclosed what categories of PII were compromised, when the attackers initially gained access, when the intrusion was discovered or how long the attackers had access, according to American Banker.
The company provides core processing and other technology to banks and credit unions. American Banker, citing Jack Henry’s most recent annual report, reported that more than 1,600 banks and credit unions operate on the company’s core account and transaction systems, while Jack Henry sells other products and services to approximately 5,600 additional clients.
American Banker reported that Jack Henry serves more than 700 credit unions, or roughly one in six U.S. credit unions.
Potential Reporting Obligations for Credit Unions
The exposure could carry regulatory implications for any federally insured credit unions among the affected institutions.
American Banker noted that NCUA regulations define a reportable cyber incident to include unauthorized access to sensitive data resulting from the compromise of a third-party data-hosting provider, even when the incident does not disrupt services.
Under NCUA’s cyber-incident notification rule, a federally insured credit union generally must notify the agency as soon as possible and no later than 72 hours after it reasonably believes a reportable cyber incident has occurred.
American Banker reported that notification requirements depend on the circumstances and when an institution reasonably believes or determines that a reportable incident occurred.
Jack Henry’s disclosure also leaves unresolved questions for financial institutions about how client and accountholder information came to be stored in the non-production corporate environment that was compromised.
Much Remains Unknown
Security.io, in an analysis of the incident, said publicly available information does not identify the affected data fields, the number of individual accountholders represented in the compromised information, the time the intrusion began or was detected, or how long the attackers remained in the environment.
Jack Henry said it intends to continue providing clients with information as its response continues.
“We deeply value the trust our clients place in Jack Henry and will continue to keep them informed as part of our commitment to transparency,” the company said.




