JPMorganChase A.I CyberSecurity Scoring
JPMorganChase
Company Information
Website:http://www.jpmorganchase.com
Employees number:224,255
Number of followers:7,067,454
NAICS:52
Industry Type:Financial Services
Homepage:jpmorganchase.com
JPMorganChase Risk Score (AI oriented)
Between 700 and 749
JPMorganChaseFinancial Services
Updated:
11/09/2026
11/09/2026
737/1000
Moderate
Ba
JPMorganChase Global Score (TPRM)
xxxx
JPMorganChaseFinancial Services
Score locked

JPMorganChaseModerate
Current Score
737Ba (MODERATE)
01000
11 incidents
-21 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
736
AUGUST 2026
736
JULY 2026
733
JUNE 2026
729
MAY 2026
728
APRIL 2026
726
MARCH 2026
722
FEBRUARY 2026
720
JANUARY 2026
717
DECEMBER 2025
714
NOVEMBER 2025
733
Breach
07 Nov 2025 • JPMorganChase
Chase Affiliated Companies
Data Breach at Chase Affiliated Companies Affecting Texas Residents
712
CRITICAL-21
JPM4403744110825
On November 7, 2025, Chase Affiliated Companies disclosed a data breach to the Texas Attorney General’s office, impacting 979 Texas residents. The exposed information included names and Social Security numbers (SSNs), both classified as personally identifiable information (PII). The breach significantly elevates the risk of identity theft for affected individuals, given the sensitivity of SSNs, which are prime targets for fraudulent activities such as loan applications, tax fraud, or unauthorized account openings.The company responded by issuing notifications via U.S. Mail to impacted individuals, detailing the compromised data and offering guidance on protective measures. However, no public information was provided regarding additional support, such as credit monitoring or identity theft protection services. The incident underscores the critical need for robust data security measures, particularly when handling high-value PII, as the exposure of such data can lead to long-term financial and reputational harm for victims.The breach’s scale—affecting nearly a thousand individuals—highlights systemic vulnerabilities in data protection, reinforcing concerns over how financial institutions safeguard sensitive customer information against evolving cyber threats.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2025
754
Breach
27 Oct 2025 • JPMorganChase
JPMorgan Chase, Fried, Frank, Harris and Shriver & Jacobson LLP: 659 JPMorgan clients affected by data breach at Fried Frank
Fried Frank Data Breach Exposes PII of 659 JPMorgan Clients
733
CRITICAL-21
JPMFRI1768878048
Fried Frank Data Breach Exposes PII of 659 JPMorgan Clients
A data breach at law firm Fried, Frank, Harris, Shriver & Jacobson LLP has compromised the personal information of 659 JPMorgan Chase clients, including investors and associated individuals. The incident stemmed from a compromised user account that allowed an unauthorized third party to access and copy files from a shared network drive.
The breach was discovered on October 27, 2025, with JPMorgan Chase notified on December 9, 2025. Exposed data included names, account numbers, Social Security numbers, passport numbers, government IDs, and contact details. Affected individuals spanned multiple states, with 37 in Massachusetts, two in New Hampshire, and one in Maine.
Regulatory disclosures were filed with the Maine Attorney General, Massachusetts Office of Consumer Affairs and Business Regulation, and New Hampshire Attorney General on January 12, 2026.
In response, JPMorgan Chase and Fried Frank conducted a joint review to assess the breach’s scope and bolster security measures. While JPMorgan’s systems remained uncompromised, the firm is offering affected clients two years of free credit monitoring through Experian IdentityWorks, including daily credit monitoring, identity theft resolution, and $1 million in insurance coverage.
The incident highlights vulnerabilities in third-party legal service providers handling sensitive financial data.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2025
755
Cyber Attack
01 Sep 2025 • JPMorganChase
Telefónica, JPMorgan Chase, Google and DJI: ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & More
Google Play Strengthens Security in 2025, Multi-Stage Phishing Campaign, Critical Flaws in BMC FootPrints, SnappyClient C2 Framework, LiveChat Phishing, GitHub Secrets Exposure, The Gentlemen RaaS, WhatsApp Alphanumeric Passwords, Malicious Packagist Themes, DJI API Flaw, CVE Exploitation Trends, Teams Phishing, EU CSAM Rules, Emerging Threats
750
CRITICAL-5
DJIJPMTELGOO1789086449
Google Play Strengthens Security in 2025, Blocking Millions of Malicious Apps and Accounts
In 2025, Google removed 1.75 million policy-violating Android apps from the Play Store a decline from 2.36 million in 2024 while banning 80,000 developer accounts, down from 158,000 the previous year. The company also blocked 255,000 apps from accessing excessive user data and conducted 10,000 safety checks on published apps, leveraging generative AI to enhance detection.
Google’s Play Protect, now scanning 350 billion apps daily, identified 27 million malicious apps sideloaded outside the Play Store. Its expanded fraud protection covered 2.8 billion devices across 185 markets, blocking 266 million installation attempts from 872,000 high-risk apps.
Additionally, Google introduced Scam Detection for phone calls on Pixel devices in 12 countries, including the U.S., U.K., and India, to combat fraudulent activity.
---
Multi-Stage Phishing Campaign Bypasses Security Filters with Legitimate Infrastructure
A sophisticated phishing-as-a-service (PhaaS) toolkit, dubbed Kratos, was used in an unsuccessful attack impersonating JPMorgan Chase. The campaign employed a multi-chain redirect tactic, leveraging Cisco’s infrastructure and trusted services like Nylas to evade security filters. Attackers implemented a Cloudflare-based "human validation" step to ensure only real users reached the credential-harvesting page.
---
Critical Flaws in BMC FootPrints ITSM Enable Pre-Auth Remote Code Execution
Four vulnerabilities (CVE-2025-71257–71260) in BMC FootPrints, a widely used IT service management (ITSM) solution, were disclosed in September 2025. The flaws could be chained to achieve pre-authentication remote code execution (RCE). The attack begins with an authentication bypass (CVE-2025-71257), extracting a guest session token to exploit an unsanitized Java deserialization sink (CVE-2025-71260). Attackers could also abuse SSRF flaws (CVE-2025-71258, CVE-2025-71259) to leak internal data.
---
SnappyClient: A Stealthy C2 Framework Targeting Cryptocurrency Theft
A new C++-based command-and-control (C2) framework, SnappyClient, was discovered in December 2025. Distributed via a fake Telefónica website, it employs evasion techniques like AMSI bypass, Heaven’s Gate, direct system calls, and transacted hollowing. The malware steals data from browsers, extensions, and applications, with suspected ties to HijackLoader based on code similarities.
---
LiveChat Abused in Phishing Campaign to Harvest Sensitive Data
A phishing campaign leveraged LiveChat’s messaging platform to trick users into entering credentials, credit card details, and MFA codes. Attackers sent refund-themed emails, redirecting victims to a LiveChat-hosted link where they engaged in real-time chat impersonating trusted brands.
---
GitHub Sees Surge in Hard-Coded Secrets, Including AI Service Credentials
In 2025, 28.65 million new secrets were exposed in public GitHub commits a 34% increase from 2024 and a 152% rise since 2021. AI service secrets surged by 81% year-over-year, reaching 1.28 million. Additionally, 24,088 unique secrets were found in MCP-related configuration files, including 2,117 valid credentials.
---
The Gentlemen: A New RaaS Operation with Fabricated Claims
A nascent Ransomware-as-a-Service (RaaS) group, The Gentlemen, emerged in mid-2025 following a payment dispute with Qilin ransomware operators. The group, consisting of ~20 members, has targeted 94 organizations but has yet to provide credible proof of successful attacks. Researchers noted fabricated data samples on their leak site.
---
WhatsApp Introduces Alphanumeric Passwords to Counter SIM Swap Attacks
WhatsApp began testing alphanumeric passwords (6–20 characters, with at least one letter and number) to strengthen account security. The measure aims to prevent unauthorized access even if attackers perform a SIM swap to intercept 2FA codes.
---
Malicious Packagist Themes Inject Ads and Redirect Users to Gambling Sites
Six trojanized Packagist packages, posing as OphimCMS themes, were found distributing malicious JavaScript disguised as jQuery libraries. The malware exfiltrates URLs, injects ads, and redirects mobile users to gambling and adult content sites operated by Funnull.
---
DJI Exposes Device Data via Unauthenticated API Access
A security flaw in DJI’s backend allowed attackers to access device data including 7,000 Romo smart vacuums and 3,000 portable power stations by simply providing a serial number. The issue was patched after disclosure.
---
Only 1% of 2025 CVEs Were Exploited in the Wild
A VulnCheck report found that just 1% of disclosed CVEs in 2025 were actively exploited, with network edge devices accounting for a third of all exploited vulnerabilities. Exploit activity by state-sponsored groups decreased by 13% compared to 2024.
---
Teams Phishing Campaigns Impersonate IT Staff for Remote Access
Threat actors increasingly abuse Microsoft Teams to impersonate internal IT departments, tricking users into launching Quick Assist for remote access. The goal is to deploy malware, exfiltrate data, or move laterally within networks.
---
EU Extends Voluntary CSAM Detection Rules Until 2027
The European Union extended a temporary exemption allowing online platforms to voluntarily detect child sexual abuse material (CSAM) until August 2027, pending a long-term legal framework.
---
Emerging Threats: AOT Malware, CursorJack, and HijackLoader’s Evolving Tactics
- AOT-compiled malware evades analysis by stripping .NET metadata, forcing reliance on native-level tooling.
- CursorJack abuses Model Context Protocol (MCP) deep links for arbitrary command execution.
- HijackLoader now delivers an updated ACRStealer variant, spreading via pirated games from PiviGames.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2025
786
Ransomware
01 May 2025 • JPMorganChase
Unnamed Financial Institution
Fog Ransomware Attack on Financial Institution
748
CRITICAL-38
JPM602061325
In May 2025, an unnamed financial institution in Asia was targeted by Fog ransomware hackers. The attackers utilized legitimate employee monitoring software Syteca (formerly Ekran) and several open-source pen-testing tools, including GC2, Adaptix, and Stowaway. This tactic, described as 'living off the land,' allowed the attackers to operate more stealthily, reducing the likelihood of detection. The use of legitimate software in the attack chain was deemed highly unusual and reflects a shift in the tactics employed by Fog hackers.
INCIDENT DETAILS -
TYPE
MOTIVATION
REFERENCES
JANUARY 2025
810
Breach
01 Jan 2025 • JPMorganChase
JPMorgan Chase, Citigroup and Morgan Stanley: Shadow AI, deepfakes, and supply chain compromise are rewriting the financial sector threat playbook
Cyber Threats in Finance: 2025’s Rising Risks and Evolving Attack Tactics
782
CRITICAL-28
CITJPM1776832106
Cyber Threats in Finance: 2025’s Rising Risks and Evolving Attack Tactics
In 2025, financially motivated cyberattacks dominated the financial sector, driving 90% of breaches targeting banks, insurers, and payment processors. Data breaches accounted for 64% of incidents, with ransomware making up the remaining 36%. The average cost of a breach in finance reached $5.56 million per incident, the second-highest across all industries.
Personal data was the most frequently compromised asset (54% of cases), followed by internal organizational data (35%) and credentials (22%). Attackers leveraged stolen information for fraud, credential resale, and persistent network access. Initial access methods remained consistent, with hacking (45%), malware (37%), and social engineering (25%) as the primary vectors.
AI Accelerates Attack Timelines and Fraud
AI integration reshaped cyber threats in 2025, compressing the window between vulnerability disclosure and exploitation. Machine learning-powered scanning tools enabled faster reconnaissance, while adaptive malware evaded signature-based detection by dynamically altering behavior in response to security controls. Generative AI amplified social engineering, producing contextually accurate phishing emails, deepfake impersonations, and fraudulent invoices that bypassed traditional filters. Fraud-as-a-service offerings on underground markets further lowered the barrier to entry for less skilled attackers.
Unmanaged AI adoption within organizations termed shadow AI contributed to 20% of AI-related breaches. Among affected institutions, 97% lacked adequate access controls for AI systems.
Third-Party Risks Escalate
Supply chain compromises played a role in 30% of financial sector breaches, a significant increase from prior years. Vulnerable file transfer solutions, managed service platforms, and APIs served as common entry points. A breach at a shared third-party provider exposed customer data at major U.S. banks, including JPMorgan Chase, Citigroup, and Morgan Stanley, prompting regulatory scrutiny. Cryptocurrency exchange Bybit suffered a $1.5 billion theft after attackers exploited weaknesses in third-party wallet infrastructure.
Ransomware Shifts to Data Exfiltration
Ransomware impacted 12.8% of B2B financial organizations, with attackers prioritizing data exfiltration over encryption. Variants like Akira, Datacarry, and BlackLock targeted European institutions, while U.S. attacks increasingly focused on stealing sensitive data to trigger regulatory disclosures and investigations even when systems remained operational.
Hacktivists and State Actors Intensify Pressure
Hacktivist groups, including NoName057(16) and DarkStorm Team, launched DDoS campaigns against banks, particularly during elections and periods of geopolitical tension. State-aligned advanced persistent threat (APT) actors continued targeting financial institutions for intelligence gathering, exploiting zero-day vulnerabilities and maintaining long-term access. Geopolitical instability sustained elevated levels of disruptive activity throughout the year.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2024
811
Vulnerability
03 Dec 2024 • JPMorganChase
Fortinet, Cisco, Amazon Web Services and JPMorgan Chase: Cloud storage buckets leaking secret data despite security improvements
Toxic Cloud Trilogies: Publicly Exposed, Critically Vulnerable, and Highly Privileged Cloud Buckets
810
CRITICAL-1
FORCISAMAJPM1767748297
Tenable Report Highlights Persistent Cloud Security Risks Despite Improvements
A recent report by Tenable reveals both progress and ongoing vulnerabilities in cloud security, particularly around "toxic cloud trilogies"—publicly exposed, critically vulnerable, and highly privileged cloud instances. Between October 2024 and March 2025, the number of organizations with at least one such instance on AWS or Google Cloud Platform (GCP) dropped from 38% to 29%, while those with five or more declined from 27% to 13%. Despite these improvements, Tenable warns that such exposures remain a pressing concern.
The report also uncovered widespread exposure of sensitive data in cloud configurations. Researchers found that 54% of AWS Elastic Container Service (ECS) task definitions and 52% of Google CloudRun environment variables contained confidential information. Additionally, over a quarter of AWS users stored sensitive data in user data fields, with 3.5% of AWS EC2 instances holding secrets—posing a significant risk if exploited. AWS hosted the highest proportion of sensitive data (16.7% of its buckets), compared to 6.5% for GCP and 3.2% for Microsoft Azure.
While nearly 80% of AWS users have enabled critical identity-checking services, the findings underscore persistent misconfigurations and overconfidence in cloud security measures. The report, released at AWS re:Invent 2024 in Las Vegas, highlights the need for continued vigilance in securing cloud environments.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2024
817
Cyber Attack
01 Oct 2024 • JPMorganChase
PayPal and Chase: New BlobPhish Attack Leverages Browser Blob Objects to Steal Users’ Login Credentials
BlobPhish: A Stealthy, Memory-Resident Phishing Campaign Targeting Microsoft 365 and Financial Institutions
810
CRITICAL-7
JPMPAY1777400719
BlobPhish: A Stealthy, Memory-Resident Phishing Campaign Targeting Microsoft 365 and Financial Institutions
Since October 2024, a sophisticated phishing campaign dubbed BlobPhish has been silently harvesting credentials from Microsoft 365 users and major U.S. financial platforms including Chase, Capital One, and PayPal by exploiting browser Blob URL APIs. Unlike traditional phishing attacks, BlobPhish generates malicious login pages entirely in the victim’s browser memory, leaving no disk artifacts, cache traces, or detectable HTTP requests for security tools to flag.
The campaign, which surged in activity in February 2026, operates as a well-maintained threat rather than a short-lived attack. Its kill chain begins with phishing emails mimicking financial alerts, invoices, or document shares, often using trusted services like DocSend or shortened URLs (e.g., t.co). Some variants employ PDF attachments with QR codes, particularly targeting the energy sector.
Upon clicking the link, victims are redirected to an attacker-controlled HTML page hosting a JavaScript loader. The loader decodes a bundled phishing payload, constructs a Blob object, and forces the browser to navigate to a blob:https:// URL all without user interaction. The phishing page, which impersonates platforms like Microsoft 365, OneDrive, or banking portals, appears legitimate due to the blob URL’s deceptive appearance. A failed-login counter ensures multiple credential entries, while stolen data is exfiltrated via HTTP POST to compromised WordPress sites (e.g., /res.php, /tele.php).
BlobPhish’s evasion tactics render traditional defenses ineffective. Since the phishing page never transmits over the network as a standalone HTTP response, URL reputation engines, proxy logs, and secure email gateways fail to detect it. Endpoint solutions find no files on disk, and cache forensics yield no evidence, as the Blob URL is revoked immediately after use.
Victims span finance, manufacturing, education, government, and telecommunications sectors, with roughly one-third based in the U.S. Additional activity has been observed in Germany, Poland, Spain, the UK, Australia, and several Middle Eastern and Asian countries.
A successful compromise can lead to business email compromise (BEC), Microsoft 365 tenant takeovers, unauthorized wire transfers, or ransomware deployment. Regulatory risks include GDPR breach notifications, SEC cybersecurity disclosures, and FFIEC compliance violations.
Key indicators of compromise (IOCs) include loader URLs like hxxps[://]mtl-logistics[.]com/blb/blob[.]html and exfiltration endpoints such as hxxps[://]wajah4dslot[.]com/wp-includes/certificates/tmp//res[.]php. Compromised domains also include larva888[.]com and riobeautybrazil[.]com.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2021
810
Breach
26 Aug 2021 • JPMorganChase
JPMorgan Chase Bank, N.A.
Data Breach at J.P. Morgan Chase Bank, N.A.
788
CRITICAL-22
JPM404072625
The California Office of the Attorney General reported a data breach involving J.P. Morgan Chase Bank, N.A. on April 29, 2024. The breach occurred due to a software issue that allowed unauthorized access to plan participant information between August 26, 2021, and February 23, 2024, potentially affecting personal and financial information such as names, addresses, Social Security numbers, and bank account details.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MAY 2021
830
Breach
24 May 2021 • JPMorganChase
JPMorgan Chase Bank, N.A.
JPMorgan Chase Bank Data Breach
808
CRITICAL-22
JPM351072625
The California Office of the Attorney General reported that JPMorgan Chase Bank, N.A. experienced a data breach on May 24, 2021, affecting customer account information. The report was made on August 13, 2021, and notification letters detailed that personal and financial information may have been accidentally seen by another customer, although no indication of misuse of information was reported.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2018
837
Breach
28 Jun 2018 • JPMorganChase
JPMorgan Chase Bank, N.A.
JPMorgan Chase Data Breach
816
CRITICAL-21
JPM357072525
On August 10, 2018, the California Office of the Attorney General reported that JPMorgan Chase Bank, N.A. experienced a data breach on June 28, 2018. An employee improperly downloaded customer information, including names, addresses, mortgage loan numbers, and Social Security numbers, to a personal computer and online data storage sites, potentially exposing this data to third parties for about three weeks.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JULY 2013
844
Breach
01 Jul 2013 • JPMorganChase
JPMorgan Chase Bank, N.A.
JPMorgan Chase Bank Data Breach
823
MEDIUM-21
JPM108072925
The California Office of the Attorney General reported a data breach involving JPMorgan Chase Bank, N.A. on December 5, 2013. The specific date of the breach is unknown, but the incident was detected between mid-July and mid-September 2013, potentially compromising personal information such as names, addresses, Social Security numbers, and bank account details.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for JPMorganChase ??
What was JPMorganChase's A.I Rankiteo Cyber Score in August 2026 ??
What was JPMorganChase's A.I Rankiteo Cyber Score in July 2026 ??
What was JPMorganChase's A.I Rankiteo Cyber Score in June 2026 ??
What was JPMorganChase's A.I Rankiteo Cyber Score in May 2026 ??
What was JPMorganChase's A.I Rankiteo Cyber Score in April 2026 ??
What was JPMorganChase's A.I Rankiteo Cyber Score in March 2026 ??
What was JPMorganChase's A.I Rankiteo Cyber Score in February 2026 ??
What was JPMorganChase's A.I Rankiteo Cyber Score in January 2026 ??
What was JPMorganChase's A.I Rankiteo Cyber Score in December 2025 ??
What was JPMorganChase's A.I Rankiteo Cyber Score in November 2025 ??
What was JPMorganChase's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on JPMorganChase's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with JPMorganChase ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view JPMorganChase's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?