Jack Henry Ransomware Attack via Voice Phishing Exposes Client Data

Jack Henry Ransomware Attack via Voice Phishing Exposes Client Data

First seen 2 Sep 2026, 06:17 UTC En.Cryptonomist.ChBankingexchangewww.equifax.comwww.ftc.gov 39.9

Article Content

Browse articles
ThreatCluster

Jack Henry, a major US banking technology provider, confirmed a ransomware attack attributed to the ShinyHunters hacking group. The attack utilized voice phishing to trick employees into revealing access credentials, allowing intruders to breach the company's internal systems. Although personally identifiable information was extracted from fewer than 10 of Jack Henry's 7,200 client banks, no client-facing systems or core banking platforms were disrupted. The company has offered two years of credit monitoring to affected financial institutions and has not made any payment to the attackers. Jack Henry's security controls detected the unauthorized activity, and the incident is currently under investigation with federal law enforcement involvement. The company considers the incident not financially material.

Key Points: • Jack Henry was attacked via voice phishing by the ShinyHunters group. • Fewer than 10 client banks had their personal data compromised. • No core banking systems were disrupted during the incident.

Timeline

2026-09-02
Jack Henry confirms ransomware attack
Jack Henry disclosed a ransomware attack attributed to ShinyHunters, using voice phishing to gain access.
En.Cryptonomist.Ch
2026-09-02
Client data compromised
The company reported that personally identifiable information was extracted from fewer than 10 client banks.
Bankingexchange
2026-09-02
Investigation initiated
Jack Henry appointed an independent cyber-forensics firm and is collaborating with federal law enforcement.
Bankingexchange