Jack Henry hit by ransomware after voice-phishing attack
Ransomware linked to ShinyHunters used voice phishing to access Jack Henry’s corporate network, exposing customer personal data at 10 of about 7,200 client banks.
Jack Henry, a U.S. core banking vendor, reported a ransomware intrusion that used a social engineering voice-phishing scheme to gain access to its internal corporate environment. The company confirmed attackers removed personally identifiable information related to customers at ten client banks out of roughly 7,200 clients.
Jack Henry reported the incident reached only its corporate network and did not access client-facing systems, operating systems, core platforms or daily processing services that support bank operations. The firm declined to identify the affected banks or specify the exact types of personal data taken.
The vendor identified the threat actor as ShinyHunters, a criminal extortion group active since 2019 and linked to multiple ransomware campaigns. “The incident involved an extortion attempt, and we are not making any payment to the threat actor,” the company wrote.
To respond, the company has hired an independent third-party cyber forensics firm to investigate and is cooperating with federal law enforcement. Jack Henry is offering two years of credit monitoring services to the affected financial institutions to provide to impacted accountholders.
The company stated it has assessed the financial impact of the incident and does not consider it material to its finances. Jack Henry expressed regret for any concern the incident may cause to its clients and their accountholders.








