type: incident ยท created: 2026-09-02 ยท updated: 2026-09-02 ยท tags: [incident, ransomware, vishing, financial-services, data-breach] ยท confidence: medium ยท severity: high ยท affected_sectors: [finance] ยท au_impact: true
Jack Henry Confirms Ransomware Incident After ShinyHunters Claim, Refuses to Pay
Summary
US core-banking vendor Jack Henry confirmed a cybersecurity incident in a "limited portion of our internal, non-production corporate environment", stating the access came through a social-engineering voice-phishing (vishing) scheme initiated by ShinyHunters. The company refuses to pay the ransom.
Key Facts
- Attribution: The extortion group Shinyhunters claimed Jack Henry as a victim on 30 August 2026.
- Access vector: A vishing scheme โ the same vector documented against McKesson, CareCloud and iRhythm.
- Scope: No client-facing systems, core platforms or daily processing were accessed; however, personally identifiable information (PII) was extracted from ten of roughly 7,200 client banks.
- Response: Two years of credit monitoring offered to impacted institutions; independent forensics firm engaged; working with federal law enforcement.
- Payment stance: "We are not making any payment to the threat actor"; the company says the incident is not financially material.
Significance
Jack Henry serves roughly 7,200 US banks and credit unions. Australian banks and mutuals procuring core-processing, self-service and know-your-customer platforms from comparable US vendors should treat the vishing-to-vendor-access chain as the operative third-party risk under APRA CPS 234.
Related Pages
- Shinyhunters โ attributing actor