Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-02 ยท updated: 2026-09-02 ยท tags: [incident, ransomware, vishing, financial-services, data-breach] ยท confidence: medium ยท severity: high ยท affected_sectors: [finance] ยท au_impact: true

Jack Henry Confirms Ransomware Incident After ShinyHunters Claim, Refuses to Pay

Summary

US core-banking vendor Jack Henry confirmed a cybersecurity incident in a "limited portion of our internal, non-production corporate environment", stating the access came through a social-engineering voice-phishing (vishing) scheme initiated by ShinyHunters. The company refuses to pay the ransom.

Key Facts

  • Attribution: The extortion group Shinyhunters claimed Jack Henry as a victim on 30 August 2026.
  • Access vector: A vishing scheme โ€” the same vector documented against McKesson, CareCloud and iRhythm.
  • Scope: No client-facing systems, core platforms or daily processing were accessed; however, personally identifiable information (PII) was extracted from ten of roughly 7,200 client banks.
  • Response: Two years of credit monitoring offered to impacted institutions; independent forensics firm engaged; working with federal law enforcement.
  • Payment stance: "We are not making any payment to the threat actor"; the company says the incident is not financially material.

Significance

Jack Henry serves roughly 7,200 US banks and credit unions. Australian banks and mutuals procuring core-processing, self-service and know-your-customer platforms from comparable US vendors should treat the vishing-to-vendor-access chain as the operative third-party risk under APRA CPS 234.

Related Pages

Source