The JPMorgan Chase data breach affected a significant number of users, exposing personal information that can be used for identity theft, phishing, and fraud. If you've ever had an account or relationship with JPMorgan Chase, it's worth checking whether your data was involved.

What Happened

JPMorgan Chase disclosed in October 2014 that it had suffered a major cyberattack over the summer, discovered in July and contained by mid-August 2014. Attackers exploited an unpatched server to gain deep access to the bank's network, affecting approximately 76 million households and 7 million small businesses — the largest bank data breach at the time.

What Data Was Exposed

The breach exposed names, addresses, phone numbers, and email addresses. JPMorgan stated that no Social Security numbers, account numbers, passwords, or other highly sensitive financial data were confirmed stolen, though the scale of contact information exposed was still significant for phishing risk.

Why This Still Matters

Even breaches from years ago remain a risk today. Stolen data is sold, traded, and reused indefinitely. Credentials from old breaches fuel credential stuffing attacks — automated attempts to reuse your email and password combination on other sites. If you reused a password anywhere, one old breach can compromise several current accounts.

How to Check If You Were Affected

Use our free breach checker below — enter your email and we'll scan it against known breach databases instantly, no signup required.

What to Do If You Were Affected

👉 Check your own exposure in 30 seconds → scan your email free.

Frequently Asked Questions

When did the JPMorgan Chase data breach happen?

Attackers had access to JPMorgan's network from June to August 2014. The bank discovered and contained the breach in mid-August and disclosed it publicly on 2 October 2014.

What data was stolen in the JPMorgan Chase breach?

Names, addresses, phone numbers, and email addresses for approximately 76 million households and 7 million small businesses were exposed. JPMorgan stated that account numbers, Social Security numbers, and passwords were not confirmed to be part of the theft.

How did the JPMorgan Chase breach happen?

Attackers exploited an unpatched, overlooked server that lacked two-factor authentication as an entry point, then moved laterally through JPMorgan's network over several months before being detected.

How do I check if I was affected by the JPMorgan Chase breach?

If you were a Chase customer in 2014, your contact information was very likely included given the massive scope. Check your email at Scan My Shadow and be alert for phishing emails referencing your Chase account.

Was anyone prosecuted for the JPMorgan Chase breach?

Yes. US prosecutors charged individuals linked to a broader hacking and securities fraud scheme connected to the JPMorgan breach and attacks on other financial firms, resulting in convictions.

Sources

Related Reading