Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Attacks - OCC Reports Major Security Breach Involving Sensitive Emails
Attacks BEC Data Breach News & Analysis Threats and Vulnerabilities

OCC Reports Major Security Breach Involving Sensitive Emails

Kirsten DoyleBy Kirsten DoyleApril 16, 20253 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
OCC Reports Security Breach
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The Office of the Comptroller of the Currency (OCC) has alerted Congress to a “major information security incident” following unauthorized access to its email systems, including messages containing sensitive financial data. The breach was discovered on 11 February 2025, and confirmed the following day. 

According to the OCC, the incident involved unusual activity by a system administrator account accessing user mailboxes without authorization. Once detected, the OCC shut down the compromised accounts and activated its incident response protocols.  

The breach was reported to the Cybersecurity and Infrastructure Security Agency and publicly disclosed on 26 February. 

The investigation, involving internal teams and third-party cybersecurity experts, is ongoing.  

So far, the OCC has found that the unauthorized access included emails containing highly sensitive information about federally regulated financial institutions — the kind of data used during regulatory examinations and oversight. 

The initial investigation, according to Bloomberg, revealed that the incident involved unauthorized access to some 150,000 emails from 103 accounts, including sensitive financial data used in regulatory examinations and oversight processes. The unauthorized access started as early as May or June last year and continued until February 2025, making it more prolonged than initially believed. 

In consultation with the Department of the Treasury, the OCC has officially classified the event as a major incident under the Federal Information Security Modernization Act (FISMA). 

Acting Comptroller of the Currency Rodney Hood said steps are being taken to assess the full impact and address the structural issues that allowed the breach to occur. “There will be full accountability for the vulnerabilities identified,” he said. 

The OCC is now reviewing its cybersecurity policies and procedures and plans to bring in additional independent experts to strengthen its defenses and response capabilities. Throughout the process, it has been closely coordinating with the Department of the Treasury. 

Identify and Respond Proactively 

Avkash Kathiriya, SVP of Threat Intelligence Research at Cyware, said:   “Incidents like the Treasury OCC breach don’t only affect the public sector and underscore why Threat Intelligence Management, when done right, empowers security teams to identify and respond to advanced threats proactively—not months after an adversary has already embedded themselves deep within critical systems. 

“But beyond internal processes, the real power lies in intelligence sharing and collaboration,” he added. “Government agencies must operate as a unified front, exchanging IOCs, TTPs, and threat context in real time to collectively strengthen our national cyber defense posture. Nation-state actors thrive in silos. By breaking them down and enabling automated, secure sharing of threat intelligence across agencies and partners, we can significantly reduce attacker dwell time and accelerate coordinated defense strategies. 

In ending, Kathiriya said protecting national security requires a connected, real-time threat intelligence ecosystem—one that enables companies to detect, respond, and mitigate the impact of threats before they become systemic. 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    Dutch police, NCSC take down major botnet
  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw
  • Kirsten Doyle
    CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet
  • Kirsten Doyle
    Threat Actors Deploy Tiflux RMM for Persistent Remote Access

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The missing link in cyber resilience: Bridging the identity visibility gap

June 4, 20266 Mins Read

Dutch police, NCSC take down major botnet

June 4, 20264 Mins Read

Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw

June 2, 20263 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}