CSIDB logo
Incident

Office of the Comptroller of the Currency

Incident posture

Attack window
Feb 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 13:59

Linked entities

Victim
Office of the Comptroller of the Currency
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A major information security incident was reported to Congress after internal and third-party reviews uncovered unauthorized access to executive and employee emails within the agency's office automation environment. The breach was first detected when unusual interactions between a compromised system administrative account and user mailboxes were identified, prompting the immediate activation of incident response protocols, disabling of the affected accounts, and notification to the Cybersecurity and Infrastructure Security Agency. Analysis of the compromised messages revealed highly sensitive information related to the financial condition of federally regulated financial institutions gathered through examinations and supervisory processes, leading officials to classify the event as a major incident in consultation with the Department of the Treasury. Independent cybersecurity experts have been engaged to review the investigation, assess IT security policies, and evaluate internal processes related to cyber incidents.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On February 11, 2025, the Office of the Comptroller of the Currency learned of unusual interactions between a system administrative account in its office automation environment and OCC user mailboxes. The following day, February 12, the agency confirmed that the activity was unauthorized and immediately activated its incident response protocols. As part of those protocols, the OCC initiated an independent third-party incident assessment and reported the incident to the Cybersecurity and Infrastructure Security Agency. On the same day, February 12, the OCC disabled the compromised administrative accounts and confirmed that the unauthorized access had been terminated. The agency provided public notice of the incident on February 26. Subsequently, on April 8, 2025, the OCC formally notified Congress of the major information security incident, as required by the Federal Information Security Modernization Act. This determination followed internal reviews and independent third-party reviews of OCC emails and email attachments that were subject to unauthorized access. The OCC coordinated with the Department of the Treasury throughout its review to share information about its findings, and the formal classification of the event as a major incident was made in consultation with the Department of the Treasury.

After confirming the unauthorized activity, the OCC began analyzing the compromised email messages to determine their contents. These efforts involved the use of internal data science experts as well as independent third-party assistance, and the review was ongoing at the time of notification to Congress. Based on the content of the emails and attachments reviewed up to that point, the OCC determined the incident met the conditions necessary to be classified as a major incident. The unauthorized access was found to involve a number of OCC executives' and employees' emails, and the content included highly sensitive information relating to the financial condition of federally regulated financial institutions used in the agency's examinations and supervisory oversight processes. The exposure of this material raised direct concerns about the confidentiality of supervisory information, given the OCC's role in overseeing the financial condition of banks and the sensitivity of examination-related communications.

In response to the breach, the OCC took several immediate steps to investigate the scope of the incident, contain the damage, and address underlying security weaknesses. The agency engaged third-party cybersecurity experts to perform a full review of the investigation and forensics efforts. It also launched an immediate and thorough evaluation of its current IT security policies and procedures with the goal of improving its ability to prevent, detect, and remediate potential security incidents in the future. In addition, the OCC began efforts to engage an additional independent third-party to assess and analyze internal processes related to cyber incidents. Acting Comptroller of the Currency Rodney E. Hood stated that the confidentiality and integrity of the OCC's information security systems are paramount to fulfilling its mission, and that immediate steps had been taken to determine the full extent of the breach and to remedy long-held organizational and structural deficiencies that contributed to the incident. He further stated that there would be full accountability for the vulnerabilities identified and any missed internal findings that led to the unauthorized access. Contact information for Stephanie Collins at (202) 649-6870 was provided for further inquiries related to the notification to Congress.

Sources

Sources available to members: 1 source.

CSIDB