Jack Henry Confirms ShinyHunters Vishing Attack Breached Non-Production Environment, Exposing PII at Fewer Than Ten Client Institutions

Fintech News

Jack Henry Confirms ShinyHunters Vishing Attack Breached Non-Production Environment, Exposing PII at Fewer Than Ten Client Institutions #

Jack Henry & Associates (Nasdaq: JKHY), one of the United States’ most widely used core banking technology companies, has disclosed that it was targeted in a cybersecurity incident carried out by the ShinyHunters threat actor group using voice phishing, a technique that manipulates employees rather than exploiting software vulnerabilities.

The Monett, Missouri-based company issued a formal statement on August 31, 2026, confirming that attackers had gained unauthorised access to a limited portion of its internal, non-production corporate environment. ShinyHunters operatives used vishing, telephone-based social engineering calls impersonating trusted colleagues, IT staff, or vendors, to deceive employees into handing over system access credentials.

Jack Henry said its production infrastructure remained entirely unaffected. No client-facing systems, core banking platforms, or daily processing services were accessed or disrupted, and the company reported no system outages. All operational environments continue to function normally.

The breach did result in the compromise of personally identifiable information belonging to customers of fewer than ten client institutions. Jack Henry did not specify what categories of data were exposed, how many individual accountholders may be affected downstream, or when the initial unauthorised access first occurred. The company said it has directly notified the affected clients.

ShinyHunters, an extortion group active since 2019 with a record of high-profile corporate intrusions, had listed Jack Henry on its dark web leak site around August 28, 2026, threatening to release alleged stolen data publicly by September 1. Jack Henry’s confirmed disclosure came three days later.

The company said it engaged an independent third-party cybersecurity forensics firm to support the investigation and is cooperating with federal law enforcement. Jack Henry serves community and regional financial institutions across the United States, including nearly 1,000 banks and more than 700 credit unions.

Vishing attacks target employee judgment rather than software flaws, which limits the effectiveness of conventional security controls. Banking regulators and security firms have warned of the tactic’s growing use by ransomware and extortion groups as an entry point into enterprise networks.

Jack Henry said its investigation is ongoing and it will provide further updates as additional facts become available.

Source: PR Newswire