Banking tech vendor SitusAMC says it suffered a November 12 hack that could expose sensitive customer data; sources say JPMorgan, Citi, and others are impacted
On November 12, 2025, SitusAMC ("we" or the “Company") became aware of an incident … Connor Jones / The Register : Intrusion at real estate finance biz sparks concern for big banks Eric Geller / Cybersecurity Dive : Hackers steal sensitive data from major banking industry vendor Cynthia B Brumfield / Metacurity : Cyberattack on a critical third-party vendor could expose top banks' customer data Blockchain.News : Senator Cynthia Lummis Slams JPMorgan's Anti-Crypto Policies, Warns of Industry Flight Overseas — Trading Implications for U.S. Crypto Liquidity Gyana Swain / CSO : JPMorgan, Citi, Morgan Stanley assess fallout from SitusAMC data breach Allison Carter / PR Daily : The Scoop: TikTok users are claiming brands reneged on promises as ‘jokes’ Ben Lovejoy / 9to5Mac : Hackers steal customer data from JPMorgan Chase and Citi PYMNTS.com : Hackers Hit ‘Necessary Plumbing’ of Big Bank Mortgage Operations Denise Wee / Bloomberg : Citi Wealth Head Sees Upside to Bull Market on Record Inflows Lockridge Okoth / BeInCrypto : JPMorgan Closed His Accounts, But You Don't Throw Out a Bitcoin CEO by Accident CNN : Wall Street banks scramble to assess fallout from hack of real-estate data firm Finextra : Top US banks hit by cyber breach at mortgage tech supplier Modern Diplomacy : NYT: Vendor Hack May Have Exposed JPMorgan, Citi, Morgan Stanley Client Data X: Howard Sherman / @icrowdfundbuzz : If you don't have identity theft protection you're playing with fire. Reach out and to me and get IDShield today. https://www.nytimes.com/... via @NYTimes Mastodon: Kevin Beaumont / @GossiTheDog@cyberplace.social : If anybody knows anybody at SitusAMC, they probably want to patch AnyConnect as they're on firmware from over a year ago as of today. — root@serenity:~# cat scannyany9.txt | grep situ — 150.221.36.140,*.situsamc.com| situsamc.com,YES,14/03/24,N/A Forums: r/FBI : A Swath of Bank Customer Data Was Hacked. The F.B.I. Is Investigating.
Context & Ripple Effects
This fits a recurring pattern in which one service provider becomes a shared exposure point for multiple financial clients: a HubSpot compromise that triggered breach notifications across crypto firms and a Kroll employee SIM-swap incident affecting several bankruptcy clients both showed how vendor access can widen an incident's reach.
For JPMorgan, the story also revives a long-running control issue: its earlier breach was traced to a server without two-factor authentication. The immediate significance is less the identity of any one bank than the sensitivity of the data and workflows concentrated at a real-estate-finance supplier.
First-order effects
- SitusAMC must investigate the intrusion, determine what customer data was accessed or taken, and coordinate with the FBI and affected clients.
- Banks named by sources, including JPMorgan and Citi, face an immediate exposure-assessment and incident-response task for data or processes handled through SitusAMC.
Second-order effects
- Bank clients are likely to intensify scrutiny of SitusAMC's access controls, data segregation, logging, and notification obligations, while reassessing which sensitive workflows can remain concentrated at one vendor.
- Other financial-services vendors will face tougher security due diligence from bank customers, especially where a provider holds data spanning multiple institutions.
Third-order effects
- If incidents continue to propagate through shared suppliers, third-party cyber risk will be treated less as a procurement checkbox and more as a system-level resilience issue, with greater emphasis on vendor dependency mapping and recoverability.
- The pattern could shift competitive advantage toward vendors that can demonstrate stronger isolation and incident transparency; whether it changes supplier concentration depends on banks' ability to replace specialized providers.
The trend: Financial institutions are increasingly managing cyber risk across the vendor ecosystem, not just inside their own networks.