SitusAMC, a major third-party vendor providing mortgage processing services to hundreds of financial institutions, suffered a significant data breach discovered on November 12 and confirmed on November 22. The breach has prompted leading US banks, including JPMorgan Chase, Citi, and Morgan Stanley, to assess the potential exposure of sensitive customer data, particularly information related to residential loan mortgages. SitusAMC has acknowledged that both corporate records and certain client customer data may have been compromised, though the full scope and impact remain under investigation.
The FBI is actively involved in the investigation and has stated that, so far, there is no evidence of operational impact on banking services. The incident highlights the increasing cyber risks associated with third-party vendors in the financial sector, with vendor-related breaches reportedly up 15% year-over-year. SitusAMC’s role in handling extensive personal and financial information for major lenders underscores the potential scale and seriousness of the breach as banks and regulators continue to evaluate the fallout.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
By November 24, reporting identified JPMorgan Chase, Citi, and Morgan Stanley among institutions assessing possible fallout from the vendor breach. No operational disruption to banking services was reported, but the extent of affected institutions and customers remained under investigation.
Following confirmation of the breach, SitusAMC reset credentials, disabled remote access tools, updated firewall rules, and strengthened security settings. The company also engaged external experts and began cooperating with the FBI, which confirmed an active investigation while services remained operational.
On November 22, SitusAMC broadened its communications and informed all customers about the incident. The company said the full scope of the stolen data was still under investigation.
On November 16, SitusAMC began notifying customers it believed were potentially affected by the breach. Major financial institutions were later reported among those alerted.
SitusAMC confirmed the security incident in mid-November after discovering unauthorized access to its environment. Reporting indicates the breach was discovered on November 12 and confirmed by November 15.
Earlier in November 2025, attackers breached SitusAMC's systems and exfiltrated confidential client information. The stolen data included accounting records, legal agreements, and potentially some customer data tied to client institutions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
computerweekly.com
Open sourcethecyberthrone.in
Open sourcego.theregister.com
Open sourcecsoonline.com
Open sourcebleepingcomputer.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.