Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

JPMorgan Chase’s October 2014 disclosure said the breach affected approximately 76 million households and 7 million small businesses—not 83 million individual people. The bank said names and contact details were compromised, while it had no evidence that account numbers, passwords, user IDs, birth dates, or Social Security numbers were exposed. Those were the bank’s statements at the time, not a claim about what may be known today.

What did “83 million account holders” mean?

The headline figure added two different categories. In its October 2, 2014 Form 8-K, JPMorgan Chase & Co. wrote: “The compromised data impacts approximately 76 million households and 7 million small businesses.” The company described households and businesses, not a count of individual account holders. JPMorgan Chase & Co., Form 8-K, October 2, 2014

Reported category Approximate number
Households 76 million
Small businesses 7 million
Combined headline shorthand 83 million households and small businesses—not 83 million verified people

What information did JPMorgan say was compromised?

The bank said names, addresses, phone numbers, email addresses, and related internal user information had been compromised. It said there was no evidence that account numbers, passwords, user IDs, dates of birth, or Social Security numbers were compromised. These statements describe JPMorgan’s public account of the incident in 2014; they should not be read as a present-day independent forensic assessment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

As of October 2, 2014, JPMorgan said it had seen no unusual customer fraud. It also said customers would not be liable for unauthorized transactions they promptly reported. JPMorgan Chase & Co., Form 8-K, October 2, 2014

#1 Best Overall

Why did officials warn about phishing?

Rhode Island Attorney General Peter F. Kilmartin confirmed a multistate investigation. His office said the attack reportedly occurred in June and July 2014 and warned that stolen contact information could help criminals craft convincing phishing messages. Its consumer advice was to monitor accounts and reach the bank by going directly to its website rather than following links in unexpected messages. Rhode Island Attorney General, consumer alert

That warning follows from the type of data JPMorgan said was exposed: contact details can make a fraudulent email, text, or call seem more credible even when the bank has not said that passwords or account numbers were taken. Unexpected requests for login credentials or payment details should be treated cautiously.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How did federal officials respond?

House oversight: examine corporate vulnerabilities

Representative Elijah Cummings, then the House Oversight Committee’s ranking member, requested a bipartisan hearing. He argued that examining vulnerabilities at major companies could help inform efforts to protect federal information-technology assets. This was a call for congressional oversight, not a finding about the breach’s cause. House Committee on Oversight and Government Reform

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Senate: limit damage and share threat information

In December 2014 remarks, Senator Mike Crapo focused on limiting harm after an intrusion and improving threat-information sharing between government and industry. His remarks represent a separate policy response; the officials’ statements should not be treated as one unified industry position. U.S. Senate Committee on Banking, Housing, and Urban Affairs

What should a reader take from the 2014 disclosure?

  • “83 million” combined JPMorgan’s reported household and small-business figures; it did not establish that 83 million individuals were affected.
  • JPMorgan identified contact details and related internal user information as compromised, while saying it had no evidence that specified financial credentials and personal identifiers were compromised.
  • Officials’ reactions ranged from a multistate investigation and phishing warnings to congressional oversight and proposals to improve cyber resilience and threat sharing.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.