Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireSecurity Leadership and ManagementCybersecurity NewsBanking/Finance/Insurance

Fidelity Investments data breach impacts more than 77,000 customers

By Jordyn Alger, Managing Editor
Golden lock and credit cards on keyboard

Image via Unsplash

October 14, 2024

Fidelity Investments announced it experienced a data breach. This breach, which occurred in mid-August, has affected a more than 77,000 customers.

Security leaders weigh in 

Mr. Venky Raju, Field CTO at ColorTokens:

“As the attackers were able to use their own accounts to access other customer accounts, it is clear that there are security misconfigurations in Fidelity’s customer-facing web applications. This attack vector is so well known and understood that it is ranked number one in OWASP’s Top 10 Web Application Security Risks. Termed ‘Broken Access Control’ by OWASP, one of the risks associated with this is permitting the viewing or editing of someone else’s account by providing its unique identifier. Attackers may have exploited this vulnerability to create new accounts at Fidelity and access other accounts.”

Sarah Jones, Cyber Threat Intelligence Research Analyst at Critical Start:

“The Fidelity data breach highlights the persistent threat faced by financial institutions and their customers. While the attackers’ specific motives remain unclear, it’s likely that information gathering was a primary objective. This information could be used for future attacks, such as identity theft, phishing campaigns, or even ransomware demands.

“The ‘beachhead’ theory, where attackers establish a foothold to launch further attacks, is a common tactic in such incidents. Although Fidelity assures customers that their accounts and funds were not directly accessed, the breach raises concerns about the security of personal information, increasing the risk of identity theft, fraud, or other malicious activities.

“Cyberattacks on financial institutions often involve a combination of techniques, such as phishing, social engineering, exploiting vulnerabilities, and credential stuffing. To mitigate these risks, banks and financial institutions should prioritize robust security measures, including multi-factor authentication, encryption, and regular vulnerability assessments. Educating employees about cybersecurity threats and best practices is crucial to prevent social engineering attacks. A comprehensive incident response plan is essential for promptly detecting and addressing security breaches. Continuous monitoring of networks and systems for suspicious activity is vital, along with adherence to relevant industry regulations and standards to ensure data privacy and security.

“The Fidelity data breach underscores the need for financial institutions to remain vigilant and proactive in protecting themselves and their customers from evolving cyber threats. By understanding common attack tactics and implementing robust security measures, institutions can better safeguard their assets and maintain customer trust.”

Mr. Piyush Pandey, CEO at Pathlock:

“It is of critical importance to have robust sensitive data and application access controls within financial institutions. The interconnectedness and intricacy of supply chains in the financial industry increases the difficulty of the management of, as well as the securing of, third-party access. Given how highly regulated this sector is when it comes to data protection and privacy, ensuring that third-party vendors adhere with these regulations is vital, yet continue to be a challenge.

“By focusing on rigorous controls testing and enforcement, including stringent management of third-party identities and access, financial institutions can significantly strengthen their security posture, protect sensitive data, and ensure compliance with regulatory requirements. This proactive approach not only safeguards customer data (and trust), it enhances the financial institution’s overall resilience against attacks like this.”

Marcus Fowler, CEO of Darktrace Federal:

“Financial institutions have historically been a top target for threat actors, given the very nature of their operations. In response, these organizations often have the most advanced and sophisticated cybersecurity programs. AI represents the greatest advancement in truly augmenting our cyber workforce and these organizations serve as an excellent example of how AI can be effectively applied to security operations to increase agility and harden defenses against novel threats. We encourage these organizations to facilitate open conversations around their successes and failures deploying AI to help other organizations across sectors accelerate their adoption of AI for cybersecurity.”

KEYWORDS: data breach finance cybersecurity financial security financial services security leaders

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Man on laptop

Healthcare Executives Face a New Era of Personal Risk

Police lights

Security Team Member Dies in Standoff with Dallas Police

Stadium

Physical Security in Global Arenas: How AI Improves Security at Scale

Four people in suits

Mexico Security Crisis: Never Waste a Crisis

Product Spotlight

ISC West 2026 Product Preview

SEC 2026 Benchmark Banner
SEC 2026 Benchmark Banner

Events

April 15, 2026

How AI is Closing the Decision Gap in Leading GSOCs

Learn how modern security teams are evolving from alert-driven workflows to outcome-driven operations and how AI is enabling faster, more confident decisions at every stage of the incident response lifecycle.

April 21, 2026

The Blind Spot in Enterprise Security: Managing Workforce Risk Post-Hire

Organizations continuously monitor their networks and systems for risk, yet the people with legitimate access are often the least monitored part of the model. Discover a Workforce Risk Intelligence Framework that adds a dedicated layer focused on workforce risk.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
SEC 2026 Top Cybersecurity Leaders

Related Articles

  • Person using ATM

    Breach exposed information of more than 500,000 credit union members

    See More
  • Doctor

    Serviceaide Data Leak Impacts Nearly 500,000 Catholic Health Patients

    See More
  • Vertical lines of light

    More than 2,000 Palo Alto Networks firewalls compromised

    See More

Related Products

See More Products
  • Risk Analysis and the Security Survey, 4th Edition

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing