Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireSecurity Leadership and ManagementCybersecurity NewsBanking/Finance/Insurance

Fidelity Investments data breach impacts more than 77,000 customers

By Jordyn Alger, Managing Editor
Golden lock and credit cards on keyboard

Image via Unsplash

October 14, 2024

Fidelity Investments announced it experienced a data breach. This breach, which occurred in mid-August, has affected a more than 77,000 customers.

Security leaders weigh in 

Mr. Venky Raju, Field CTO at ColorTokens:

“As the attackers were able to use their own accounts to access other customer accounts, it is clear that there are security misconfigurations in Fidelity’s customer-facing web applications. This attack vector is so well known and understood that it is ranked number one in OWASP’s Top 10 Web Application Security Risks. Termed ‘Broken Access Control’ by OWASP, one of the risks associated with this is permitting the viewing or editing of someone else’s account by providing its unique identifier. Attackers may have exploited this vulnerability to create new accounts at Fidelity and access other accounts.”

Sarah Jones, Cyber Threat Intelligence Research Analyst at Critical Start:

“The Fidelity data breach highlights the persistent threat faced by financial institutions and their customers. While the attackers’ specific motives remain unclear, it’s likely that information gathering was a primary objective. This information could be used for future attacks, such as identity theft, phishing campaigns, or even ransomware demands.

“The ‘beachhead’ theory, where attackers establish a foothold to launch further attacks, is a common tactic in such incidents. Although Fidelity assures customers that their accounts and funds were not directly accessed, the breach raises concerns about the security of personal information, increasing the risk of identity theft, fraud, or other malicious activities.

“Cyberattacks on financial institutions often involve a combination of techniques, such as phishing, social engineering, exploiting vulnerabilities, and credential stuffing. To mitigate these risks, banks and financial institutions should prioritize robust security measures, including multi-factor authentication, encryption, and regular vulnerability assessments. Educating employees about cybersecurity threats and best practices is crucial to prevent social engineering attacks. A comprehensive incident response plan is essential for promptly detecting and addressing security breaches. Continuous monitoring of networks and systems for suspicious activity is vital, along with adherence to relevant industry regulations and standards to ensure data privacy and security.

“The Fidelity data breach underscores the need for financial institutions to remain vigilant and proactive in protecting themselves and their customers from evolving cyber threats. By understanding common attack tactics and implementing robust security measures, institutions can better safeguard their assets and maintain customer trust.”

Mr. Piyush Pandey, CEO at Pathlock:

“It is of critical importance to have robust sensitive data and application access controls within financial institutions. The interconnectedness and intricacy of supply chains in the financial industry increases the difficulty of the management of, as well as the securing of, third-party access. Given how highly regulated this sector is when it comes to data protection and privacy, ensuring that third-party vendors adhere with these regulations is vital, yet continue to be a challenge.

“By focusing on rigorous controls testing and enforcement, including stringent management of third-party identities and access, financial institutions can significantly strengthen their security posture, protect sensitive data, and ensure compliance with regulatory requirements. This proactive approach not only safeguards customer data (and trust), it enhances the financial institution’s overall resilience against attacks like this.”

Marcus Fowler, CEO of Darktrace Federal:

“Financial institutions have historically been a top target for threat actors, given the very nature of their operations. In response, these organizations often have the most advanced and sophisticated cybersecurity programs. AI represents the greatest advancement in truly augmenting our cyber workforce and these organizations serve as an excellent example of how AI can be effectively applied to security operations to increase agility and harden defenses against novel threats. We encourage these organizations to facilitate open conversations around their successes and failures deploying AI to help other organizations across sectors accelerate their adoption of AI for cybersecurity.”

KEYWORDS: data breach finance cybersecurity financial security financial services security leaders

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Person using ATM

    Breach exposed information of more than 500,000 credit union members

    See More
  • Doctor

    Serviceaide Data Leak Impacts Nearly 500,000 Catholic Health Patients

    See More
  • Vertical lines of light

    More than 2,000 Palo Alto Networks firewalls compromised

    See More

Related Products

See More Products
  • Risk Analysis and the Security Survey, 4th Edition

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing