The Bank of America has warned customers of the potential for data breaches after Infosys McCamish Systems was compromised last year.

The breach at Infosys McCamish Systems directly impacted their client, with the Bank of America confirming that approximately 57,000 people had their identity information stolen and exposed – including their name, addresses, date of birth and financial information.

It is unclear whether the bank learned lessons from similar, past incidents, where their providers’ systems which handled customer data on behalf of the bank were attacked.

This incident has compounded the need to improve IAM controls and data encryption across all integrating system providers and partners.

The MOVEit Transfer platform of Ernst & Young was compromised in May 2023 whilst being appointed as the accounting firm to handle data for Bank of America. Banks are a common target for attacks given the trove of data they hold as trust anchors.