Figure Technology Solutions and Jack Henry: Jack Henry refuses to pay extortionists after data theft

Figure Technology Solutions and Jack Henry: Jack Henry refuses to pay extortionists after data theft

Jack Henry Refuses Ransom Demand After Data Breach; ShinyHunters Threat Fizzles

Jack Henry, a major U.S. financial technology provider, confirmed it was targeted in a ransomware extortion attempt by the cybercriminal group ShinyHunters but refused to pay. The hackers set a deadline for payment before leaking stolen data, yet no files were published after the deadline passed.

The breach exposed personal information belonging to account holders at fewer than 10 client institutions, though the exact number of affected individuals remains undisclosed. Jack Henry, which supports over 1,600 banks and credit unions with core processing systems and serves an additional 5,600 financial institutions, stated that no client-facing systems or daily operations were disrupted.

The attack began with a vishing (voice phishing) scheme, where ShinyHunters impersonated trusted contacts to obtain credentials. The intrusion was contained to a non-production corporate environment, and the company detected the breach "recently," though it has not specified the timeline of the attack or discovery.

Jack Henry notified all 7,200+ clients and is offering two years of credit monitoring to affected institutions for their account holders. However, under federal regulations, financial institutions not Jack Henry are responsible for notifying impacted customers. The reporting timeline depends on whether the affected clients are banks (36-hour notice to regulators) or credit unions (72-hour notice to the NCUA).

ShinyHunters has a history of targeting financial services, including breaches at TransUnion (4.4M records, August 2025), Betterment, and Figure Technology Solutions. While the group has previously followed through on threats, this incident marks a rare public refusal to pay, aligning with U.S. government guidance discouraging ransom payments.

Financial institutions paid $365.6 million in ransomware extortion between 2022 and 2024, the highest of any industry, according to a 2025 FinCEN report. Despite federal warnings, many organizations continue to pay to avoid data leaks or operational disruptions.

Source: https://www.americanbanker.com/news/jack-henry-refuses-to-pay-extortionists-after-data-theft

Jack Henry Banking cybersecurity rating report: https://www.rankiteo.com/company/jack-henry-banking

Figure cybersecurity rating report: https://www.rankiteo.com/company/figuretechnologies

"id": "JACFIG1788589594",
"linkid": "jack-henry-banking, figuretechnologies",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Fewer than 10 client '
                                              'institutions (exact number of '
                                              'individuals undisclosed)',
                        'industry': 'FinTech',
                        'location': 'U.S.',
                        'name': 'Jack Henry & Associates',
                        'size': 'Supports over 1,600 banks and credit unions, '
                                'plus 5,600 additional financial institutions',
                        'type': 'Financial Technology Provider'}],
 'attack_vector': 'Vishing (Voice Phishing)',
 'customer_advisories': 'Financial institutions responsible for notifying '
                        'impacted customers',
 'data_breach': {'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'Personally identifiable information '
                                        '(PII)',
                 'type_of_data_compromised': 'Personal information'},
 'description': 'Jack Henry, a major U.S. financial technology provider, '
                'confirmed it was targeted in a ransomware extortion attempt '
                'by the cybercriminal group ShinyHunters but refused to pay. '
                'The hackers set a deadline for payment before leaking stolen '
                'data, yet no files were published after the deadline passed. '
                'The breach exposed personal information belonging to account '
                'holders at fewer than 10 client institutions.',
 'impact': {'data_compromised': 'Personal information of account holders at '
                                'fewer than 10 client institutions',
            'downtime': 'No disruption to client-facing systems or daily '
                        'operations',
            'identity_theft_risk': 'Potential for affected account holders',
            'operational_impact': 'Minimal; contained to non-production '
                                  'environment',
            'systems_affected': 'Non-production corporate environment'},
 'initial_access_broker': {'entry_point': 'Vishing (voice phishing)'},
 'motivation': 'Extortion',
 'post_incident_analysis': {'root_causes': 'Vishing attack leading to '
                                           'credential compromise'},
 'ransomware': {'data_exfiltration': 'Threatened but not executed',
                'ransom_demanded': 'Yes (amount undisclosed)',
                'ransom_paid': 'No'},
 'references': [{'source': 'FinCEN Report'}],
 'regulatory_compliance': {'regulatory_notifications': 'Financial institutions '
                                                       'required to notify '
                                                       'regulators (36-hour '
                                                       'for banks, 72-hour for '
                                                       'credit unions)'},
 'response': {'communication_strategy': 'Notified clients; financial '
                                        'institutions responsible for customer '
                                        'notifications under federal '
                                        'regulations',
              'containment_measures': 'Intrusion contained to non-production '
                                      'corporate environment',
              'remediation_measures': 'Notified all 7,200+ clients; offering '
                                      'two years of credit monitoring to '
                                      'affected institutions'},
 'stakeholder_advisories': 'Notified all 7,200+ clients',
 'threat_actor': 'ShinyHunters',
 'title': 'Jack Henry Ransomware Extortion Attempt by ShinyHunters',
 'type': 'Ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.