Cybersecurity Gaps Exposed in US Treasury’s OCC Breach, 100 Bank Regulators’ Emails Compromised

Published on April 9, 2025
Written by:
Lore Apostol
Lore Apostol
Cybersecurity & Streaming Writer

The Office of the Comptroller of the Currency (OCC), an agency under the U.S. Treasury Department, revealed a major email system breach impacting its executives and employees.
Unidentified hackers monitored over 150,000 emails from June 2023 to February 2025.

The OCC confirmed on Tuesday that the breach, first identified on February 11, involved unauthorized access to sensitive information, including details tied to the financial condition of federally regulated financial institutions. 

The regulator, which oversees all national banks, federal savings associations, and federal branches of foreign banks, has initiated a detailed evaluation of its information security policies. The aim is to strengthen its defenses against future threats while ensuring faster detection and remediation of potential breaches.

For more than a year, hackers monitored employee emails at the Office of the Comptroller of the Currency, gaining access to highly sensitive financial information via about 103 bank regulators’ compromised emails, according to Bloomberg News. The attackers hijacked an administrator’s account. 

Although the extent of the intrusion remains unclear, no immediate impact on the broader financial sector has been reported.

The OCC disclosed the breach to Congress two weeks after its discovery. According to Acting Comptroller Rodney E. Hood, deeply rooted “organizational and structural deficiencies” played a significant role in allowing the security lapse. 

Hood emphasized there would be accountability measures to address the vulnerabilities and missed opportunities that contributed to the incident.

The OCC has not provided specific information on the technical flaws exploited during the breach, nor has it disclosed the identity of the actor responsible. Requests for further comment from the agency have thus far gone unanswered.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: