Citi says 360,000 accounts hacked in May cyber attack

NEW YORK/HONG KONG Thu Jun 16, 2011 3:37pm EDT

Pedestrians are reflected in the window of a Citibank branch in Boston, July 17, 2009. REUTERS/Brian Snyder

Pedestrians are reflected in the window of a Citibank branch in Boston, July 17, 2009.

Credit: Reuters/Brian Snyder

Related Topics

NEW YORK/HONG KONG (Reuters) - Citigroup Inc said a cyber attack in May affected almost twice as many accounts as the bank's figures had initially suggested, as major U.S. lenders come under growing pressure from lawmakers to improve account security.

A total of 360,083 North American Citigroup credit card accounts were affected by the breach, the third-largest U.S. bank by assets said in a statement released late on Wednesday.

Of those affected, some 217,657 customers were reissued with new cards along with a notification letter, while the remaining accounts were either inactive or had already received new cards earlier, the bank added.

Citigroup had earlier said that about 1 percent of its North American accounts were affected. The bank's annual report puts the total number of its customers at 21 million.

"It is mainly due to the actual number of accounts being more than what's in the 2010 annual report as well as variances such as some of the accounts being closed," United States-based Citi spokesman Sean Kevelighan said in an emailed response.

Customers had their names, account numbers and contact information accessed, but Citi said that "data critical to commit fraud was not compromised" and that other consumer banking online systems were not accessed.

Citigroup also said it identified "the majority" of accounts compromised within seven days, adding that the information was accessed on the accounts by May 24 but that it only started notifying customers of the breach on June 3.

"What Citi should have done upon finding out is to call for a press conference to announce the news, reassure customers that they take this in utmost seriousness, and to personally reach out the affected accounts," said Li-May Chew, associate research director at IDC Financial Insights.

LUCRATIVE TARGETS

The bank is the latest in a growing list of companies to face cyber attacks in recent months, with Sony, Google Inc and Lockheed Martin all having suffered under hackers this year.

In response to the latest bout of attacks, many banks have stepped up their security effort, with two Australia-based banks -- ANZ and Westpac -- replacing their customers' "SecurID" electronic keys earlier this month.

"Cyber hackers are no longer interested in just stealing money directly," said Edison Yu, industry manager at consultancy Frost and Sullivan.

"They are more interested in stealing peripheral information such as contact details and ID numbers that can be sold on the black market later," Yu said, adding that the global black market for email addresses and national ID numbers is now worth about $5 billion, making it a lucrative area for hackers looking to steal contact information.

Regulators in many countries have also been preparing new measures on data security, with the head of the Federal Deposit Insurance Corp in the United States saying last week she may "ask some banks to strengthen their authentication when a customer logs onto online accounts."

The Hong Kong Monetary Authority also said it requires banks to have risk management systems to ensure the adequacy of their security systems.

"Banks are expected to continue to review their security measures in place to enhance the controls, where appropriate, on an ongoing basis," said an HKMA spokeswoman.

(Editing by Lincoln Feast and Muralikumar Anantharaman)

FILED UNDER:
We welcome comments that advance the story through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can flag it to our editors by using the report abuse links. Views expressed in the comments do not represent those of Reuters. For more information on our comment policy, see http://blogs.reuters.com/fulldisclosure/2010/09/27/toward-a-more-thoughtful-conversation-on-stories/
Comments (4)
minipaws wrote:
I am sick of Citi sending me a new credit card every 6 months because they’ve been hacked. All of my auto payments get screwed up. They need to get their security act together.

Jun 16, 2011 10:21am EDT  --  Report as abuse
minipaws wrote:
I am sick of Citi sending me a new credit card every 6 months because they’ve been hacked. All of my auto payments get screwed up. They need to get their security act together.

Jun 16, 2011 10:22am EDT  --  Report as abuse
Nyikayedu wrote:
Overdraft by $2- Penalty is $30
Expose over 300000 accounts to millions in losses- Penalty is CEO gets raise.

Jun 16, 2011 12:28pm EDT  --  Report as abuse
This discussion is now closed. We welcome comments on our articles for a limited period after their publication.