Desk live·
ForensicPost
Breaches/Third party/File 25-1112b

SitusAMC Attack Exposed Client Records Including JPMorgan Agreements

SitusAMC disclosed a cyberattack on 12 November 2025. Compromised material included accounting records and legal agreements belonging to clients including JPMorgan Chase, Citi and Morgan Stanley.

Constructed geometry · not a chart of case data
TargetSitusAMC
ActorUnattributed
D. Kennedy12 min readConfidence: high3 sources reviewed

SitusAMC, a vendor providing loan origination and servicing support for residential and commercial real estate, suffered a cyberattack on 12 November 2025. Reporting describes compromised corporate data including accounting records and legal agreements belonging to client institutions, among them JPMorgan Chase, Citi and Morgan Stanley.

Named Institutions, Unnamed Exposure

The corpus filed at 25-0814 that a compromise at an analytics vendor reached data belonging to customers of 74 banks and credit unions, and observed that seventy-four independent due-diligence processes established nothing about whether the vendor patched its perimeter.

This is the same structure at the top of the market. The institutions involved are among the largest and most heavily supervised financial firms in the world, with the most demanding third-party risk programmes in this database.

That is the finding. Vendor assessment at its most rigorous did not prevent this, which is consistent with the corpus’s repeated conclusion that the instrument measures the existence of a control framework rather than its operation.

Mortgage Servicing Accumulates Unusually Complete Files

A loan file contains income verification, tax returns, bank statements, employment history, property details and identity documents — assembled at origination because a lender requires all of it to make a decision.

It is arguably the densest financial record an ordinary person produces, and this desk made the same observation about credit applications at 25-1105. A servicing vendor holds those files for institutions the borrower has a relationship with, and has none itself.

What Is Not Established

The reporting this desk reviewed describes corporate data — accounting records and legal agreements — rather than consumer loan files. Whether borrower data was reached is not established here and we do not assert it.

That distinction matters for what follows, and it is the subject of 25-1124b.

How we reported this

Compiled from public reporting and regulatory guidance, listed below. The extent of any consumer data exposure is not established. Corrections: corrections@forensicpost.com.

Sources
  1. Major US banks impacted by SitusAMC hackSecurityWeek
  2. SitusAMC confirms breach of client data after cyberattackThe Register
  3. Initial guidance on responding to the SitusAMC data breachRopes & Gray
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary