SitusAMC, a vendor that manages real-estate loan and mortgage functions on behalf of more than 1,500 banks and financial institutions, disclosed on Saturday, November 23, that it had suffered a cyberattack roughly two weeks earlier, on November 12, 2025. The company says the incident is now contained and its services are fully operational, but the breach has already been publicly tied to at least one major bank: JPMorgan Chase.

SitusAMC said attackers accessed banks' accounting records, legal agreements, and customer information belonging to some of its clients. The company has declined to say who was behind the attack, how many clients were affected in total, or how many individual customer records were exposed — leaving the full scope of the incident unclear more than a week after disclosure. No ransomware was involved, according to the company.

The FBI's reassurance, and its limits

The FBI is investigating alongside SitusAMC. FBI Director Kash Patel said the bureau has "identified no operational impact to banking services" — a statement about operational continuity, not about the confidentiality of the data that was taken. Accounting records and legal agreements exposed in a breach like this one don't stop a bank's services from running, but they can still contain sensitive counterparty information, loan terms and client details that are valuable to attackers for fraud, extortion or follow-on social engineering long after the "operational impact" question is answered.

The vendor most people have never heard of

SitusAMC is not a household name, and that is precisely the point security researchers keep making about this category of breach. Major banks pour enormous resources into securing their own networks, but they route enormous volumes of loan servicing, accounting and legal documentation through specialized vendors like SitusAMC that don't receive anywhere near the same level of security scrutiny — despite sitting on data just as sensitive as what the banks themselves hold.

That mismatch is what makes financial-sector supply-chain attacks so persistent: an attacker who can't get through a top-tier bank's own defenses can often reach the same underlying data by going through a smaller vendor several steps removed from the bank's brand and public accountability, where security investment historically hasn't kept pace with the sensitivity of what's being processed. As banks lean further into third-party servicing relationships to cut costs, incidents like the SitusAMC breach are likely to keep surfacing — not because any single vendor is uniquely negligent, but because the industry's security spending still tends to concentrate at the institutions with the recognizable names, not the vendors quietly processing the paperwork behind them.