Skip to main content
  1. Home
  2. Computing
  3. Web
  4. Legacy Archives

‘Massive’ data security breach strikes JPMorgan Chase, Kroger, possibly others

Add as a preferred source on Google
security-breach-hack-hackers-epsilon
Image used with permission by copyright holder

What’s being described as a “massive” security breach at email marketing firm Epsilon has compromised the customer names and emails of some of the largest companies in the US, including seven of Fortune’s top 10 institutions, reports SecurityWeek.

Epsilon reportedly sends out 40 billion emails each year for more than 2,500 clients. SecurityWeek reports that clients of Epsilon affected by the infiltration include: TiVo, US Bank, JPMorgan Chase, Verizon, Capital One, Marriott Rewards, Ritz-Carlton Rewards, Citi, Brookstone, McKinsey & Co., New York & Co, Kroger and Walgreens.

Recommended Videos

Epsilon has refused to confirm the full list of companies hit by the breach. But the company tells Reuters that it is “cooperating with a number of authorities now, so I don’t know how long it (the investigation) will take.”

According to SecurityWeek, the data breach has put some customer email addresses of the second largest bank in the US, JPMorgan Chase, and the email addresses and names of Kroger, the largest grocery store chain in the country, in the hands of hackers.

“On March 30th, an incident was detected where a subset of Epsilon clients’ customer data were exposed by an unauthorized entry into Epsilon’s email system,” Epsilon said in a statement on Friday. “The information that was obtained was limited to email addresses and/or customer names only.”

Kroger sent out an email to customers letting them know that names and email addresses had been stolen, and to warn them that they may receive “phishing” emails as due to the Epsilon breach.

“As a result, it is possible you may receive some spam email messages,” Kroger said in the email. “We apologize for any inconvenience. Kroger wants to remind you not to open emails from senders you do not know. Also, Kroger would never ask you to email personal information such as credit card numbers or social security numbers. If you receive such a request, it did not come from Kroger and should be deleted”

SecurityWeek extends the possibility of phishing attacks to any company affected by the database break-in.

The situation for Chase and Citibank could potentially be more problematic. Epsilon manages the loyalty programs from Chase and Citi credit card customers. According to Computerworld, this includes information that may “be extremely valuable to criminals looking to steal banking information in phishing attacks.”

Chase said in a statement that it is “actively investigating to confirm” that, aside from email addresses, no other personal information was acquired by the hackers. The bank also tells Reuters that a “full investigation” is underway.

Citi released a statement via Twitter. The tweet read: “Please be careful of phishing scams via email. Statement from Citi for our valued Customers regarding Epsilon & email.” A link to a full statement was provided, which also warned customers of phishing attacks.

(Image via)

Andrew Couts
Features Editor for Digital Trends, Andrew Couts covers a wide swath of consumer technology topics, with particular focus on…
Google Play’s latest speed boost goes way beyond the phone
Play Store v52.1 targets app install performance across Android devices, including cars, TVs, watches, tablets, and phones.
Google Play Store Photo

Google is rolling out Play Store v52.1 with changes built around a practical Android problem, getting apps installed more smoothly on very different kinds of hardware.

The update focuses on Play Store infrastructure, with Google pointing to stability, performance, and better memory use while a device adds an app. That install path now has to work on phones, tablets, Wear OS watches, Google TV, Android TV, Android Auto, and cars running Android Automotive.

Read more
Peacock Premium Plus joins YouTube as the streaming bundle battle gets messier
The $16.99 subscription brings Peacock’s sports-heavy catalog into YouTube, with account details still unclear.
Adult, Female, Person

Peacock Premium Plus is now available through YouTube Primetime Channels, giving viewers a new way to add a major streaming service inside YouTube.

The $16.99-per-month subscription brings Peacock’s live sports, NBC and Bravo shows, originals, Universal movies, Telemundo programming, and Spanish-language FIFA World Cup 2026 coverage into YouTube’s channel marketplace.

Read more
OpenClaw lands on Android and iOS, turning your phone into a control hub for your AI agent
OpenClaw's mobile apps bring chat, voice, and approvals straight to your phone.
openclaw-ios-android-app

OpenClaw, the open-source AI agent that runs entirely on your own computer, just landed native apps for Android and iOS. The app does not run the AI itself. Instead, it connects to a private gateway you set up yourself on a Mac, PC, or Linux machine, turning your phone into a secure remote for everything that gateway can do.

https://twitter.com/openclaw/status/2071688039114342592

Read more