Data leak
β Supply Chain
SitusAMC Real Estate Finance Tech Breach - JPMorgan/Citi/Morgan Stanley Affected
Primary Source βIncident Details
SitusAMC (a financial technology provider serving 1,500+ clients including major US banks, real estate firms, and insurers) became aware of a breach on November 12, 2025, and notified all clients on November 22. Compromised data included corporate information such as accounting records, legal agreements, and potentially customer data of SitusAMC’s clients. Major affected institutions include JPMorgan Chase, Citigroup, and Morgan Stanley. No encrypting malware was involved; the incident was described as contained. No ransomware group claimed responsibility and no ransom demands were disclosed. The FBI stated no operational impact to banking services was identified. SitusAMC processes billions of documents related to real estate loans annually.
Technical Details
- Initial Attack Vector
- Unknown; no encrypting malware was involved; SitusAMC described it as a contained data exfiltration incident
- Vendor / Product
- SitusAMC (real estate debt/equity origination, transaction, and management platform)
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2025-11-12 Breach occurred
- 2025-11-22 Publicly disclosed
- 2025-11-22 Customers notified