STOCK TITAN

Jack Henry Issues Statement on Response to Cybersecurity Incident

(Neutral)
(Neutral)
Tags

Jack Henry (Nasdaq: JKHY) reported a cybersecurity incident affecting a limited part of its internal, non-production corporate environment. According to Jack Henry, no client-facing or core banking systems were accessed or disrupted. Fewer than 10 clients had PII impacted, and the company deems the incident not financially material.

Loading...
Loading translation...

Positive

  • No disruption to client-facing systems, core platforms, or daily processing services
  • Personally identifiable information impacted for fewer than 10 clients
  • Company determined incident is not financially material
  • Rapid detection and containment by existing security controls
  • Provision of two years of credit monitoring for impacted accountholders
  • Engagement of independent cyber forensics firm and collaboration with law enforcement

Negative

  • Cybersecurity incident in internal, non-production corporate environment
  • Personally identifiable information (PII) data impacted for fewer than 10 clients
  • Involvement of an extortion attempt by a threat actor

News Explained

Jack Henry is offering two years of credit monitoring and says the extortion attempt will not result in a payment.

Jack Henry says it contained the incident and is continuing its investigation and response; it is offering two years of credit monitoring for impacted financial institutions to provide to their accountholders.

The company also says it will make no payment to the threat actor in response to the extortion attempt.

It has notified more than 7,200 clients and is working directly with affected clients.

The response includes an independent third-party cyber forensics firm and collaboration with federal law enforcement.

Market Context

JKHY had relatively low short positioning in the platform's current risk data. That context left the...
Analysis

JKHY had relatively low short positioning in the platform's current risk data. That context left the incident's operational containment and limited PII impact to weigh against cyber-response, client-trust, and disclosure risks.

Key Figures

Impacted clients: fewer than 10 clients Clients notified: more than 7,200 clients Credit monitoring: two years
3 metrics
Impacted clients fewer than 10 clients Personally identifiable information impacted
Clients notified more than 7,200 clients Incident notification
Credit monitoring two years Services offered to impacted financial institutions

Historical Context

5 past events · Latest: Aug 24 (Neutral)
Pattern 5 events
Date Event Sentiment 24h Move Catalyst
Aug 24 Board appointment Neutral +1.9% Richard Preece joined the board while Wes Brown planned to retire under policy.
Aug 24 Dividend announcement Positive +2.6% The board maintained the quarterly cash dividend at $0.61 per share.
Aug 20 Bank platform selection Positive +1.2% Prevail Bank selected Jack Henry's core processing and integrated technology solutions.
Aug 18 Fiscal earnings report Positive +6.5% Fiscal-year revenue, operating income, and EPS increased despite weaker fourth-quarter results.
Aug 11 Deconversion revenue Neutral +1.9% Fiscal-year deconversion revenue reached $42.8 million from client contract terminations.

24h Move is the share-price change in the day after each event; other market factors may also have contributed.

Pattern Detected

Recent positive company news generally coincided with gains, while neutral announcements produced mixed alignment; no comparable cybersecurity event appeared in the selected history.

Key Terms

social engineering, vishing, pii, cyber forensics
4 terms
social engineering technical
"a sophisticated social engineering attack commonly known as vishing"
Social engineering is the practice of manipulating people into revealing confidential information, granting access, or taking actions that compromise security, often by posing as a trusted person or using urgent, persuasive stories. For investors it matters because these scams can lead to direct financial loss, theft of sensitive corporate data, disrupted operations, or damage to a company’s reputation — similar to a con artist who tricks a business into handing over its keys.
vishing technical
"commonly known as vishing (voice phishing) initiated by a threat actor"
Vishing is a phone-based scam where a caller pretends to be a trusted person or organization to trick someone into revealing passwords, account numbers, or authorizing money transfers. It matters to investors because stolen credentials or coerced permissions can lead to unauthorized trades, drained accounts, or identity theft; think of it as a con artist posing as your bank on the phone to get the keys to your safe.
pii regulatory
"personally identifiable information (PII) data for fewer than 10 clients"
Personally Identifiable Information (PII) is any data that can identify or be used to contact a specific person, such as names, addresses, email, government ID numbers, phone numbers, or medical records. For investors, PII matters because mishandling or losing it can lead to regulatory fines, legal liability, customer loss and reputational damage—similar to a company misplacing the keys to customers’ identities, which can erode value and increase costs.
cyber forensics technical
"an independent third-party cyber forensics firm to support our investigation"
Cyber forensics is the practice of collecting, preserving, analyzing and presenting digital evidence from computers, servers, networks, and other electronic devices to determine how a cyber incident occurred and who or what caused it. It matters to investors because forensic findings reveal the scope of a breach, potential legal or regulatory exposure, and the integrity of a company’s systems — like an investigator reconstructing a crime scene to show what was taken and how severely the business was affected.

AI-generated analysis. How Rhea-AI works. Not financial advice.

See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google

MONETT, Mo., Aug. 31, 2026 /PRNewswire/ -- Jack Henry & Associates Inc.® (Nasdaq: JKHY) today issued the following statement on its response to a recent cybersecurity incident:

New Logo

"Jack Henry recently detected a cybersecurity incident within a limited portion of our internal, non-production corporate environment. No client-facing systems, operating systems, core platforms, or daily processing services were accessed or disrupted, and they all remain secure and fully operational. We did not experience any system outages.

Protecting the financial institutions we serve and maintaining transparency are fundamental to everything we do at Jack Henry. We recognize and deeply regret any concern this incident may cause to our clients and their accountholders. Based on our investigation to date, personally identifiable information (PII) data for fewer than 10 clients was impacted. We have notified our more than 7,200 clients that an incident occurred, and we are working directly with the affected clients. We are offering two years of credit monitoring services to impacted financial institutions to provide to their accountholders.

Based on our investigation, the incident began with a sophisticated social engineering attack commonly known as vishing (voice phishing) initiated by a threat actor identified as ShinyHunters. Our security controls operated as intended to rapidly detect and contain the unauthorized activity. Upon detection, our teams immediately deployed specialized protocols to secure the network, isolate affected systems, and further heighten safeguards. We partnered with an independent third-party cyber forensics firm to support our investigation and response efforts and are actively collaborating with federal law enforcement.

This incident involved an extortion attempt, and we are not making any payment to the threat actor. We have determined that the incident is not financially material to the company.

Cyber incidents are an industry-wide reality, and our commitment to standing as a vigilant line of defense remains absolute. Through proactive monitoring and our rapid response framework, we effectively mitigated the threat and maintained operational integrity.

We deeply value the trust our clients place in Jack Henry and will continue to keep them informed as part of our commitment to transparency."

About Jack Henry & Associates, Inc.®
Jack Henry® (Nasdaq: JKHY) is a well-rounded financial technology company that strengthens connections between financial institutions and the people and businesses they serve. We are an S&P 500 company that prioritizes openness, collaboration, and user centricity – offering banks and credit unions a vibrant ecosystem of internally developed modern capabilities as well as the ability to integrate with leading fintechs. For 50 years, Jack Henry has provided technology solutions to enable clients to innovate faster, strategically differentiate, and successfully compete while serving the evolving needs of their accountholders. We empower more than 7,200 clients with people-inspired innovation, personal service, and insight-driven solutions that help reduce the barriers to financial health. Additional information is available at www.jackhenry.com

Cision View original content to download multimedia:https://www.prnewswire.com/news-releases/jack-henry-issues-statement-on-response-to-cybersecurity-incident-302865383.html

SOURCE Jack Henry & Associates, Inc.

FAQ

What cybersecurity incident did Jack Henry (JKHY) report on August 31, 2026?

Jack Henry reported detecting a cybersecurity incident in a limited part of its internal, non-production corporate environment. According to Jack Henry, client-facing systems and core banking platforms were not accessed or disrupted, and all operations remained secure and fully functional during the event.

Were Jack Henry (JKHY) client-facing systems impacted by the August 2026 cyber incident?

According to Jack Henry, no client-facing systems, operating systems, core platforms, or daily processing services were accessed or disrupted. The company stated that these systems remained secure, fully operational, and experienced no outages while the cybersecurity incident was contained internally.

How many Jack Henry (JKHY) clients had PII affected in the August 31, 2026 breach?

Jack Henry reported that personally identifiable information (PII) data for fewer than 10 clients was impacted. According to Jack Henry, more than 7,200 clients were notified of the incident, and the company is working directly with the affected clients to manage follow-up and mitigation steps.

What support is Jack Henry (JKHY) offering after the August 2026 cybersecurity incident?

Jack Henry is offering two years of credit monitoring services to impacted financial institutions for their accountholders. According to Jack Henry, this support is part of its response while it works directly with affected clients and continues its investigation with third-party forensic experts.

Is the August 31, 2026 Jack Henry (JKHY) cyber incident financially material to the company?

Jack Henry determined that the August 2026 cybersecurity incident is not financially material to the company. According to Jack Henry, security controls rapidly contained the event, operations continued without outages, and no payment is being made related to the associated extortion attempt.