NACHA Risk Alert: Notification of ACH Data Breach Incident
An ODFI in Green Bay, WI has informed NACHA of a breach of consumer-level data in accordance with NACHA’s Interim Policy on ACH Data Breach Notification Requirements. NACHA has provided both ACH Operators a list of affected RDFI routing numbers and contact information of the designated ODFI security representative for communications to RDFIs. The ACH Operators will follow their respective procedures to notify their ACH services customers.
This particular incident involves keylogging and is reportedly limited in its scope. However, the ODFI reported that (1) the breached data contains the consumer name, account number and routing number; and (2) they were not successful in communicating with all affected RDFIs.
ACH Data Breach Notification Requirements
A copy of NACHA’s Interim Policy on ACH Data Breach Notification Requirements, the Data Breach Notification Form, and the related ACH Operations Bulletin dated August 28, 2007 may be found online at:
http://www.nacha.org/DataBreach/default.htm