Skip to main content
Close
Security

Jack Henry: When the Vendor Falls, the Bank Falls Too

Gabriel Ferraresi· CEO | Tech86October 2, 20263 min
fourth-partycore-bankingvishingransomwarerisk-managementthird-party

The entry point for the month’s biggest vendor incident was not a zero-day. It was the phone.

Jack Henry, a core banking provider for thousands of US institutions, confirmed a security incident following a vishing campaign: criminals impersonating trusted contacts over phone calls. No endpoint protection stops someone who answers and trusts.

The official picture and the circulating one

The company’s statement points to an internal corporate environment, outside production. Specialized press reports several terabytes taken, including client profiles and confidential documents, extortion refused, and circulating attribution to the ShinyHunters group.

Both versions can be true at once, and that is precisely the lesson: an incident contained at a vendor serving thousands of banks is not a local event, it is a systemic case. When someone’s core banking goes down, the institution goes down with it. We have already covered ransomware’s move against Brazilian banks with The Gentlemen and the Fortigate worm: financial chains are targets where the edge falls and the node yields.

The fourth participant of the chain

For anyone operating in Brazil, the lesson is regulatory and practical at once. The Central Bank already requires third-party risk management under Resolutions 4.893 and 5.274. The paperwork is covered.

The gap is scope: due diligence reviews the third party, the direct vendor. The fourth participant of the chain, the vendor’s vendor, rarely appears. Where the data truly rests, which platform the vendor runs, who administers that platform: that is the layer where risk silently accumulates.

The right mental model is the same one from the hypervisor attacks: risk concentrators. A vendor serving thousands of institutions is a hypervisor for the financial sector: compromise one point and you reach every workload at once.

Why the phone beat the zero-day

The detail that deserves more attention than the terabytes: the entry was vishing. A human answered, trusted, and handed over what the attacker needed.

That changes the algebra of the security budget. No tool patches trust. The human link is the cheapest to train and the most expensive to neglect, and the cadence of 2026’s major incidents (vendors, supply chains, social engineering) shows where the groups’ effort is going.

In the audits I run, the cheapest test remains calling your own team while impersonating a vendor. If the call gets through, the entire security budget is guarding the wrong doors. Training whoever answers the phone is worth more than buying one more tool.

What the diligent institution does now

Three moves come out of this case without a new budget:

  1. Map the fourth participant of every critical vendor and record where the data actually rests.
  2. Put an incident-notification SLA into contracts, with deadline, minimum content, and access to evidence. Without the clause, you learn from the press.
  3. Design degradation without the vendor: what operations does the day the core banking stops, with client and regulator communication.

None of the three requires new technology. They require the decision to look beyond the first ring, which is exactly where almost nobody looks.

There is a fourth move, and it is organizational: treat vendor risk as recurring, not annual. The chain changes (your vendor signs a new platform, that platform signs a new data center, a key employee leaves), and the fourth participant of January is not the fourth participant of July. A quarterly one-hour review of the critical-vendor map costs less than any of the terabytes this case is measuring.

Conclusion

The Jack Henry case is not about one vulnerable American vendor. It is about the financial sector’s architecture of trust: thousands of institutions diligence the third party and inherit the fourth party’s risk without knowing its name.

Your most critical vendor has been audited. And the vendor’s vendor? If the answer is "I don’t know", that is this week’s due diligence. Your team’s phone is ringing too: the only question is whether whoever answers has been trained for the call that is coming.

Interested in this solution?

Explore our managed services and infrastructure.

Perimeter shielding and incident response

Frequently Asked Questions

Jack Henry, a core banking provider for thousands of US institutions, confirmed a security incident initiated by a vishing campaign: criminals impersonating trusted contacts over phone calls. The company’s official statement points to an internal corporate environment, outside production. Specialized press reports several terabytes taken, including client profiles and confidential documents, extortion refused, and circulating attribution to the ShinyHunters group.

It is the risk of the fourth participant in the chain: your vendor’s vendor. You perform due diligence on the direct vendor (the third party), but you rarely audit who stands behind them. When someone’s core banking provider suffers an incident, the client institution goes down with it, even having done everything right on the first ring.

Resolutions 4.893 (cybersecurity, 2021) and 5.274 (2024) require third-party risk management from financial institutions, including vendor selection criteria, monitoring, and incident response. The typical gap is not on paper, it is in scope: due diligence rarely sees beyond the first ring of the chain.

Because it is cheaper. No endpoint protection stops someone who answers and trusts: vishing exploits the human link, which has no patch. The month’s highest-impact attack on US financial infrastructure started with a phone call, and that should recalibrate where security budgets go.

Three things: map the vendors behind your critical vendors (the fourth participant), run an authorized vishing drill on your own team, and revise contracts to require an incident-notification SLA. The cheapest test remains calling your own team while impersonating a vendor: if the call gets through, the budget is guarding the wrong doors.

Blog — Get in Touch

Have a question about our articles or services? Our team is ready to help.

Schedule a Meeting

Book a time slot.

Schedule Now

Email

Send us a message.

[email protected]

WhatsApp

Quick conversation.

Address

Avenida Paulista, 1636 - São Paulo - SP - 01310-200

Tech86 Specialist

Online now

Hello! How can we help scale your business today?

Tech86 Engineering

We Value Your Privacy

We use cookies and similar technologies to optimize your experience, analyze site traffic, and personalize content. By clicking "Accept All", you agree to the use of all cookies. Read our Privacy Policy.