That kind of information is nearly public (not that it's OK but it seems a lot less damaging).
If more was, it would be good know.
User contact information – name, address, phone number and email
address – and internal JPMorgan Chase information relating to
such users have been compromised.
I have multiple personal and business accounts at Chase, and they collect a shitload of other "internal information", way beyond name, address, phone and email.Ostensibly for KYC [2] they try to collect personal information about the other members of my company, non-public information about my company's revenues and customers, my work and professional history, business plans and projections, my kids' college plans, real estate holdings, interests in other businesses, etc., etc., etc.
They're very pushy about gathering this information, claiming it's for regulatory compliance. I'm sure it's mostly for their own attempts to hawk their lame financial products.
So that category of "information relating to such users" could be ginormous.
[1] http://investor.shareholder.com/jpmorganchase/secfiling.cfm?...
Only have a couple of recurring bills with the card and don't generally use it at stores, so I'm pretty confident that it was due to the breach at Chase. My biggest concern is someone using the other information they stole to open accounts under my name.
If stealing card/account information was their goal, there are a lot easier ways to do it. Any time you use your card at a non-official ATM, put it down to pay at a restaurant or even not shredding any mail with account information, you're putting yourself at risk. Heck, account information can be social engineered out of people quite easily as well - your particular usage habits could have nothing to do with it.
Or am I just off in my understanding of fraud protection?
[1] https://www.schneier.com/blog/archives/2009/08/small_busines...
I could see that.