Skip to content

Mainframe hacks and consequences

The true cost of a data breach is notoriously difficult to calculate, but one thing is clear: it can be staggering. Multi-year litigation, ongoing response efforts, and settlement costs can sometimes reach into the billions. Moreover, most breaches are not direct attacks on mainframe systems, but rather exploits of open systems and web components that then move laterally, causing significant harm to mainframe data. While details on mainframe involvement are often scarce, the high-profile companies listed in this article all utilize mainframes.

Notable cyber attacks involving mainframes

The examples below highlight breaches where mainframes might have been involved due to the industries and data types affected. However, specific details about the role of mainframes in each incident are typically not disclosed by the companies involved.


#1. Equifax — 2017

What happened

In one of the most infamous data breaches in U.S. history, Equifax announced on September 7, 2017, that hackers had exfiltrated the personal data of approximately 147 million Americans—nearly half the country. The breach stemmed from an unpatched Apache Struts vulnerability (CVE-2017-5638) in a consumer-facing web application. Though the patch had been available for months, Equifax failed to apply it across all systems.

Attackers used the exploit to gain root access to a public-facing web server, then moved laterally into internal systems. They stole certificates, accessed encrypted credentials, and eventually reached core infrastructure, including the systems that housed credit reports, identity records, and dispute-processing applications.

The hackers maintained access for at least 76 days, operating undetected. They built 30+ custom SQL queries, triggering thousands of data pulls, all while hiding in encrypted outbound traffic. The breach went unnoticed until July 29, 2017, when suspicious outbound activity was finally flagged.

By then, the attackers had made off with names, Social Security numbers, dates of birth, driver’s license details, and in some cases, credit card numbers and dispute records. The fallout led to a CEO resignation, multiple congressional hearings, and at least $1.38 billion in remediation costs.

For more information and the Mainframe involvement visit Equifax

#2. Anthem — 2015

What happened

In late 2014, attackers launched a phishing campaign targeting Anthem, one of the largest health insurers in the United States. A single employee clicked a malicious link, enabling attackers to gain access to internal systems. They quickly escalated privileges, established remote command and control, and spent several weeks mapping out Anthem’s infrastructure.

Ultimately, they were able to access a database containing nearly 79 million member records—names, birthdates, Social Security numbers, addresses, phone numbers, and email accounts. Unlike many other healthcare breaches, no medical records were stolen—only identity-related PII. Still, the scale of the breach made it the largest healthcare-related breach in U.S. history at the time.

Anthem disclosed the breach in early February 2015. The U.S. Department of Health & Human Services (HHS) later imposed a $16 million HIPAA settlement, the largest to date. Total costs exceeded $260 million, including legal fees, credit monitoring, and technology upgrades.

For more information and the Mainframe involvement visit Anthem

#3. U.S. Office of Personnel Management — 2015

What happened

Between 2014 and 2015, attackers believed to be linked to Chinese state-sponsored groups infiltrated the U.S. Office of Personnel Management (OPM) in one of the most consequential breaches of U.S. government data. The hackers initially gained access using stolen credentials from a contractor with privileged access. Over time, they escalated privileges, moved laterally, and remained undetected for more than a year.

The breach exposed the sensitive background investigation files of 21.5 million people—including federal employees, military personnel, and contractors—along with 5.6 million sets of fingerprints. These files, stored as SF-86 forms, contain deeply personal data such as family relationships, foreign contacts, mental health history, financial details, and security clearances.

Much of this information resided in legacy systems, many of which were hosted on IBM z/OS mainframes. Attackers exfiltrated data using custom malware that mimicked normal network traffic, allowing them to bypass intrusion detection systems and avoid setting off alarms.

The breach was disclosed in two phases during June and July 2015. Fallout included the resignation of OPM’s director, a full IT system overhaul, and over $500 million spent on credit monitoring, system modernization, and breach response.

For more information and the Mainframe involvement visit U.S. Office of Personnel Management

#4. UnitedHealth / Change Healthcare — 2024

What happened

On February 21, 2024, Change Healthcare—a major U.S. healthcare clearinghouse and UnitedHealth Group subsidiary—was hit by a ransomware attack attributed to the ALPHV/BlackCat group. Attackers gained access via compromised credentials to a Citrix remote-access server that lacked multi-factor authentication. They escalated privileges, exfiltrated approximately 6 terabytes of protected health information (PHI), and deployed ransomware across hundreds of systems.

The breach paralyzed Change Healthcare’s transaction pipelines, including pharmacy claims, insurance eligibility verification, prior authorization systems, and back-end medical billing. For weeks, providers nationwide resorted to paper-based workarounds or paused billing altogether. Many practices suffered severe revenue disruption, with some on the verge of closure. UnitedHealth Group confirmed a $22 million ransom was paid, although the attackers reportedly conducted an exit scam—keeping the money without returning the data.

As of early 2025, UnitedHealth estimates the breach has cost $2.87 billion in response costs, financial assistance, lost revenue, and recovery. The number of individuals impacted has been updated to approximately 190 million, making this the largest healthcare data breach ever reported in the U.S.

For more information and the Mainframe involvement visit UnitedHealth / Change Healthcare

#5. Industrial & Commercial Bank of China — 2023

What happened

On November 8, 2023, the U.S. broker-dealer unit of the Industrial and Commercial Bank of China (ICBC), the world’s largest bank by assets, was hit by a major ransomware attack. The perpetrators were linked to LockBit 3.0, a notorious ransomware-as-a-service group with ties to Russian-speaking cybercriminal networks.

The attack exploited a critical zero-day vulnerability known as Citrix Bleed (CVE-2023-4966), which allowed unauthenticated access to internal Citrix systems. Once inside ICBC’s environment, the attackers moved quickly—dumping credentials, disabling endpoint protection, and deploying encryption payloads across both distributed systems and core infrastructure.

What made this attack globally significant was its timing and target. ICBC’s U.S. operation handles the clearing and settlement of U.S. Treasury trades. Following the attack, the bank was forced to revert to manual operations. Staff resorted to using USB drives to transfer trade details between systems and relied on Gmail accounts to coordinate with partners like BNY Mellon and the Depository Trust & Clearing Corporation (DTCC). The disruption caused an estimated $9 billion in unsettled trades and rattled confidence in one of the world’s most liquid markets.

Although ICBC did not publicly confirm whether z/OS systems were directly encrypted, numerous indicators point to core back-office infrastructure—likely powered by IBM mainframes—being at least partially disabled during the incident. The attack also exposed broader risks in how distributed front-ends and centralized back-ends are interconnected in hybrid banking architectures.

For more information and the Mainframe involvement visit Industrial & Commercial Bank of China

The slew of high-profile hacks, including Home Depot (2014), Anthem (2015), and Experian (2015), has compromised the personal information of millions of users, leaving them vulnerable to identity theft, phishing, and financial loss. Although the mainframe was not directly breached in every case, in many cases, sensitive data typically managed on mainframes was accessed or exfiltrated, even if the breach originated elsewhere, underscoring the importance of robust security measures and vigilant monitoring.

An analysis of these major hacks reveals a stark truth: many breaches can be traced back to preventable errors. Phishing attacks, third-party vulnerabilities, weak passwords, outdated software, lack of encryption, inadequate monitoring, human error, and poor segmentation all contributed to these devastating breaches. By addressing these common vulnerabilities and prioritizing proactive security measures, companies can significantly reduce the risk of falling victim to a similar breach, safeguarding their customers’ sensitive information and their own reputation. By learning from these incidents, we can work towards a safer, more secure digital landscape.

The total cost of a breach is difficult to calculate, and published figures often only reflect the initial costs of response and remediation. The long-term expenses, including litigation, legal settlements, and reputational damage, can far exceed the initial estimates, making proactive security measures a wise investment for any organization handling sensitive data.

Back To Top

Based on your location, we think you may prefer the Vertali APAC site where you’ll get regional content, offerings and contacts.

Dismiss