Your Core Provider Says an Incident Occurred. Your 72-Hour Clock May Have Already Started.
On August 31, 2026, Jack Henry issued a statement about a cybersecurity incident. The company said it notified more than 7,200 clients that an incident had occurred, and that personally identifiable information for fewer than 10 clients was impacted.
If you are one of the 7,200, you received a notice telling you something happened. If you are not one of the fewer than 10, you may not have been told that yet.
That space between the two is where your regulatory obligation lives. It is worth understanding before you are in it.
What the company said, and what it did not
Jack Henry's statement is specific in places and silent in others. Both matter.
The company said the incident involved a limited portion of its internal, non-production corporate environment. It said no client-facing systems, operating systems, core platforms, or daily processing services were accessed or disrupted, and that there were no system outages. It attributed the initial vector to a vishing attack by a threat actor it identified as ShinyHunters, and said its controls detected and contained the activity. It engaged an outside forensics firm, is working with federal law enforcement, refused an extortion demand, and determined the incident is not financially material to the company. It is offering two years of credit monitoring to impacted institutions to pass along to their accountholders.
Here is what the statement does not say.
It does not say how many individual accountholders sit behind those fewer than 10 client institutions. It does not identify which data fields were involved. It does not say when the access began. And it does not say whether the investigation has finished identifying everything that was copied.
The "fewer than 10 clients" figure counts institutions, not people. That distinction has been lost in some of the coverage, and it is the difference between a small incident and an unknown one.
For scale, Jack Henry's client base breaks down to roughly 1,600 institutions running its core account and transaction systems, plus about 5,600 more buying other products, according to the company's most recent annual report as reported by American Banker. And in a November 2025 request for information, the OCC noted that the three largest core providers together served more than 70 percent of U.S. depository institutions in 2022.
Where your clock starts
If you are a federally insured credit union, your obligation sits in 12 CFR 748.1(c), effective September 1, 2023.
Read the trigger carefully, because it has two prongs.
You must notify NCUA as soon as possible and no later than 72 hours after you reasonably believe you have experienced a reportable cyber incident, or after you receive notification from a third party regarding a reportable cyber incident.
Read that second prong closely, because the qualifier does the work. The notice has to concern a reportable cyber incident, which the rule defines as one causing a substantial loss of confidentiality, integrity, or availability through unauthorized access to or exposure of sensitive data, disrupting vital member services, or seriously affecting the safety and resiliency of operational systems. A vendor telling you that an incident occurred somewhere in its environment does not by itself establish any of that.
What it does establish is a duty to find out quickly. NCUA's current guidance, Letter to Credit Unions 25-CU-02, which updated 23-CU-07, treats notification from a third party that sensitive data has been compromised or business operations disrupted as starting the 72 hours.
Note what the standard is not. It is not confirmation. It is not the completion of your investigation. It is reasonable belief. NCUA has said the 72-hour notification is an early alert and does not require you to have finished assessing the incident.
The federal banking agencies use a different test. Notice is generally due within 36 hours after a banking organization determines that a computer-security incident has risen to the level of a notification incident. Shorter clock, and a trigger built on determination rather than reasonable belief. If you sit in a structure with both charters, analyze each rule separately rather than running one process.
A notice sent to more than 7,200 clients while the vendor works directly with the affected ones is the hardest version of this rule to run. You have been told an incident occurred. You do not yet know whether it reached your data, or whether it meets the definition. Treat that notice as the start of a documented investigation, not as proof your clock has started and not as permission to wait on the vendor. Decide now, in writing, who makes the reporting call and what they need to see.
Vendor materiality is not your materiality
Jack Henry said the incident is not financially material to the company. That sentence is doing specific work, and it is not about you.
Materiality in that context is a securities-law judgment about what a reasonable investor in a public company would consider important. It speaks to Jack Henry's shareholders.
It says nothing about whether member data was affected at your credit union, whether your examiner will want to see your file on this, or whether your own notification analysis under 748.1(c) comes out yes or no. Those are separate questions under separate rules with separate audiences.
The operational statement and the data statement answer different questions. Saying core platforms were not accessed or disrupted addresses access to those systems and service availability. It does not establish that nothing left the separate non-production environment where the incident happened. Read each vendor statement against the scope it actually claims.
The pattern behind the incident
NCUA's most recent Cybersecurity and Credit Union System Resilience Report went to Congress on June 17, 2026. It counts 588 cyber incident reports between May 1, 2025 and April 30, 2026. The prior report counted 539 for the year before that. Both group incidents into ATM jackpotting, phishing and business email compromise, ransomware, and third-party provider incidents, and both state that no reported incident was systemic to the credit union system.
The June 2026 report does name one number that moved. Credit unions reported 40 known business email compromise instances in the period, against 27 the year before.
What neither recent report contains is a third-party percentage. The only one NCUA has published came in June 2024: of 892 incidents between September 1, 2023 and May 1, 2024, roughly 73 percent involved a third party. Treat that as a historical measure of an eight-month window, not as a current rate.
The direction still holds, and the June 2026 report keeps third-party risk on its threat list, noting that using service providers may leave a credit union without visibility into vendor controls and security posture. Much of what you report will not be something that happened to you. It will be something that happened to somebody you pay.
What to do now
Write down who owns the reporting call. Name a person and a backup, and give them authority to escalate and file once the institution concludes an incident is reportable. Because the clock runs from reasonable belief rather than from certainty, the process needs legal, compliance, and security input without letting any one of them become a blocking step.
Build the file at hour zero, not hour seventy. When a vendor notice arrives, start a timestamped record immediately: when the notice arrived, what it said, what you asked the vendor, when you asked, and what came back. Whether or not you end up reporting, that record is what an examiner will generally want to see.
Send the vendor a specific question, in writing, the same day. Not "are we affected." Ask whether your institution's data was within the scope of the compromised environment, when the vendor expects to be able to answer that, and what it has already ruled out. A vague answer is itself information, and having asked in writing on day one is worth having.
Pull your notification clauses this quarter. Go through your core, digital banking, and card processing agreements and find out what each vendor actually owes you and by when. Many agreements commit to telling you an incident occurred and commit to nothing about telling you whether your data was in it. That is the gap that turns into a scramble. It is also negotiable at renewal.
Check your accountholder notification path separately. Appendix B to 12 CFR Part 748 governs member notice and is a different obligation from the 72-hour report to NCUA. Two clocks, two audiences. Know which of your third parties would be doing the notifying and which leaves it to you.
If you are a fintech or a payments company rather than a credit union, 748.1(c) does not apply to you. Your obligations sit elsewhere, in your state breach notification statutes, your GLBA obligations, your sponsor bank agreements, and your own customer contracts. The reasoning above still holds. The citations do not.
Source note
This article is based on Jack Henry's statement of August 31, 2026 as published in its investor relations newsroom; NCUA's cyber incident notification final rule at 12 CFR 748.1(c), published in the Federal Register March 1, 2023 and effective September 1, 2023, together with NCUA Letter to Credit Unions 25-CU-02, which updated Letter 23-CU-07; NCUA's Cybersecurity and Credit Union System Resilience Reports submitted to Congress in June 2026, April 2026, and June 2024; the OCC's Request for Information Regarding Community Banks' Engagement With Core Service Providers and Other Essential Third-Party Service Providers, released November 24, 2025, docket OCC-2025-0537; and reporting by American Banker.
Facts in this incident are still developing. Verify the current state of Jack Henry's disclosures before relying on any detail here.
Disclaimer
This article is provided for general information and does not constitute legal advice. Regulatory requirements, compliance dates, examiner priorities, and enforcement posture change frequently. Verify current requirements against primary agency sources and your legal counsel before acting on anything described here.

