American Funds urges new client passwords over Heartbleed

Parent Capital Group says has no information indicating client accounts hacked.
APR 18, 2014
The Capital Group Cos., the third-largest manager of U.S. mutual funds, urged 800,000 customers to change account passwords and other information to protect themselves from risk caused by the Heartbleed computer bug. The bug may have exposed some customers who accessed their accounts on the website for the firm's American Funds mutual funds between Dec. 12 and April 14, said Chuck Freadhoff, a spokesman for the firm. The company Thursday recommended in an e-mail to those clients that they change their user information, password, security image and questions, and delete their browsing history and “cookies.” (See also: 'Heartbleed' cybersecurity threat looms over advisers and clients) “Through an outside vendor there was with Heartbleed a vulnerability that gave a view to information flowing through that vendor's servers,” Mr. Freadhoff said. “We are doing this out of an abundance of caution,” he said, adding that the company had no information indicating accounts had been accessed by hackers. Heartbleed, which was recently discovered by technology researchers and made public on April 7, prompted security experts to urge consumers to change their Internet passwords, even as Google Inc., Facebook Inc. and large banks said they weren't affected. The bug can expose people to hacking of their passwords and other sensitive information. PROGRAMMING ERROR The Federal Financial Institutions Examination Council, made up of representatives from the Federal Reserve Board of Governors, the Consumer Financial Protection Bureau and other U.S. regulators, said last week that systems operating a widely used encryption technology called OpenSSL are at risk of being hacked. The flaw stemming from a two-year-old programming mistake was discovered by researchers from Google and Codenomicon Ltd., a technology security firm based in Finland, and reported to OpenSSL, according to a blog post from Codenomicon. It isn't known whether malicious hackers were aware of the bug and exploiting it, the researchers wrote. Bloomberg News reported April 11 that the National Security Agency knew about the bug for two years and made it part of its hacking toolkit for information gathering. The NSA has since denied that it knew of the bug before an April 7 report by the private security researchers. Capital Group manages $1.3 trillion for clients, including $1.1 trillion in its American Funds lineup, according to the company and data compiled by research firm Morningstar Inc. Only The Vanguard Group Inc.and Fidelity Investments oversee more in mutual funds. Capital Group's largest fund is the $138 billion Growth Fund of America, according to data compiled by Bloomberg. The firm operates more than 50 million shareholder accounts, Mr. Freadhoff said. (Bloomberg News)

Latest News

Mesirow acquires part of flexPATH in second retirement deal of 2026
Mesirow acquires part of flexPATH in second retirement deal of 2026

Chicago-based Mesirow Fiduciary Solutions adds flexPATH's plan-level outsourced fiduciary book, boosting its retirement market reach to $164 billion.

Advisor moves: LPL lands $350M veteran advisor duo in Florida
Advisor moves: LPL lands $350M veteran advisor duo in Florida

Also, Raymond James's employee advisor channel adds breakaways from Wells Fargo and Stifel, while UBS welcomes an ex-Morgan Stanley duo in Indiana.

SEC accuses crypto firm founder of running $425 million Ponzi scheme
SEC accuses crypto firm founder of running $425 million Ponzi scheme

It promised guaranteed principal and 10% monthly returns. The SEC says it invested nothing.

MassMutual Ascend tops $2 billion in RIA annuity sales as advisors warm to income products
MassMutual Ascend tops $2 billion in RIA annuity sales as advisors warm to income products

Ten years after entering the fee-based annuity market, MassMutual Ascend says nearly half its lifetime sales came in the past two years alone – but barriers remain among fee-only advisors.

Fintech bytes: Wealth tech firms target advisor productivity with new integrations
Fintech bytes: Wealth tech firms target advisor productivity with new integrations

Amplify, WealthReach, Zeplyn and Zocks have unveiled partnerships aimed at automating portfolio management, content creation, account opening, and client communication.

SPONSORED Direct indexing webinar targets tax-loss harvesting amid market swings

Northern Trust’s Ken Lassner shows advisors how to convert volatility into after-tax portfolio gains

SPONSORED Who builds the income when the pension disappears?

Dan Biagini of American Equity says the steady decline of pensions, longer lifespans and a reset in interest rates are rewriting how advisors build retirement income