Happy State Bank
Incident posture
Linked entities
- Victim
- Happy State Bank
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Happy State Bank reported a data security incident after a third‑party vendor inadvertently emailed a customer file to an unintended recipient, who opened the file before notifying the vendor. The bank and its parent, Centennial Bank, stated that the email was recalled, access terminated and the file destroyed. The incident potentially exposed names, Social Security numbers, dates of birth, addresses, driver’s license numbers, government identification numbers, financial account information and health insurance data for approximately two thousand fifty Texas residents, with additional individuals possibly affected nationwide. Details regarding the full scope and the exact data compromised remain unconfirmed.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
A notification filed with the Texas Attorney General disclosed that Happy State Bank, a division of Centennial Bank, experienced a data security incident involving a third‑party service provider. According to public accounts, an associate at Fidelity Information Services (FIS) prepared a secure email containing a customer file and inadvertently sent it to an unintended recipient, described as an employee at another financial institution. The misdirected file was sent on or about August 7, 2026, and the unintended recipient opened it on or about August 10, 2026 before notifying FIS. Upon learning of the error, FIS and the bank took steps to contain the incident, including recalling the email, terminating access to the file, and confirming that the file had been destroyed. The breach was reported to state authorities and affected individuals were notified by U.S. Mail.
The Texas Attorney General notification indicated that approximately 2,050 Texas residents were affected, with additional individuals potentially impacted nationwide. The information that may have been involved includes names, Social Security numbers, dates of birth, addresses, driver’s license numbers, government‑issued identification numbers, financial information such as account or credit and debit card numbers, health insurance information, and other sensitive personal data. The combination of these data elements increases the risk of identity theft, financial fraud, unauthorized transactions, and fraudulent account activity. While the full scope and precise impact remain unconfirmed publicly, the bank acknowledged that certain details of the incident have not been fully detailed.
In response to the breach, Happy State Bank and Centennial Bank issued breach notices to affected individuals via U.S. Mail. The national class action law firm Edelson Lechtzin LLP announced an investigation into potential data privacy claims and offered free, confidential case evaluations to those who received a breach notice or believe their information was exposed. The firm’s outreach noted that the reported data breach described in the press release remains unconfirmed in certain details. No further specifics about attacker motives, additional technical controls, or long‑term remediation measures were provided in the source material.
Sources
Sources available to members: 1 source.