CSIDB logo
Incident

Citizens Bank, N.A.

Incident posture

Attack window
Apr 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-16 02:06

Linked entities

Victim
Citizens Bank, N.A.
Threat actors
1 actor
Sources
2 sources

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Apr 2026
Resolved
Pending

Summary

Citizens Bank, N.A. experienced a breach after attackers accessed data through a shared third‑party vendor, deploying Everest ransomware that exposed approximately 3.4 million records containing names, home addresses and account numbers. The incident appeared on the ransomware group's dark web leak site, prompting class action lawsuits and an investigation by a national law firm into potential identity theft and fraud risks for affected individuals.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On April 20, 2026 the Everest ransomware group posted both Citizens Bank and Frost Bank on its dark web leak site, indicating that samples of sensitive financial data from the two institutions had been obtained. The leak showed that the breach originated at an unnamed third‑party vendor that was shared by Citizens Bank and Frost Bank, and both banks confirmed that the compromise did not occur on their own internal networks. According to the Massachusetts Attorney General’s data breach notification, the exposed information for Citizens Bank included names, home addresses and account numbers, with the Everest gang claiming approximately 3.4 million records belonging to the bank. The same vendor‑related incident also affected Frost Bank, which reported exposure of names, addresses, Social Security numbers, taxpayer identification numbers, mortgage interest records, W‑2s, 1099s and HSA contributions. Class action lawsuits were filed against Citizens Bank within days of the public disclosure.

Individuals who received a data breach notification from Citizens Bank faced an increased risk of identity theft and fraud as a direct consequence of the exposed personal data. Edelson Lechtzin LLP, a national class action law firm, announced an investigation into potential legal claims arising from the Citizens Bank cybersecurity incident and offered free case evaluations to affected individuals. Citizens Financial Group, Inc., the parent company of Citizens Bank, N.A., is headquartered in Providence, Rhode Island and operates the bank across Connecticut, Delaware, Florida, Maryland, Massachusetts, Michigan, New Hampshire, New Jersey, New York, Ohio, Pennsylvania, Rhode Island, Vermont, Virginia and Washington, DC. The breach was linked to the same third‑party vendor that had also been implicated in the Frost Bank incident, underscoring the shared exposure pathway.

The Citizens Bank incident was part of a broader pattern observed in April 2026 where attackers gained access through trusted third parties rather than through front‑door intrusions, as noted in industry analyses of the month’s breach landscape. The situation illustrated how a vendor’s security posture effectively became the security posture of the banks that relied on it, leading to consequential legal actions and ongoing scrutiny of the breach’s origins and impact. The episode contributed to the growing emphasis on supply‑chain risk management within the financial sector during that period.

Sources

Sources available to members: 2 sources.

CSIDB