Menu
Browse

Cyber Incident Victim: Citizens Bank, N.A.

Date:

Apr 2026

Location:

United States of America

Summary

Citizens Bank, N.A. disclosed a breach originating from a shared third‑party vendor that also affected Frost Bank, with the Everest ransomware group posting stolen data on its dark web leak site. The attackers claimed approximately 3.4 million records from the bank, exposing names, home addresses and account numbers, while Frost Bank reported over 250,000 Social Security numbers, taxpayer identification numbers and related financial records exposed. The breach stemmed from ransomware deployed via the vendor’s environment, not the banks’ own networks, prompting class‑action investigations and notifications to affected individuals.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

In April 2026 Citizens Financial, operating as Citizens Bank, N.A., and Frost Bank were both compromised through a single shared third‑party vendor on the same day. The Everest ransomware group posted both institutions on its dark web leak site on April 20, claiming to have exfiltrated data from the banks. Each bank publicly confirmed that the breach originated at the unnamed vendor’s systems and not within their own internal networks. Within days of the disclosure, affected customers filed class action lawsuits against both banks.

Cyber Incident Image

The Citizens Bank incident involved approximately 3.4 million records that contained names, mailing addresses and account numbers. Frost Bank’s exposure was reported as over 250 000 Social Security numbers and taxpayer identification numbers, together with names, addresses, mortgage interest records, W‑2 forms, 1099 forms and health savings account contributions. The cause of both breaches was identified as Everest ransomware leveraging the vendor’s access to move laterally and encrypt data before exfiltration. The Massachusetts Attorney General’s office received a data breach notification detailing these specifics.

The April 2026 breach landscape was described in the source material as being defined by attackers gaining entry through trusted third parties such as vendors, BPO contractors or OAuth‑connected applications, with no front‑door breaches or brute‑force attempts reported. The Citizens and Frost incidents exemplified this pattern, as both banks were hit simultaneously via the same unnamed vendor. This highlighted the shift in attacker focus from perimeter defenses to supply‑chain and trusted‑relationship vectors.

Regulatory filings followed the public disclosure, with the Massachusetts Attorney General’s office recording the breach as required by state law, and the banks facing the aforementioned class actions. The incidents underscored the downstream risk associated legal and financial consequences when a shared vendor becomes the point of failure for multiple financial institutions. The events concluded with the banks addressing the fallout through litigation and regulatory reporting while the vendor’s security posture remained under scrutiny.

Sources
Sources available to members
2 sources