Citizens Bank, N.A.
Incident posture
Linked entities
- Victim
- Citizens Bank, N.A.
- Threat actors
- 1 actor
- Sources
- 2 sources
Timeline
Summary
Citizens Bank, N.A. experienced a breach after attackers accessed data through a shared third‑party vendor, deploying Everest ransomware that exposed approximately 3.4 million records containing names, home addresses and account numbers. The incident appeared on the ransomware group's dark web leak site, prompting class action lawsuits and an investigation by a national law firm into potential identity theft and fraud risks for affected individuals.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On April 20, 2026 the Everest ransomware group posted both Citizens Bank and Frost Bank on its dark web leak site, indicating that samples of sensitive financial data from the two institutions had been obtained. The leak showed that the breach originated at an unnamed third‑party vendor that was shared by Citizens Bank and Frost Bank, and both banks confirmed that the compromise did not occur on their own internal networks. According to the Massachusetts Attorney General’s data breach notification, the exposed information for Citizens Bank included names, home addresses and account numbers, with the Everest gang claiming approximately 3.4 million records belonging to the bank. The same vendor‑related incident also affected Frost Bank, which reported exposure of names, addresses, Social Security numbers, taxpayer identification numbers, mortgage interest records, W‑2s, 1099s and HSA contributions. Class action lawsuits were filed against Citizens Bank within days of the public disclosure.
Individuals who received a data breach notification from Citizens Bank faced an increased risk of identity theft and fraud as a direct consequence of the exposed personal data. Edelson Lechtzin LLP, a national class action law firm, announced an investigation into potential legal claims arising from the Citizens Bank cybersecurity incident and offered free case evaluations to affected individuals. Citizens Financial Group, Inc., the parent company of Citizens Bank, N.A., is headquartered in Providence, Rhode Island and operates the bank across Connecticut, Delaware, Florida, Maryland, Massachusetts, Michigan, New Hampshire, New Jersey, New York, Ohio, Pennsylvania, Rhode Island, Vermont, Virginia and Washington, DC. The breach was linked to the same third‑party vendor that had also been implicated in the Frost Bank incident, underscoring the shared exposure pathway.
The Citizens Bank incident was part of a broader pattern observed in April 2026 where attackers gained access through trusted third parties rather than through front‑door intrusions, as noted in industry analyses of the month’s breach landscape. The situation illustrated how a vendor’s security posture effectively became the security posture of the banks that relied on it, leading to consequential legal actions and ongoing scrutiny of the breach’s origins and impact. The episode contributed to the growing emphasis on supply‑chain risk management within the financial sector during that period.
Sources
Sources available to members: 2 sources.