{"id":27838,"date":"2026-04-23T03:28:58","date_gmt":"2026-04-23T03:28:58","guid":{"rendered":"https:\/\/finderica.com\/?p=27838"},"modified":"2026-04-23T03:28:58","modified_gmt":"2026-04-23T03:28:58","slug":"citizens-frost-blame-vendor-after-data-breach-claim","status":"publish","type":"post","link":"https:\/\/finderica.com\/?p=27838","title":{"rendered":"Citizens, Frost blame vendor after data breach claim"},"content":{"rendered":"<p><\/p>\n<div>\n<ul class=\"rte2-style-ul\" style=\"margin-top: 0px; margin-bottom: 0px; padding-inline-start: 48px;\">\n<li><b>Key insight<\/b>: Same-day leak posting plus document-production data in both banks&#8217; samples points to a shared vendor compromise rather than two separate attacks, according to ZeroFox&#8217;s analysis shared with American Banker.<\/li>\n<li><b>Supporting data<\/b>: Everest&#8217;s victim-shaming site attributes 3.4 million records to Citizens and more than 250,000 Social Security numbers and taxpayer identification numbers to Frost; neither figure has been reconciled with the banks&#8217; statements.<\/li>\n<li><b>Forward look<\/b>: Everest has threatened to publish the stolen files on April 25, which would be the first public test of the banks&#8217; limited-exposure framing against Everest&#8217;s actual dataset.<\/li>\n<\/ul>\n<p><i>Overview bullets generated by AI with editorial review<\/i><\/p>\n<p>Processing Content<\/p>\n<p>Ransomware group Everest recently claimed it stole 3.4 million records from Citizens Bank and 250,000 Social Security numbers from Frost Bank.<\/p>\n<p>On Tuesday, the day after Everest listed the two banks as victims, Citizens issued a statement attributing the incident to a third-party vendor. Frost provided American Banker a similar statement on Wednesday. Neither bank has named the compromised vendor.<\/p>\n<p>The data samples on Everest&#8217;s site suggest a single third-party compromise affected both banks, according to Adam Darrah, vice president of Intelligence at ZeroFox. The affected vendor appears to handle statement printing for Citizens and tax document fulfillment for Frost, Darrah told American Banker.<\/p>\n<p>The samples do not suggest Everest reached internal systems at either bank, Darrah said.<\/p>\n<p>The breach is yet another example of an attack on an outsourced vendor, affecting multiple banks in the fallout. In this case, the attack affects statement printing and tax-document outsourcing, which is common in banking and concentrated among a handful of large vendors.<\/p>\n<p>ZeroFox has previously assessed that Everest likely overstates the volume and sensitivity of the data it claims to hold. So, the breach also serves as a case study in how banks calibrate their public response when the group claiming the breach has a documented record of overstating its plunder.<\/p>\n<h2 class=\"cms-heading-h2 HeadingH2\">What the banks say vs. what Everest claims<\/h2>\n<p>In its <ps-link><a href=\"https:\/\/investor.citizensbank.com\/about-us\/newsroom\/latest-news\/2026\/2026-04-21.aspx\" class=\"Link\" target=\"_blank\" rel=\"noopener\"><u>April 21 statement<\/u><\/a><\/ps-link>, Citizens said most of what got stolen was masked test data, with a &#8220;limited set of information for a small number of customers&#8221; involved. The bank said it has no evidence of unauthorized access to its own network.<\/p>\n<p>A spokesperson for Citizens did not directly respond to Everest&#8217;s claim that it had stolen 3.4 million records from the bank. The spokesperson told American Banker that the compromised data does not contain Social Security numbers.<\/p>\n<p>Likewise, a spokesperson for Frost did not directly address Everest&#8217;s claim that it had more than 250,000 Social Security numbers and taxpayer identification numbers stolen from the bank.<\/p>\n<p>The Frost spokesperson said the bank received a notification from a third-party vendor about unauthorized access to the vendor&#8217;s systems that &#8220;may have included Frost customer data.&#8221; Early findings indicate the incident &#8220;may be related to recent claims made by cybercriminals,&#8221; the spokesperson said.<\/p>\n<p>Frost has engaged external cybersecurity experts and has no evidence of unauthorized access to its own network, the spokesperson added.<\/p>\n<p>The spokesperson did not directly address Everest&#8217;s claim that the group had stolen more than 250,000 Social Security numbers and taxpayer identification numbers from the bank.<\/p>\n<h2 class=\"cms-heading-h2 HeadingH2\">What we do and do not know<\/h2>\n<p>A single shared vendor compromise is the most likely explanation for the samples Everest has posted, Darrah said. The alternative scenario, in which two vendors in the same category were hit in a coordinated operation, is possible but less likely.<\/p>\n<p>&#8220;The appearance of document-production-specific data in two banks within a single posting is probably not a coincidence,&#8221; Darrah said.<\/p>\n<p>Several gaps in the public record remain. Neither bank has named the vendor. A Citizens spokesperson referred the question of whether it shares the vendor with Frost to Frost itself. A Frost spokesperson did not address the question.<\/p>\n<p>Neither bank has publicly reconciled its framing with the specific counts in Everest&#8217;s claim. Frost has not said whether it confirms or disputes the claim outright. Neither bank has said whether it has notified its federal banking regulators.<\/p>\n<p>Neither bank is new to a vendor-involved incident. Frost <ps-link><a href=\"https:\/\/www.prnewswire.com\/news-releases\/frost-bank-issues-statement-regarding-unauthorized-access-to-commercial-lockbox-image-archive-300615468.html\" class=\"Link\" target=\"_blank\" rel=\"noopener\"><u>disclosed<\/u><\/a><\/ps-link> a compromise of third-party lockbox software in 2018 that affected roughly 470 commercial customers. Citizens <ps-link><a href=\"https:\/\/www.maine.gov\/agviewer\/content\/ag\/985235c7-cb95-4be2-8792-a1252b4f8318\/add73b69-6932-4579-9659-eebc8a3f1cd1.html\" class=\"Link\" target=\"_blank\" rel=\"noopener\"><u>notified<\/u><\/a><\/ps-link> 8,358 consumers in December 2024 of an incident it attributed to insider wrongdoing.<\/p>\n<p>The scale of what Everest is now claiming would represent a different order of magnitude.<\/p>\n<h2 class=\"cms-heading-h2 HeadingH2\">Everest and its credibility problem<\/h2>\n<p>The Everest ransomware and extortion group emerged in December 2020. An <ps-link><a href=\"https:\/\/web.archive.org\/web\/20250408030426\/dd80b675424c132b90b3-e48385e382d2e5d17821a5e1d8e4c86b.ssl.cf1.rackcdn.com\/external\/hhs-hc3-everest-ransomware-threat-actor-profile-alert-8-20-24.pdf\" class=\"Link\" target=\"_blank\" rel=\"noopener\"><u>August 2024 threat-actor profile<\/u><\/a><\/ps-link> from the U.S. Department of Health and Human Services, or HHS, describes the group as Russia-based.<\/p>\n<p>Everest shifted from pure double-extortion ransomware (encrypting a victim&#8217;s data and threatening to leak it publicly unless a ransom is paid) to a mix of data extortion and so-called initial access brokering (selling stolen access to other criminal groups) starting in late 2021 and specializing by 2023, the profile said.<\/p>\n<p>The group has also run a program offering cash to corporate insiders in exchange for remote access, according to the HHS analysis.<\/p>\n<p>Everest has likely exaggerated the quantity and quality of its alleged victim data and in some cases fabricated it entirely, ZeroFox concluded in <ps-link><a href=\"https:\/\/www.zerofox.com\/intelligence\/flash-report-everest-continues-to-tout-prominent-brands-in-latest-disclosures\/\" class=\"Link\" target=\"_blank\" rel=\"noopener\"><u>a Feb. 6 report<\/u><\/a><\/ps-link>.<\/p>\n<p>In the case of Citizens and Frost, the specifics of Everest&#8217;s claim (250,000-plus Social Security numbers and taxpayer identification numbers from Frost and 3.4 million banking records from Citizens) remain unverified.<\/p>\n<p>The group is currently threatening to publish the stolen files on April 25.<\/p>\n<\/div>\n<p><a href=\"https:\/\/www.americanbanker.com\/news\/citizens-frost-blame-vendor-after-data-breach-claim\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Key insight: Same-day leak posting plus document-production data in both banks&#8217; samples points to a shared vendor compromise rather than two separate attacks, according to ZeroFox&#8217;s analysis shared with American Banker. Supporting data: Everest&#8217;s victim-shaming site attributes 3.4 million records to Citizens and more than 250,000 Social Security numbers and taxpayer identification numbers to Frost;<\/p>\n","protected":false},"author":1,"featured_media":27839,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"rank_math_lock_modified_date":false,"footnotes":""},"categories":[218],"tags":[6784,2871,135,371,162,10210,9173],"class_list":{"0":"post-27838","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-banking","8":"tag-blame","9":"tag-breach","10":"tag-citizens","11":"tag-claim","12":"tag-data","13":"tag-frost","14":"tag-vendor"},"_links":{"self":[{"href":"https:\/\/finderica.com\/index.php?rest_route=\/wp\/v2\/posts\/27838","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/finderica.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/finderica.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/finderica.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/finderica.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=27838"}],"version-history":[{"count":0,"href":"https:\/\/finderica.com\/index.php?rest_route=\/wp\/v2\/posts\/27838\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/finderica.com\/index.php?rest_route=\/wp\/v2\/media\/27839"}],"wp:attachment":[{"href":"https:\/\/finderica.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=27838"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/finderica.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=27838"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/finderica.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=27838"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}