Classical stone bank building facade with columns
Photo via Unsplash

TL;DR: The Everest ransomware group claimed on April 21, 2026, that it stole 3.4 million records from Citizens Bank, one of the largest retail banks in the northeastern United States. Citizens says the breach came through a third-party vendor, not their own network, and that most of the stolen data was "masked test data" with only a "limited set" of real customer information. But two class-action lawsuits filed in federal court on April 22 tell a different story, alleging names, addresses, dates of birth, Social Security numbers, and financial account information were compromised. Frost Bank got hit in the same attack, with Everest claiming 250,000 Social Security numbers from that breach. Neither bank will name the vendor. Security analysts at ZeroFox believe a single document-production vendor was responsible for both breaches.

A Vendor Got Hacked. Two Banks Got Exposed.

On April 20, 2026, the Everest ransomware group listed Citizens Bank as a victim on its dark web leak site. One day later, Frost Bank appeared on the same page [1][2].

Both banks immediately went into damage-control mode with nearly identical statements: the breach came from a third-party vendor, not from direct access to their networks. Citizens confirmed it on April 21. Frost followed on April 23 [2].

Neither bank has named the vendor.

That's not a coincidence. According to security researchers at ZeroFox, the data posted by Everest from both banks contained document-production-specific files: statement printing data from Citizens and tax document fulfillment data from Frost. Their assessment: a single shared vendor got compromised, and both banks' customer data walked out the door with it [2].

Everest gave both banks a six-day deadline before threatening to publish everything. That deadline (April 25) has already passed [2].

What Everest Claims vs. What Citizens Says

The gap between what the ransomware group claims and what Citizens Bank admits is wide enough to drive a class-action lawsuit through. Two of them, actually.

Everest's claims [1][2]:

  • 3.4 million Citizens Bank records from a SQL database dump
  • Full names, home addresses, account numbers, and internal document flags
  • 250,000 Social Security numbers and Tax IDs from Frost Bank

Citizens Bank's response [2][3]:

  • "Most of this was masked test data"
  • "A limited set of information for a small number of customers was involved"
  • No SSNs exposed (from their end)
  • "No evidence of unauthorized access" to Citizens' own network
  • Operations continue normally

ZeroFox notes that Everest has a documented history of exaggerating data volumes and sensitivity. The actual number of affected real customers could be far lower than 3.4 million [2].

But "some of it was test data" doesn't mean none of it was real. And the lawsuits filed the very next day suggest plaintiffs' attorneys aren't buying the "small number of customers" line.

Two Federal Lawsuits in 48 Hours

It took exactly one day. On April 22, 2026 (the day after Citizens' public statement) two class-action complaints landed in U.S. District Court [3][4]:

  1. The D'Allesandro complaint (34 pages), filed by Rhode Island attorney Jules D'Allesandro
  2. The Wasylyk complaint (40 pages), filed by Rhode Island attorney Peter Wasylyk on behalf of a plaintiff class

Both lawsuits allege that Citizens Bank failed to "safeguard, monitor, maintain, and protect highly sensitive personal and financial information." The charges include negligence, breach of implied contract, unjust enrichment, breach of fiduciary duty, and recklessness [4].

The lawsuits claim the exposed data includes names, addresses, dates of birth, Social Security numbers, and financial account information, significantly more than the "limited set" Citizens acknowledges [4].

Citizens declined to comment on the lawsuits [4].

This is the playbook now. A ransomware group posts stolen data. The company downplays it. Plaintiffs' attorneys file suit within days, arguing the company knew its vendor security was inadequate and did nothing. The lawsuits drag on for years while affected customers wait for a $12 settlement check and "free" credit monitoring they didn't ask for.

The Third-Party Vendor Problem

Citizens and Frost didn't get hacked directly. Their vendor did. And that distinction matters less than banks want you to think.

When you open a bank account, you give your information to that bank. You trust that bank to protect it. You don't consent to your data being shipped to some unnamed document-printing company whose security posture you know nothing about. But that's exactly what happens.

Banks outsource statement printing, tax document generation, payment processing, and dozens of other functions to third-party vendors. Each vendor is another attack surface. Each vendor's security is only as strong as its weakest employee, its cheapest contractor, its most outdated system.

This pattern is accelerating. The ADT breach came through an employee's SSO credentials. The Vercel breach came through an employee's compromised AI tool. Now Citizens and Frost got hit through a shared document-production vendor.

Different attackers, same story: the weakest link isn't the company you gave your data to. It's the company they gave your data to without telling you.

What Citizens Bank Customers Should Do Now

  • Don't wait for a notification letter. Citizens says they're contacting affected customers, but "small number" could still mean tens of thousands. Check your account activity now.
  • Freeze your credit. If your SSN was in that vendor's database (and you may never know for sure) a credit freeze at Equifax, Experian, and TransUnion is free and blocks new accounts from being opened in your name. Do it anyway.
  • Watch for scams that reference Citizens Bank. Attackers with your name and address can craft convincing phishing emails and phone calls. If someone contacts you about your Citizens account, hang up and call the number on your card.
  • Check Have I Been Pwned. Visit haveibeenpwned.com to see if your email was included in the Everest dump.
  • Consider your bank's track record. This is Citizens' problem today. Ask yourself: does your bank audit its vendors? Do you know who has your data? You probably don't. Nobody does. That's the problem.

Frost Bank Got Hit Too

Frost Bank, a Texas-based financial institution, appeared on Everest's leak site one day after Citizens. Everest claims to have 250,000 Social Security numbers and Tax IDs from Frost's customers [2].

Frost confirmed the incident on April 23, stating the data "may have included" customer information and that they'd "engaged external cybersecurity experts." Like Citizens, Frost blamed the third-party vendor and denied any direct network compromise [2].

Frost customers should take the same precautions listed above. If Everest has your SSN, a credit freeze isn't optional: it's urgent.

Sources

  1. PYMNTS: "Citizens Bank Customers Targeted in Third-Party Data Breach" (April 2026)
  2. American Banker: "Citizens, Frost blame vendor after data breach claim" (April 2026)
  3. PR Newswire: "Citizens Bank Data Breach: Edelson Lechtzin LLP Launches Investigation" (April 2026)
  4. GoLocalProv: "Citizens Bank Hit With Two Federal Lawsuits After Cyberattack" (April 2026)