Written by

Joe Gangale

The New Extortion: Defending Regional Banks Against Ransomware and Third-Party Breaches

Security Advisory Regarding SolarWinds Supply Chain Compromise

SHARE

Intro

Imagine it’s a cool June morning. As you’re getting ready to head into the office, you receive a call from your IT team. The bank you work for has been hit by ransomware, your systems have been encrypted, and potentially large amounts of customer data were stolen.

This scenario became reality for the regional Alabama bank, River Bank & Trust. The attack began on June 16 and wasn’t fully detected until June 19. On June 25, the bank filed an 8-K detailing the timeline of the compromise. The attackers later claimed that the stolen data had been deleted, but the consequences of a ransomware attack extend far beyond whether the data ultimately reappears online.

The Alabama-based bank is now being investigated to potentially pursue a class action lawsuit. Beyond the theft of customer data, an incident like this can have a lasting impact on customer trust and damage brand reputation. While the full details of the attack, including the specific tactics used by the attackers and the extent of the impact, have not yet been made public, the incident highlights a broader concern for regional banks, ransomware is no longer limited to encrypting systems and demanding payment for their restoration.

Threat actors have increasingly expanded their use of data theft and extortion, sometimes stealing sensitive information and threatening to release it without encrypting a victim’s systems, and in other cases combining data theft with encryption in a tactic known as double extortion. These evolving approaches give attackers additional leverage and create new challenges for financial institutions responding to an attack.

However ransomware is only part of the problem. As financial institutions increasingly rely on third-party vendors for everything from infrastructure and data processing to customer communications, those vendors can become an attractive target for threat actors. A compromise at a trusted third party can expose a bank to data theft, operational disruption, and extortion, even when the bank’s own environment was never directly compromised.

How can regional banks defend themselves against ransomware while also addressing the growing threat of third-party breaches? The first step is to understand the threat.

Ransomware Has Changed

The Alabama incident demonstrates the consequences ransomware can have for a regional bank. To understand why the threat is becoming more difficult to manage, it is important to look at how ransomware itself has changed. To explain briefly, ransomware is a type of malware or malicious software that encrypts a system’s file storage, preventing the victim from accessing those files unless a ransom is paid to the attacker. But the traditional form/attack model of ransomware is no longer the only one being used today.


The traditional simplified ransomware attack model looks like this:



This model worked and still works today. Organizations are unable to access their systems, and backups and recovery can be time-consuming. Anytime a bank is down without operational capability, money is lost. The attackers knew this and offered a simple out. Pay the ransom and all of these problems go away.

This model then began to slightly change with new ransomware tactics like data-only extortion and double extortion. The model remains largely the same, but with data-only extortion, encryption is skipped, and the attackers silently steal your data and demand a ransom, or the files will be released to the public or sold on the dark web. Double extortion is where the attackers not only encrypt your files, but they also threaten to release your data to the public or be sold on the dark web.

These types of ransomware attacks that threaten disclosure are especially threatening to banks, as banks often hold very sensitive customer data and financial information that is particularly valuable to cyber criminals. Ransomware attacks involving disclosure against financial institutions also bring heavy legal, regulatory, and reputational consequences.

Traditional ransomware primarily targeted availability among systems and operational capability, while more modern methods target confidentiality of customer data, trust between a business and their customers, and the business’s reputation.

The Third-Party Attack Surface

To operate a regional bank at maximum efficiency in the modern day, relying on third-party services is unavoidable. Some examples of third-party services that apply to regional banks are listed below:

• Call centers
• Payment processors
• HR/payroll providers
• IT support providers
• Fraud detection providers
• Cloud service providers
• Managed service providers
• Document management providers
• Loan/origination providers
• Software vendors
• Data processors
• Marketing platforms
• Customer communication platforms

Each of these third-party services can provide a potential entry point into a bank's network or access to its customer data. However, the risk is not limited to a third party being directly compromised. Depending on the type of service, the information it handles, and the level of access it has, there are several different ways a third party can expose a bank's systems or data. Understanding these different forms of third-party exposure is important when looking at the larger cybersecurity risks facing regional banks.

Third-party data exposure can take several different forms. Some of the more common examples include:

• Unauthorized Access - A third party has legitimate access to bank systems or data, but that access is misused or compromised.

• Data Breach - Customer or bank information held by a third party is stolen after the vendor is compromised.

• Accidental Data Exposure - Sensitive information is exposed through misconfiguration, human error, or improper handling.

• Credential Compromise - Attackers obtain credentials belonging to a third-party provider and use them to access bank systems.

• Supply-Chain Compromise - Malicious code, compromised software, or another weakness in a vendor's products or services is used to target the bank.

• Fourth-Party Exposure - A bank's vendor relies on another company or subcontractor that has access to the bank's information or systems, creating another layer of exposure.

• Operational Exposure - A third-party compromise disrupts a service the bank depends on, even if customer data itself is not stolen.

These categories are not exhaustive. A bank does not have to be directly compromised for a cyberattack to affect it. A bank's data and operations can also depend on the security of the organizations it trusts with its systems, information, and services. 

Because of this, every third-party relationship effectively expands a bank's attack surface. The more vendors a bank relies on, and the more access or sensitive information those vendors have, the more opportunities there are for a threat actor to exploit weaknesses outside of the bank's direct control.

An attacker could compromise a vendor, obtain access to sensitive bank or customer information, and then use that information to threaten the bank. In this situation, the bank may still face many of the same consequences as a direct ransomware attack, even though its own network was never compromised.

This shows how ransomware and third-party risk are becoming more connected. As ransomware continues to move beyond simply encrypting a bank's systems, attackers have more ways to use a third-party relationship to target a bank.

Ransomware and Third-Party Risk Are Converging

The growing connection between ransomware and third-party risk is not theoretical. Recent incidents involving Citizens Financial Group and Frost Bank demonstrate how a bank can become the target of a ransomware-related extortion campaign without its own network being directly compromised.

In April 2026, both Citizens and Frost disclosed incidents involving unauthorized access to data held by a third-party vendor. Citizens stated that most of the affected information was masked test data, although a limited amount of information belonging to customers was involved, and that there was no evidence of unauthorized access to its own network. Frost similarly stated that it had been notified by a third-party vendor of unauthorized access to the vendor's systems that may have included Frost customer data.

Around the same time, the ransomware group Everest claimed responsibility for stealing data associated with both banks. The full scope and details of the incidents are still being investigated. However, these cases show how attackers can use a trusted third party to target a bank. Attackers can obtain sensitive bank or customer information through a third party and use that information for extortion without ever gaining direct access to the bank's own network.

For regional banks, this means defending against ransomware requires more than securing the bank's own environment. It also requires understanding where sensitive data resides, who can access it, and how a compromise at a trusted third party could be used to threaten the bank and its customers.

7 Steps Regional Banks Can Take to Reduce Ransomware and Third-Party Risk

There is no single solution that can eliminate the risk of ransomware or third-party breaches. Regional banks should instead focus on reducing their exposure, limiting the potential impact of a compromise, and ensuring they can recover when an attack occurs.

1. Identify Critical Third Parties

Maintain an up-to-date inventory of third parties and identify which vendors have access to sensitive data, critical systems, or important business functions. Prioritize vendors based on the level of access and potential impact if they are compromised.

2. Limit Third-Party Access

Third parties should only have the access necessary to perform their services. Use strong authentication, least-privilege access, and regular access reviews to reduce the risk of compromised vendor credentials being used against the bank.

3. Know Where Your Data Is

Banks should know what sensitive information is shared with each third party and where that information is stored and processed. This allows the bank to quickly determine what may have been exposed if a vendor is compromised.

4. Strengthen Vendor Oversight

Vendor assessments should go beyond compliance reports. Banks should continuously monitor critical vendors and reassess their security, risk profile, and ability to respond to a cyberattack throughout the relationship.

5. Maintain Reliable Backups

Banks should maintain secure, regularly tested backups of critical systems and data. Recovery plans should also account for the possibility that a critical third party becomes unavailable following a ransomware attack.

6. Develop an Incident Response Plan

Banks should develop an incident response plan to prepare for stolen data, threats of disclosure, customer notification, and the legal and regulatory consequences of an extortion attempt.

7. Test the Response

Banks should regularly conduct tabletop exercises involving ransomware and third-party breach scenarios. Testing helps identify gaps in communication, recovery, vendor coordination, and decision-making.

Frost Bank spokesman Bill Day commenting on recent incident in April 2026 - https://finance.yahoo.com/sectors/technology/articles/frost-bank-hit-class-action-193000972.html?guccounter=1&guce_referrer=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS8&guce_referrer_sig=AQAAAE_M_9II45BQ_UWKMNLwKlwT3YRV8yrvEy3rydV503q9hPTm3DCJ35k27Xlrr39khAEN9n1MgPd5fcG3GCUaXtvOMMG2-5wgQHOJl6n25u6TE28g-kGiJm90Rl_eN3N5oDabN8dMFWl5NdjhvxhVakqMGQ2GPWHqJvqax6ZSm_te

Citizens Financial Group statement regarding the incident in April 2026 - https://investor.citizensbank.com/about-us/newsroom/latest-news/2026/2026-04-21.aspx

Claim of attackers deleting data stolen during River Bank & Trust ransomware attack - https://securityaffairs.com/196537/cyber-crime/river-bank-obtained-assurances-from-the-attackers-that-the-stolen-data-in-the-june-attack-was-deleted.html

8K filed by River Bank & Trust with details of ransomware attack -  https://www.sec.gov/Archives/edgar/data/1641601/000119312526282946/ck0001641601-20260619.htm

Class action lawsuit pending investigation against River Bank & Trust - https://www.classaction.org/data-breach-lawsuits/river-bank-and-trust-june-2026

Ransomware remediation and protection guide - https://www.cisa.gov/stopransomware/ransomware-guide

Citizens and Frost Bank Incidents - https://schneiderdowns.com/our-thoughts-on/third-party-cyber-risk-in-banking-everest-ransomware-claims/

Third-party risk - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161r1-upd1.pdf

Third-party risk - https://nvlpubs.nist.gov/nistpubs/ir/2021/NIST.IR.8276.pdf

Third-party risk - https://www.federalregister.gov/documents/2023/06/09/2023-12340/interagency-guidance-on-third-party-relationships-risk-managemen

Ransomware attack model graphic - https://www.fortinet.com/resources/cyberglossary/ransomware