Citizens, Frost Data Breaches Appear Linked to Third-Party Vendor Flaw
U.S.-based Citizens Bank and Texas-based Frost Bank both used the same unnamed vendor to print statements or process tax documents. A single supply-chain breach could therefore expose customers at multiple banks. The incident shows that banks face legal and reputational risks over third-party data protection and oversight even when their core networks are not compromised.
Everest listed both banks on its leak site on April 20, 2026, claiming to have obtained 3.4 million Citizens records and more than 250,000 Social Security and taxpayer identification numbers from Frost. Citizens confirmed the vendor incident on April 21, followed by Frost on April 22; both denied any unauthorized access to their internal networks. By April 29, customers had filed six proposed class-action lawsuits, with damages yet to be disclosed.
All Coverage
3 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →