Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
ransomware-group-operationthird-party-vendor-breachunderground-data-leakfinancial-sector-threat

Everest Ransomware Claims Third-Party Data Theft at Citizens Financial and Frost Bank

Updated 1mo agoFirst seen Apr 23, 20263 sources

The Everest ransomware operation claimed it stole data tied to Citizens Financial Group and Frost Bank and threatened to publish the information after listing both institutions on its leak site. Reports said Everest alleged it held nearly 3.4 million Citizens-related records from a SQL database dump and about 250,000 Frost customer records, with sample data purportedly including personal and financial information. The gang gave the organizations a short deadline before release and framed the incident as part of its broader double-extortion campaign.

Both banks said their own internal networks were not directly compromised and attributed the exposure to a third-party vendor. Citizens said the material involved mostly masked test data with only limited real customer information, while Frost said it had brought in external cybersecurity experts to investigate. The activity was linked to Everest, a Russia-linked ransomware-as-a-service group that has previously targeted major enterprises including Nissan, Collins Aerospace, Iberia Airlines, Under Armour, and BMW.

Share:
Everest Ransomware Claims Third-Party Data Theft at Citizens Financial and Frost Bank
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
May 28, 20261mo ago

Sefas discloses breach details and 191,848 Frost Bank customers affected

Sefas disclosed a data security incident involving unauthorized access to an SFTP server used for software support, with intermittent file downloads occurring between December 2025 and April 2026. Frost Bank reported to Texas regulators that at least 191,848 individuals were affected, and Sefas said the intrusion did not extend beyond the SFTP server and had ceased after April 16, 2026.

teiss - News - Close to 200,000 Frost Bank customers affected by Sefas security breach
Apr 26, 20262mo ago

Everest threatens public release of allegedly stolen bank data

Everest's leak-site deadline indicated it would publish the allegedly stolen data from Frost Bank and Citizens Financial Group if its demands were not met. The threatened release date was set for April 26.

Apr 22, 20262mo ago

Banks say incident stemmed from third-party vendor, not internal networks

Frost Bank and Citizens Financial Group said the exposed data was tied to a third-party vendor rather than a compromise of their own internal systems. Citizens said most of the data was masked test data with limited real customer information, while Frost said it brought in external cybersecurity experts to investigate.

Apr 20, 20262mo ago

Everest lists Frost Bank and Citizens Financial Group on leak site

On its dark web leak site, the Everest ransomware operation claimed it had breached Frost Bank and Citizens Financial Group, posted sample data, and set a six-day deadline before full publication.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

9 LINKEDOpen in app
Threat actors
1 linked
Organizations
8 linked
BMWCybernewsIberiaCollins AerospaceCullen/Frost BankersCitizens Financial GroupNissan Motor Co., Ltd.Under Armour
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.