2026 Citizens Financial Group - third-party vendor data incident amid Everest claims
Data compromised
Limited customer information for a small number of customers, with most extracted material described by Citizens as masked test data
Technical writeup
Citizens Financial Group said it was managing an incident involving data extracted from a third-party vendor. The bank stated that most of the material was masked test data, that a limited set of information for a small number of customers was involved, and that there was no evidence of unauthorized access to Citizens network systems. Reporting noted that Everest ransomware claims about broader datasets remained unverified.
Root cause
Third-party vendor data extraction; broader ransomware claims unverified