惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 司徒正美
The GitHub Blog
The GitHub Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Apple Machine Learning Research
Apple Machine Learning Research
L
LangChain Blog
GbyAI
GbyAI
博客园_首页
V
Visual Studio Blog
Martin Fowler
Martin Fowler
WordPress大学
WordPress大学
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 叶小钗
腾讯CDC
博客园 - Franky
IT之家
IT之家
Google DeepMind News
Google DeepMind News
Microsoft Azure Blog
Microsoft Azure Blog
D
Docker
大猫的无限游戏
大猫的无限游戏
Recent Announcements
Recent Announcements
小众软件
小众软件
博客园 - 三生石上(FineUI控件)
B
Blog
酷 壳 – CoolShell
酷 壳 – CoolShell

PYMNTS.com

Crypto Payments Are Back. Will Merchants Actually Care This Time? B2B’s New Battlefield Is Everything Before the Button Amazon Targets the GLP-1 Gap Big Pharma Left Open LendingClub Signals Expanded Capabilities With Happen Bank Rebrand Congress Moves to Give FinTechs Direct Fed Payment Access Microsoft Tests Mythos to Identify and Mitigate Vulnerabilities United Airlines Hikes Fares as Fuel Costs Surge OpenAI Images 2.0 Is a Real Leap With a Real Price Tag Morgan Stanley Says Gaming Could Score $22 Billion With AI FTC Shuts Down Alleged Healthcare Fraud Scheme Sam’s Club Offers eCommerce Shoppers Hour-or-Less Deliveries FinTechs Cut Staff as AI and Margins Redefine Growth JPMorganChase Extends Critical Industries Investment Program to Continental Europe OpenAI Lands $75 Million Investment From Robinhood Ventures House Bill Would Reduce Small Lenders’ Reporting Requirements Coinbase Lists tGBP to Expand Locally-Denominated Stablecoin Access BNY Names New Head for Payments/Trade Client Platform KnowBe4 Automates Global Cash Flow Via Flywire Partnership Treasury Calls for Programmable Financial Enforcement Across Crypto DeepSeek Seeks $20 Billion Valuation as Tech Giants Weigh Investment Google Accelerates Agentic AI Shift With New Enterprise Platform OpenAI Begins Briefing Governments on Cybersecurity Capabilities DeFi Security Suffers New Blow With $3 Million Volo Exploit Uninvited Users Access Anthropic’s Mythos AI Model Block and Uber Expand Partnership Across Several Global Markets OpenAI Pledges $1.5 Billion to PE Enterprise AI Project Podcast: Inside the $9 Billion DeFi Hack That’s Shaking Crypto’s Foundations Synchrony CFO Flags Momentum in Spending and Credit Banks Risk Slowing the Emerging Middle Market Firms Driving Growth Paysafe Expands Digital Wallet Availability Across 18 European Markets
Citizens Bank Customers Targeted in Third-Party Data Breach
PYMNTS · 2026-04-24 · via PYMNTS.com

By  |  April 23, 2026

 | 

Two U.S. banks say they are investigating data breaches targeting their customers’ information.

“We have been managing an incident involving data extracted from a third party vendor,” Citizens Bank said in a statement Tuesday (April 21).

“For Citizens, most of this was masked test data, although a limited set of information for a small number of customers was involved.”

The bank said there is no evidence of unauthorized access to its network, and operations would continue as usual, with enhanced monitoring in place.

Meanwhile, a report from the website Cyber News says that Texas-based lender Frost Bank had learned from one of its vendors that hackers had gained access to its system, which may have compromised Frost customer data.

“We have engaged external cybersecurity experts to assist in our investigation, and early findings indicate that the incident may be related to recent claims made by cybercriminals,” a spokesperson for the bank told Cyber News, adding there is “no evidence of unauthorized access to the Frost network.”

Advertisement: Scroll to Continue

That report notes that both banks had appeared on the dark web site of the Everest ransomware gang, with attackers giving the lenders six days before releasing the stolen data.

“Ransomware has become a structured, global industry,” PYMNTS wrote earlier this month. “Organized cybercriminal groups now operate with business-like efficiency. Attacks are no longer limited to encrypting files; they often involve ‘double extortion, where attackers threaten to leak stolen data if payment is not made.”

It has led to the rise of the ransomware negotiator, people whose skills lie not so much in technical expertise and more about human interaction, albeit via virtual channels. Negotiators need to quickly assess the attacker’s credibility, figure out whether stolen data will actually be released and consider how flexible the ransom demand might be.

The emergence of ransomware negotiators, PYMNTS added, is a sign of a broader shift in how organizations view cyber risk.

“It is no longer solely a technical problem; it is a business risk that requires strategic management,” the report continued. “In this sense, negotiators function as a form of corporate diplomat, engaging with adversaries to protect organizational interests.”

Meanwhile, research by PYMNTS Intelligence has found that third-party vulnerabilities are at the heart of many contemporary cyberattacks.

Findings from PYMNTS Intelligence in the August edition of the 2025 Certainty Project report, “Vendors and Vulnerabilities: The Cyberattack Squeeze on Mid-Market Firms,” show that attackers often compromise a vendor first, then exploit the trust relationship to infiltrate their target firm.

The research found that 38% of invoice fraud cases and 43% of phishing attacks originated with compromised vendors.