Full Report
A data breach involving Frost Bank was reported in May 2026. See incident details, impact on customers, and recommended security measures.
Analysis Summary
# Incident Report: Third-Party SFTP Compromise Affecting Frost Bank
## Executive Summary
Frost Bank experienced a significant data breach originating from a third-party vendor, Sefas Innovation, involving unauthorized access to an SFTP server. The incident resulted in the intermittent exfiltration of sensitive customer financial and personal data over a five-month period. While no specific threat actor has been identified, the exposure of Social Security numbers and account details has prompted a medium-severity classification due to high risks of identity theft.
## Incident Details
- **Discovery Date:** April 16, 2026
- **Incident Date:** December 1, 2025 (Initial Access) to April 2026
- **Affected Organization:** Frost Bank (via Sefas Innovation)
- **Sector:** Financial Services / Banking
- **Geography:** United States (San Antonio, Texas headquarters)
## Timeline of Events
### Initial Access
- **Date/Time:** December 1, 2025
- **Vector:** Third-party vulnerability
- **Details:** Unauthorized actors gained access to a Secure File Transfer Protocol (SFTP) server maintained by Sefas Innovation, a document composition and software support provider.
### Lateral Movement
- **Details:** The attack appears focused on the SFTP environment used for software support; the report does not indicate lateral movement into Frost Bank’s internal corporate network, but rather persistent access to the vendor's file-sharing infrastructure.
### Data Exfiltration/Impact
- **Details:** Between December 2025 and April 2026, the unauthorized group intermittently downloaded files containing sensitive Frost Bank customer data.
### Detection & Response
- **Discovery:** Sefas Innovation detected unauthorized access on April 16, 2026.
- **Reporting:** The incident was publicly disclosed and reported to affected parties on May 20, 2026.
## Attack Methodology
- **Initial Access:** Exploitation of unauthorized access to a third-party SFTP server.
- **Persistence:** Intermittent access maintained for approximately five months.
- **Collection:** Gathering of customer PII and financial documents stored on the SFTP for support purposes.
- **Exfiltration:** Direct download of files from the compromised SFTP server.
- **Impact:** Sensitive data exposure leading to increased risk of financial fraud.
## Impact Assessment
- **Financial:** Not disclosed, but involves high potential costs for credit monitoring and fraud mitigation.
- **Data Breach:** Exposure of Names, Addresses, Social Security Numbers (SSNs), Taxpayer Identification Numbers, Account Numbers, Dates of Birth, Loan Numbers, Tax forms, and Bill Pay check images.
- **Operational:** Disruption to software support workflows and necessity for forensic investigation.
- **Reputational:** Public impact associated with third-party supply chain vulnerabilities.
## Indicators of Compromise
- **Network indicators:** Unauthorized connections to Sefas Innovation SFTP server (IPs not disclosed).
- **Behavioral indicators:** Unusual file download patterns and intermittent unauthorized logins over a multi-month period.
## Response Actions
- **Containment:** Sefas Innovation secured the affected SFTP server upon discovery.
- **Eradication:** Forensic investigation to identify the scope of the data accessed.
- **Recovery:** Public reporting on May 20, 2026, and notification to Frost Bank customers.
## Lessons Learned
- **Key takeaways:** Third-party software support channels (like SFTP) remain high-value targets for attackers seeking to bypass primary bank defenses.
- **Weaknesses:** The five-month dwell time between initial access (December) and discovery (April) indicates a need for more robust logging and alerting on vendor file-transfer systems.
## Recommendations
- **Third-Party Risk Management (TPRM):** Conduct more frequent security audits of vendors and enforce strict data retention policies on SFTP servers (delete files immediately after use).
- **Technical Controls:** Implement phishing-resistant Multi-Factor Authentication (MFA) for all vendor support portals and SFTP access.
- **Monitoring:** Deploy continuous attack surface management and monitor for unusual egress traffic or access patterns from third-party environments.
- **Customer Protection:** Frost Bank customers should place a security freeze on credit reports and monitor financial statements for unauthorized activity at hxxps[://]frostbank[.]com.