Hilltop National Bank, a $1.14 billion institution based in Casper, Wyoming, has kept its online and mobile banking systems offline for a week following a cybersecurity incident. The bank has not provided a timeline for when those services will be restored.

The disruption began on September 8, when the bank’s IT systems started to degrade. Overnight into September 9, staff determined the issue was a cybersecurity incident, and Hilltop took all systems offline as a precaution.

In a Monday evening update on a status page the bank created because its main website is down, Hilltop said it could not give a restoration time. “We had hoped to give you a definitive time tonight,” the update read. “Unfortunately, this process is time and labor-intensive, and, for that reason, we are currently unable to provide that level of detail at this time.”

Darren Cantlay, Hilltop’s president and chief executive, said in a video message on Saturday that restoring the systems is “specific and detailed work that takes time.” He added, “We deeply regret the concern and frustration this has caused all of you.”

Current Status of Banking Services

Hilltop closed all of its offices on September 9. Five reopened the next day, and by Monday, seven of its eight offices were open, each handling only a narrow set of transactions. The bank holds $987.6 million in deposits across those eight offices.

The reopened offices are handling deposits, withdrawals, checks issued by the bank itself, and limited cash back on other checks. For more complex requests, the bank has asked customers to come in and ask.

Debit cards are capped at $1,000 per day across stores and ATMs.

Direct deposits are still arriving, and customers “will have access to their funds,” according to a question-and-answer page the bank posted, though it did not specify how.

Scheduled outgoing payments for car notes, mortgages, and credit card bills were initially not going out, and the bank said it would reimburse any late charges caused by the outage. Payments that a lender pulls on its own will still clear. On Tuesday, a Hilltop spokesperson told American Banker that “scheduled outgoing recurring payments are going out as normal.”

Phone service went down with everything else, but the bank brought it back first. It opened a call center on September 10, two days into the outage, staffed from 9 a.m. to 5 p.m. on weekdays. The bank has warned that criminals are spoofing its call center number and has told customers not to answer calls from it, according to an update on its incident site.

The bank advises customers to trust only its updates site, its social media page, or a Hilltop employee. Its own website, hilltop.bank, was still down on Tuesday.

What the Bank Has Not Disclosed

Hilltop has not provided details about the cybersecurity incident that caused the outage. It has not disclosed whether malware, a stolen credential, or an intruder was involved, whether any data left its systems, or whether anyone demanded an extortion payment.

The bank also would not say which outside company runs its core banking software or when service is expected to return. A spokesperson did not answer American Banker’s questions on these matters.

No cybersecurity gang has claimed the bank as a victim on a leak site, the kind of page a criminal group uses to name organizations it says it hit to pressure them to pay. The monitoring service ransomware.live listed nothing for Hilltop as of Tuesday, and the bank has not called the incident ransomware.

Regulatory Notification and Disclosure Rules

Hilltop has notified the Office of the Comptroller of the Currency (OCC) and the Federal Reserve Bank in Kansas City about the incident, according to a question-and-answer page the bank posted last week.

A federal banking rule gives a national bank such as Hilltop 36 hours to notify the OCC once it decides it has had an incident serious enough to disrupt service to a meaningful share of its customers. The rule does not require the bank to tell its customers anything, and nothing in it requires the OCC to tell the public anything.

That is deliberate, according to Justin Herring, a partner at law firm Mayer Brown. Bank incident-notice rules “are deliberately designed to be confidential,” Herring said. “Unlike state data breach laws, they are created as part of the regulators’ regulatory supervision authority and not as consumer notice rules.”

Hilltop will owe the OCC a fuller account eventually, he said, but the public will not see that either. “The bank will still have to provide reporting to regulators, often extensive reporting,” Herring said. “But the regulators usually deem those reports to be protected as Confidential Supervisory Information.”

The rules that do produce a customer notice regard data breaches. A bank has to tell customers when someone gains unauthorized access to their sensitive information, and Hilltop has not said anyone did. Absent a data breach, Herring said, disclosure “will be driven by the bank’s judgment about what is necessary to maintain customer trust rather than a legal mandate.”

Regulators usually wait for a company to get further into its investigation before demanding detail, because “in the first week of responding to a major incident, most companies are still focused on recovering from the incident and in the process of piecing together what happened,” Herring said.

Asked about disclosure rules and Hilltop, a spokesperson for the OCC said the agency “does not comment on specific banks.” A spokesperson for the Federal Reserve Bank of Kansas City did not immediately respond to a request for comment.

How This Compares to Other Bank Outages

A week is a long time for customers to go without regular digital banking services, but it has happened before.

In early August, Sawyer Savings Bank in Saugerties, New York, closed all four of its branches over an apparent cybersecurity incident and then reopened them a week later. Sawyer’s outage was “likely the result of a data security incident,” its president and chief executive, James P. Whitaker, said in an August 6 update to customers. He said a vendor vulnerability was behind it but did not name the vendor. A group called Storm-1175 listed Sawyer on August 7 on a leak site.

Other outages have run much longer than a week. TruStage Financial Group, which says it serves 93% of credit unions, took its network offline in mid-July after identifying a cyberattack on July 11. Credit union members lost access to accounts including their 401(k) plans. A month later, TruStage still could not say whether anyone’s data had been taken. It faced 14 class actions in a single Wisconsin court.

What Customers Can Do

Hilltop customers should rely on the bank’s official updates site, its social media page, or a Hilltop employee for accurate information. The bank has warned about spoofed calls from its call center number, so customers should not answer calls from that number.

For transactions, the seven open offices can handle deposits, withdrawals, checks issued by the bank, and limited cash back on other checks. Debit card spending is capped at $1,000 per day. Direct deposits are still arriving, and scheduled outgoing recurring payments are going out as normal, according to the bank’s latest statement.

The bank has said it will reimburse any late charges caused by the outage. Customers with more complex needs should visit a branch and ask for assistance.

By Ryan

Leave a Reply

Your email address will not be published. Required fields are marked *