- What's at stake: Customers of the $1.14 billion bank have gone a week without online banking or mobile banking, with debit cards capped at $1,000 a day and scheduled bill payments not going out.
- Supporting data: Hilltop holds $987.6 million in deposits across eight offices, seven of which are open for a narrow set of transactions.
- Forward look: Asked directly, the bank would not say what caused the incident, whether any data left its systems, which outside company runs its core banking software, or when service will return.
Overview bullets generated by AI with editorial review.
Hilltop National Bank took its online and mobile banking offline a week ago to contain a cybersecurity incident, and it has not said when customers will get them back.
The $1.14 billion bank in Casper, Wyoming, has run on partial service since Sept. 8, when its IT systems began to degrade.
Staff determined overnight into Sept. 9 that the trouble was what the bank has described as a cybersecurity incident. Hilltop took all of its systems offline as a precaution.
The bank could not give a restoration time, according to a
"We had hoped to give you a definitive time tonight," that update read. "Unfortunately, this process is time and labor-intensive, and, for that reason, we are currently unable to provide that level of detail at this time."
"We deeply regret the concern and frustration this has caused all of you," Darren Cantlay, Hilltop's president and chief executive, said in a
Hilltop closed all of its offices on Sept. 9. Five reopened the next day, and seven were open by Monday, each handling only a narrow set of transactions.
Hilltop has capped debit cards at $1,000 a day across stores and ATMs.
The bank told customers that scheduled outgoing payments for car notes, mortgages and credit card bills would not go out for the time being, and it will reimburse any late charges the outage causes. Payments a lender pulls on its own will still clear.
A spokesperson for Hilltop told American Banker on Tuesday that "scheduled outgoing recurring payments are going out as normal."
Direct deposits are still arriving and customers "will have access to their funds," according to a
Hilltop has not provided details about the cybersecurity incident that instigated the outage. It has not disclosed whether malware, a stolen credential or an intruder was involved, whether any data left its systems or whether anyone demanded an extortion payment.
No rule requires the bank to say publicly what happened. Hilltop is privately owned, so Securities and Exchange Commission rules on disclosing cyber incidents do not apply to the bank.
The spokesperson did not answer American Banker's questions about the cause, about who runs the bank's core banking software or about when service is expected to return.
No cybersecurity gang has claimed the bank as a victim on a leak site, the kind of page a criminal group uses to name the organizations it says it hit to pressure them to pay. The monitoring service
A week is long, but not unheard of
For any customer, a week is a long time to go without regular digital banking services, but it has happened before.
In early August, Sawyer Savings Bank in Saugerties, New York, closed all four of its branches over an apparent cybersecurity incident then
Sawyer's outage was "likely the result of a data security incident," its president and chief executive, James P. Whitaker, said in an
A group called Storm-1175 listed Sawyer on Aug. 7 on a leak site.
Other outages have run much longer than a week. TruStage Financial Group, which says it serves 93% of credit unions, took its network offline in mid-July after
The notice went to the regulator and stopped there
Hilltop has notified the Office of the Comptroller of the Currency and the Federal Reserve Bank in Kansas City about the incident, according to a
The rule does not require the bank to tell its customers anything, and nothing in it requires the OCC to tell the public anything. That is deliberate, according to Justin Herring, a partner at law firm Mayer Brown.
Bank incident-notice rules "are deliberately designed to be confidential," Herring said. "Unlike state data breach laws, they are created as part of the regulators' regulatory supervision authority and not as consumer notice rules."
Hilltop will owe the OCC a fuller account eventually, he said. The public will not see that either.
"The bank will still have to provide reporting to regulators, often extensive reporting," Herring said. "But the regulators usually deem those reports to be protected as Confidential Supervisory Information."
That leaves what a customer learns up to the bank. Absent a data breach, Herring said, disclosure "will be driven by the bank's judgment about what is necessary to maintain customer trust rather than a legal mandate."
Regulators usually wait for a company to get further into its investigation before demanding detail, because "in the first week of responding to a major incident, most companies are still focused on recovering from the incident and in the process of piecing together what happened," Herring said.
Asked about disclosure rules and Hilltop, a spokesperson for the OCC said the agency "does not comment on specific banks."
A spokesperson for the Federal Reserve Bank of Kansas City did not immediately respond to a request for comment.
What customers are left with
The seven offices Hilltop has reopened handle deposits, withdrawals, checks the bank issued itself and limited cash back on other checks. For customers with any request more complicated than that, the bank has said to come in and ask.
Hilltop "is working with federal agencies, appropriate law enforcement and cybersecurity professionals" on its response, according to a
Phone service went down with everything else, and the bank brought it back first. It opened a call center on Sept. 10, two days into the outage, and has staffed it from 9 a.m. to 5 p.m. on weekdays. The bank has warned that criminals are spoofing its call center number and has told customers not to answer calls from it, according to an update on its incident site.
The bank's advice is that customers trust only its updates site, its social media page, or a Hilltop employee.
Its own website,