In 2026, Frost Bank experienced a data breach not from its internal systems but through a third-party vendor, Sefas Innovation. The breach occurred intermittently from December 2025 through April 2026 and was discovered by Frost Bank on April 22, 2026. This incident involved unauthorized access to an SFTP server maintained by Sefas Innovation, a document production service.
The confirmed data types exposed include names, Social Security numbers (SSNs), addresses, account numbers, taxpayer identification numbers (TINs), W-2s, 1099s, mortgage interest records, HSA contributions, tax forms, and bill-pay check images. The bank confirmed 191,848 affected individuals. While some reports suggest a higher number, up to 250,000 via vendor/leak estimates, the bank's confirmed number stands at 191,848. The full scope of the breach remains unclear, with some claims from the Everest ransomware group indicating up to 3.4 million records from Frost Bank and Citizens Financial Group due to a single vendor compromise.
Data breaches continue to be a concern, and details about incidents can emerge over time or be subject to delayed notifications.