New York bank regulator says vendor flaw hit its firms

1763662098723.jpeg
Kaitlin Asrow, acting superintendent of the New York Department of Financial Services
NYDFS
  • Key insight: New York's regulator says the N-central flaw reached firms it supervises, and American Banker identified Sawyer Savings Bank as possibly among them.
  • What's at stake: A bank whose IT provider gets caught in the window between a patch's release and its installation can suffer branch outages.
  • Expert quote: "At least in the U.S., technology services doesn't have its own sectoral regulator," said Justin Herring, a Mayer Brown partner who built the NYDFS cybersecurity division.

Overview bullets generated by AI with editorial review.

Processing Content

The software flaw at the center of a warning last week by New York's financial regulator might have reached at least one bank.

The New York State Department of Financial Services, or NYDFS, is "aware of impact to a limited number of covered entities and are working closely with them to ensure that consumers are protected," a department spokesperson told American Banker.

Covered entities are the firms the department licenses or charters: state-chartered banks, insurers and other financial companies. American Banker independently identified one such potentially impacted company: Sawyer Savings Bank in Saugerties, New York.

Asked how many firms the attacks reached or whether any reached a bank or a credit union, the spokesperson said NYDFS "cannot speak to specifics about individual institutions or comment on cybersecurity investigations."

The vulnerable product at the center of the impacts is N-central, sold by N-able. IT firms known as managed service providers, or MSPs, use it to monitor, patch and remotely control the computers of the businesses that hire them.

So, it's primarily a product that banks' vendors use, not banks themselves. However, an attacker who takes over a provider's N-central console inherits that control over every client on it, including a bank.

The department's Aug. 11 letter said the vulnerability is "likely limited to MSPs," then told regulated firms to find out whether any provider supporting their systems runs it.

Attackers began exploiting the N-central flaw on July 31, according to N-able, which shipped a fix on Aug. 2. N-able's hosted N-central installations updated themselves, but any copy running on an MSP's own server required someone to act.

Security firm Huntress found on Aug. 3 that 28.6% of the self-hosted servers it could reach were still unpatched.

A bank has only one way to know which kind of copy its vendor runs or whether that copy is patched. The bank must ask its vendor, as NYDFS has instructed.

Did the N-central flaw hit Sawyer Savings Bank?

Three days after attackers began exploiting the N-central flaw, Sawyer Savings Bank, a 155-year-old institution with $279 million of assets, closed all four of its branches. It reopened them a week later.

While it is unclear whether the Sawyer outage is tied to the N-central flaw, the circumstances suggest it.

The disruption is "likely the result of a data security incident," according to an Aug. 6 update from James P. Whitaker, Sawyer's president and chief executive.

"We believe this was the result of a vendor vulnerability," Whitaker said, although he did not name a specific vendor. Asked directly whether N-central or a provider running it was involved, the bank declined to answer.

"As our investigation into this matter is ongoing, I am unable to comment further at this time," Jenn Gutheil-Denier, Sawyer's senior vice president and chief operating officer, told American Banker on Monday.

Sawyer has a New York state bank charter, which makes it one of the firms the NYDFS letter addresses. The department did not answer American Banker's questions about whether Sawyer was affected by the N-central vulnerability.

Storm-1175, the group Microsoft says likely exploited the N-central flaw, listed Sawyer on Aug. 7 on its leak site, a page where a ransomware gang names the organizations it claims to have hit and pressures them to pay. American Banker reviewed the listing.

That does not necessarily mean the group hit Sawyer through the N-central flaw; the group reaches victims by multiple means.

No researcher, regulator or company has tied Sawyer's outage to N-central.

The bank is still working out "what if any data may have been affected, and to whom that data belongs," Whitaker wrote on Aug. 9.

Why New York moved this time

N-central had two other exploited vulnerabilities in the federal government's catalog of actively exploited flaws in August 2025, but the department did not write a letter then.

This time around, NYDFS issued a letter naming N-central due to an "awareness of ransomware activity involving exploitation of the N-Central vulnerability in managed service provider environments resulting in downstream impacts to financial services organizations," the department spokesperson said.

The alert "is not associated with" the 2025 entries, the spokesperson said.

Regulators learn about vulnerability exploitations from reports the public never sees, according to Justin Herring, a partner at the law firm Mayer Brown who built the department's cybersecurity division and signed its 2020 alert on the SolarWinds breach.

"Those reports are not public, but if NYDFS sees multiple related incidents reported, it is much more likely to issue a notice," Herring told American Banker.

Few victims, serious damage

Attackers reached "fewer than 10 organizations in our customer base," according to John Hammond, a senior principal security researcher at Huntress, which sells security monitoring to managed service providers.

Huntress has "not identified any impacted organization that was a bank, credit union, insurer, or provider serving one of those institutions," Hammond told American Banker.

Sophos, whose Aug. 4 analysis detailed one of the intrusions, now counts one confirmed and another suspected compromise in its own customer data, according to Rafe Pilling, its senior director of threat research.

The company's assessment remains that there is "no evidence that compromises are widespread," Pilling said.

The attacks looked "more opportunistic than targeted," Pilling told American Banker.

A security vendor only knows about the networks it monitors; the NYDFS sees confidential incident reports from every firm it licenses.

The vendors' accounts diverge on ransomware. Huntress has "not observed ransomware deployment" in these intrusions, Hammond said. Sophos saw ransomware-linked activity in both of its cases, Pilling said.

S-RM, a firm companies hire to respond to breaches, handled "several ransomware incidents" in which attackers got in through vulnerable N-central servers, according to an Aug. 7 advisory.

Hammond cautioned that the handful of cases his firm saw "cannot meaningfully be used as evidence that a particular sector was targeted."

Nobody supervises the company in the middle

Financial regulators "regulate financial institutions, not MSPs," said Herring, the attorney who built the New York department's cyber division.

As such, "the guidance and alerts they produce are directed towards regulated companies," he said. "At least in the U.S., technology services doesn't have its own sectoral regulator."

The gap is not New York's alone. The National Credit Union Administration has told Congress for years that it cannot examine the vendors serving credit unions, an authority it briefly held over Y2K worries and lost at the end of 2001.

That leaves banks as the only reachable target for regulators looking to contain vulnerabilities that start in the tech sector.

A bank should keep a program for managing outside vendors, Herring said, with procedures for chasing possible break-ins at the important ones, a named contact at each and contractual promises that the vendor will cooperate.

Regulators "will expect banks to be asking their MSPs about this risk but, of course, that doesn't guarantee that they will get a responsive answer," Herring said.

If something goes wrong, regulators "will likely take a dim view of a company that did not conduct diligence even after the DFS alert," he said, and will "more likely be forgiving with a bank that tried to get answers but couldn't."


For reprint and licensing requests for this article, click here.
Regulation and compliance Cyber Security Community banking Vendor management State regulators New York Risk management Technology
MORE FROM AMERICAN BANKER
Load More