- Key insight: New York's regulator says the N-central flaw reached firms it supervises, and American Banker identified Sawyer Savings Bank as possibly among them.
- What's at stake: A bank whose IT provider gets caught in the window between a patch's release and its installation can suffer branch outages.
- Expert quote: "At least in the U.S., technology services doesn't have its own sectoral regulator," said Justin Herring, a Mayer Brown partner who built the NYDFS cybersecurity division.
Overview bullets generated by AI with editorial review.
The software flaw at the center of
The New York State Department of Financial Services, or NYDFS, is "aware of impact to a limited number of covered entities and are working closely with them to ensure that consumers are protected," a department spokesperson told American Banker.
Covered entities are the firms the department licenses or charters: state-chartered banks, insurers and other financial companies. American Banker independently identified one such potentially impacted company: Sawyer Savings Bank in Saugerties, New York.
Asked how many firms the attacks reached or whether any reached a bank or a credit union, the spokesperson said NYDFS "cannot speak to specifics about individual institutions or comment on cybersecurity investigations."
The vulnerable product at the center of the impacts is N-central, sold by N-able. IT firms known as managed service providers, or MSPs, use it to monitor, patch and remotely control the computers of the businesses that hire them.
So, it's primarily a product that banks' vendors use, not banks themselves. However, an attacker who takes over a provider's N-central console inherits that control over every client on it, including a bank.
The department's
Attackers began exploiting the N-central flaw on July 31,
Security firm
A bank has only one way to know which kind of copy its vendor runs or whether that copy is patched. The bank must ask its vendor, as NYDFS has instructed.
Did the N-central flaw hit Sawyer Savings Bank?
Three days after attackers began exploiting the N-central flaw, Sawyer Savings Bank, a 155-year-old institution with
While it is unclear whether the Sawyer outage is tied to the N-central flaw, the circumstances suggest it.
The disruption is "likely the result of a data security incident," according to an
"We believe this was the result of a vendor vulnerability," Whitaker said, although he did not name a specific vendor. Asked directly whether N-central or a provider running it was involved, the bank declined to answer.
"As our investigation into this matter is ongoing, I am unable to comment further at this time," Jenn Gutheil-Denier, Sawyer's senior vice president and chief operating officer, told American Banker on Monday.
Sawyer has a New York state bank charter, which makes it one of the firms the NYDFS letter addresses. The department did not answer American Banker's questions about whether Sawyer was affected by the N-central vulnerability.
Storm-1175, the group Microsoft says
That does not necessarily mean the group hit Sawyer through the N-central flaw; the group
No researcher, regulator or company has tied Sawyer's outage to N-central.
The bank is still working out "what if any data may have been affected, and to whom that data belongs," Whitaker
Why New York moved this time
N-central had two other exploited vulnerabilities in the federal government's
This time around, NYDFS issued a letter naming N-central due to an "awareness of ransomware activity involving exploitation of the N-Central vulnerability in managed service provider environments resulting in downstream impacts to financial services organizations," the department spokesperson said.
The alert "is not associated with" the 2025 entries, the spokesperson said.
Regulators learn about vulnerability exploitations from reports the public never sees, according to Justin Herring, a partner at the law firm Mayer Brown who built the department's cybersecurity division and signed its
"Those reports are not public, but if NYDFS sees multiple related incidents reported, it is much more likely to issue a notice," Herring told American Banker.
Few victims, serious damage
Attackers reached "fewer than 10 organizations in our customer base," according to John Hammond, a senior principal security researcher at Huntress, which sells security monitoring to managed service providers.
Huntress has "not identified any impacted organization that was a bank, credit union, insurer, or provider serving one of those institutions," Hammond told American Banker.
Sophos, whose
The company's assessment remains that there is "no evidence that compromises are widespread," Pilling said.
The attacks looked "more opportunistic than targeted," Pilling told American Banker.
A security vendor only knows about the networks it monitors; the NYDFS sees confidential incident reports from every firm it licenses.
The vendors' accounts diverge on ransomware. Huntress has "not observed ransomware deployment" in these intrusions, Hammond said. Sophos saw ransomware-linked activity in both of its cases, Pilling said.
S-RM, a firm companies hire to respond to breaches, handled "several ransomware incidents" in which attackers got in through vulnerable N-central servers, according to an
Hammond cautioned that the handful of cases his firm saw "cannot meaningfully be used as evidence that a particular sector was targeted."
Nobody supervises the company in the middle
Financial regulators "regulate financial institutions, not MSPs," said Herring, the attorney who built the New York department's cyber division.
As such, "the guidance and alerts they produce are directed towards regulated companies," he said. "At least in the U.S., technology services doesn't have its own sectoral regulator."
The gap is not New York's alone. The National Credit Union Administration has
That leaves banks as the only reachable target for regulators looking to contain vulnerabilities that start in the tech sector.
A bank should keep a program for managing outside vendors, Herring said, with procedures for chasing possible break-ins at the important ones, a named contact at each and contractual promises that the vendor will cooperate.
Regulators "will expect banks to be asking their MSPs about this risk but, of course, that doesn't guarantee that they will get a responsive answer," Herring said.
If something goes wrong, regulators "will likely take a dim view of a company that did not conduct diligence even after the DFS alert," he said, and will "more likely be forgiving with a bank that tried to get answers but couldn't."












