Wyoming bank has been offline a week due to cyber incident

vlcsnap-2026-09-15-12h59m49s406.png
Darren Cantlay, president and CEO of Hilltop Bank, provides an update in a video message posted Saturday about the bank's ongoing outage.
Hilltop Bank
  • What's at stake: Customers of the $1.14 billion bank have gone a week without online banking or mobile banking, with debit cards capped at $1,000 a day and scheduled bill payments not going out.
  • Supporting data: Hilltop holds $987.6 million in deposits across eight offices, seven of which are open for a narrow set of transactions.
  • Forward look: Asked directly, the bank would not say what caused the incident, whether any data left its systems, which outside company runs its core banking software, or when service will return.

Overview bullets generated by AI with editorial review.

Processing Content

Hilltop National Bank took its online and mobile banking offline a week ago to contain a cybersecurity incident, and it has not said when customers will get them back.

The $1.14 billion bank in Casper, Wyoming, has run on partial service since Sept. 8, when its IT systems began to degrade.

Staff determined overnight into Sept. 9 that the trouble was what the bank has described as a cybersecurity incident. Hilltop took all of its systems offline as a precaution.

The bank could not give a restoration time, according to a Monday evening update on a site the bank created to post status updates (because its main website is down).

"We had hoped to give you a definitive time tonight," that update read. "Unfortunately, this process is time and labor-intensive, and, for that reason, we are currently unable to provide that level of detail at this time."

"We deeply regret the concern and frustration this has caused all of you," Darren Cantlay, Hilltop's president and chief executive, said in a video message on Saturday. Restoring the systems is "specific and detailed work that takes time," he said.

Hilltop closed all of its offices on Sept. 9. Five reopened the next day, and seven were open by Monday, each handling only a narrow set of transactions.

Hilltop has capped debit cards at $1,000 a day across stores and ATMs.

The bank told customers that scheduled outgoing payments for car notes, mortgages and credit card bills would not go out for the time being, and it will reimburse any late charges the outage causes. Payments a lender pulls on its own will still clear.

A spokesperson for Hilltop told American Banker on Tuesday that "scheduled outgoing recurring payments are going out as normal."

Direct deposits are still arriving and customers "will have access to their funds," according to a question-and-answer page the bank posted, though it did not say how.

Hilltop has not provided details about the cybersecurity incident that instigated the outage. It has not disclosed whether malware, a stolen credential or an intruder was involved, whether any data left its systems or whether anyone demanded an extortion payment.

No rule requires the bank to say publicly what happened. Hilltop is privately owned, so Securities and Exchange Commission rules on disclosing cyber incidents do not apply to the bank.

The spokesperson did not answer American Banker's questions about the cause, about who runs the bank's core banking software or about when service is expected to return.

No cybersecurity gang has claimed the bank as a victim on a leak site, the kind of page a criminal group uses to name the organizations it says it hit to pressure them to pay. The monitoring service ransomware.live listed nothing for Hilltop as of Tuesday, and the bank also has not called the incident ransomware.

A week is long, but not unheard of

For any customer, a week is a long time to go without regular digital banking services, but it has happened before.

In early August, Sawyer Savings Bank in Saugerties, New York, closed all four of its branches over an apparent cybersecurity incident then reopened them a week later.

Sawyer's outage was "likely the result of a data security incident," its president and chief executive, James P. Whitaker, said in an Aug. 6 update to customers. He said a vendor vulnerability was behind it but did not name the vendor.

A group called Storm-1175 listed Sawyer on Aug. 7 on a leak site.

Other outages have run much longer than a week. TruStage Financial Group, which says it serves 93% of credit unions, took its network offline in mid-July after identifying a cyberattack on July 11. Credit union members lost access to accounts including their 401(k) plans.

A month on, TruStage still could not say whether anyone's data had been taken. It faced 14 class actions in a single Wisconsin court.

The notice went to the regulator and stopped there

Hilltop has notified the Office of the Comptroller of the Currency and the Federal Reserve Bank in Kansas City about the incident, according to a question-and-answer page the bank posted last week.

A federal banking rule gives a national bank such as Hilltop 36 hours to notify the OCC once it decides it has had an incident serious enough to disrupt service to a meaningful share of its customers.

The rule does not require the bank to tell its customers anything, and nothing in it requires the OCC to tell the public anything. That is deliberate, according to Justin Herring, a partner at law firm Mayer Brown.

Bank incident-notice rules "are deliberately designed to be confidential," Herring said. "Unlike state data breach laws, they are created as part of the regulators' regulatory supervision authority and not as consumer notice rules."

Hilltop will owe the OCC a fuller account eventually, he said. The public will not see that either.

"The bank will still have to provide reporting to regulators, often extensive reporting," Herring said. "But the regulators usually deem those reports to be protected as Confidential Supervisory Information."

The rules that do produce a customer notice regard data breaches. A bank has to tell customers when someone gains unauthorized access to their sensitive information, and Hilltop has not said anyone did.

That leaves what a customer learns up to the bank. Absent a data breach, Herring said, disclosure "will be driven by the bank's judgment about what is necessary to maintain customer trust rather than a legal mandate."

Regulators usually wait for a company to get further into its investigation before demanding detail, because "in the first week of responding to a major incident, most companies are still focused on recovering from the incident and in the process of piecing together what happened," Herring said.

Asked about disclosure rules and Hilltop, a spokesperson for the OCC said the agency "does not comment on specific banks."

A spokesperson for the Federal Reserve Bank of Kansas City did not immediately respond to a request for comment.

What customers are left with

The seven offices Hilltop has reopened handle deposits, withdrawals, checks the bank issued itself and limited cash back on other checks. For customers with any request more complicated than that, the bank has said to come in and ask.

Hilltop "is working with federal agencies, appropriate law enforcement and cybersecurity professionals" on its response, according to a statement the Wyoming Bankers Association posted on Hilltop's incident site. The association is an industry group representing the state's banks.

Phone service went down with everything else, and the bank brought it back first. It opened a call center on Sept. 10, two days into the outage, and has staffed it from 9 a.m. to 5 p.m. on weekdays. The bank has warned that criminals are spoofing its call center number and has told customers not to answer calls from it, according to an update on its incident site.

The bank's advice is that customers trust only its updates site, its social media page, or a Hilltop employee.

Its own website, hilltop.bank, was still down on Tuesday.


For reprint and licensing requests for this article, click here.
Cyber Security Community banking OCC Regulation and compliance Technology
MORE FROM AMERICAN BANKER
Load More