-
Nine months before the outage, the NCUA told a federal council it may no longer need the authority to examine vendors like the one that failed.
September 21 -
Constellation Software subsidiary CORA Group rebranded its U.S. core banking service as regulators are looking to inspect core vendor relationships.
September 14 -
The theft of 153 million drivers' licenses highlights the danger of having a small number of vendors serve an entire industry.
September 8 -
The New York State Department of Financial Services warned banks about a security vulnerability in IT software. Now it's acknowledged some companies it oversees were affected by it.
August 17 -
As community banks lean on third-party vendors to keep up with AI developments, executives say regulatory standards must be put in place to account for the increased risk they face.
August 14 -
Many banks can't say what software their IT provider runs. Only 58% of community and midsize banks even hold the right to audit that vendor, a survey found.
August 13 -
The company, which says it serves 93% of credit unions, expects most key processes to run by mid-August. Its status page still said "Investigating" Wednesday.
August 12 -
The banking regulator is in early discussions with trade groups to build an organization for certifying tech providers that pass voluntary due diligence checks.
August 12 -
The class action is an early test of whether credit unions can hold their vendors liable for the cybersecurity they promise.
July 21 -
Verizon's 2026 Data Breach Investigations Report finds attackers now break in most often through unpatched software and third-party vendors, not stolen passwords.
June 1 -
The case exposes a systemic risk for banks: incident-response and ransomware-negotiation firms receive sensitive breach details that a corrupted insider can sell back to the attackers.
May 1 -
Both banks deny their networks were breached. Experts say the data likely points to a single vendor that was compromised.
April 22 -
Union Bank and Trust is resolving claims from a 2023 software exploit that exposed customer data to cybercriminals.
March 17 -
Cybercriminals say they stole sensitive records by exploiting an unpatched vulnerability known as React2Shell and using the password Lexis1234.
March 6 -
Threat group ShinyHunters claimed responsibility for the attack, which reportedly targeted third-party platforms rather than Betterment's own systems.
February 6 -
Supply chain attacks have doubled since 2021, with professional services firms increasingly acting as "stepping stones" to access bank data.
January 29 -
New disclosures show the ransomware attack on the marketing vendor affected far more community banks and credit unions than initially estimated.
January 5 -
A service outage on Friday at Fiserv affected multiple banks and crippled at least 60 applications for some Fiserv customers, including Early Warning's peer-to-peer money transfer app Zelle. The issue, while resolved, reiterates the importance of bank redundancies.
May 5 -
A power outage and hardware failure at fintech FIS last week delayed deposits and payments at 27 banks, including Capital One.
January 21 -
Automatic updates and data encryption have their advantages. As many CrowdStrike customers learned on July 19, they also have disadvantages.
August 12






















