Frost Bank
bd_57500bb26b4174d5 · schema v1 · pii pii-v2
Full breach record for Frost Bank →Sefas Innovation, Inc. notified Frost Bank customers of a data security incident involving an SFTP server used for software support. Unauthorized access occurred between December 2025 and April 2026, resulting in the exfiltration of tax forms and bill pay images containing names, SSNs, and account numbers. Frost Bank was notified on April 22, 2026. Affected individuals were offered 12 months of credit monitoring. The incident is contained.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 1, 2025
Begins
Apr 16, 2026
Discovered
May 19, 2026
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteeverestbd_5a86e8b29efb82bf2026-04-20 · +29dVerified
Regulatory filings (4) · sorted by filing gap
- Texas State AGbd_5f4aac65b3dc3f392026-05-20 · +1dVerified
- Massachusetts State AGbd_8b776d1a699a96f92026-05-20 · +1dVerified
- Vermont State AGbd_9bc98c2af470155e2026-05-20 · +1dVerified
- California State AGbd_b213ce708cd456a52026-05-20 · +1dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.