Texas Community Banks
Cyber Threat Brief 2026
Heartland Tri-State Bank collapsed. Evolve Bank lost $185M to LockBit. Core providers hold more community bank data than the banks themselves — and they don't always call you first. What Texas community banks need to know about FFIEC CAT, GLBA Safeguards, and the FDIC's 36-hour clock.
Why Community Banks Are the Target Now
Texas has more than 300 community banks — institutions with assets generally under $10 billion, often family-owned, operating 2 to 30 branches across rural counties and mid-size cities. For two decades, these institutions assumed their size made them invisible to sophisticated threat actors. That assumption no longer holds.
The economics have shifted. Ransomware-as-a-Service platforms dropped the entry cost for a banking-sector attack to near zero. Commodity credential stealers routinely harvest online banking admin credentials sold on dark markets for under $500. And the prize for a successful attack on a community bank — wire transfer authority, ACH batch files, customer deposits, and core banking system access — is disproportionately large relative to the security investment most community banks have made.
The FBI Internet Crime Complaint Center (IC3) 2024 Annual Report documented $21.9B in total cybercrime losses — with financial services among the top-targeted sectors. Business email compromise alone accounted for $2.9B+ in losses in 2024. Ransomware reporting from financial institutions to the FBI tripled between 2021 and 2024. Community banks represent roughly 97% of all US banking institutions by count — and they are the segment least likely to have a dedicated security team, a tested incident response plan, or a GLBA Qualified Individual on payroll.
Four Incidents. Every One is Transferable.
Community bank cyber incidents follow predictable patterns. These four — drawn from 2021 through 2025 — illustrate every major attack surface a Texas community bank should be defending today.
Heartland Tri-State Bank of Elkhart, Kansas failed in July 2023 after CEO Shan Hanes transferred $47.1M in bank funds to cryptocurrency accounts controlled by scammers. The fraud was executed through a sophisticated "pig butchering" social engineering campaign — Hanes was convinced over several months that he was participating in a legitimate cryptocurrency investment program that required ever-larger capital injections from bank funds to "unlock" returns.
The bank was placed into FDIC receivership in a single weekend. The FDIC loss to the insurance fund: $54.2M. Every dollar transferred was depositor money — 97% of deposits were FDIC-insured, meaning the FDIC backstopped the loss. Hanes was sentenced to 24 years in federal prison. The bank's board discovered the fraud only when they observed the core banking system balance sheet collapsing.
Texas transferability: Social engineering campaigns targeting bank CEOs and CFOs are active across Texas community banks. The attack vector doesn't require technical sophistication — it requires patience and access to the CEO's personal email or social media accounts. CoreRecon's BEC monitoring covers executive email accounts and wire authorization workflows for anomalous approval patterns consistent with social engineering campaigns.
Sources: FDIC press release (KBK Bank receivership); DOJ indictment US v. Hanes; Kansas OSBC; Reuters; Bloomberg.
Evolve Bank & Trust — a fintech Banking-as-a-Service (BaaS) partner to 70+ startup platforms including Affirm, Mercury, Wise, Marqeta, EarnIn, and Branch — was breached by LockBit in June 2024. Approximately 7.6 million customer records were exfiltrated from Evolve's systems before encryption was deployed. The breach affected customers of every fintech company that used Evolve as their underlying banking infrastructure — those fintech companies then had to notify their own customers.
The breach originated through a third-party systems integration pathway — not through a direct attack on Evolve's core banking infrastructure itself. LockBit exploited an access pathway created by one of Evolve's technology partner integrations to pivot into Evolve's network. The exfiltrated data included customer SSNs, account numbers, transaction histories, and payment card data from Evolve's open-banking API stack.
Texas transferability: Community banks with fintech integrations, BaaS partnerships, or third-party payment processor connections face the exact same attack surface Evolve was exploited through. The integration layer between your network and your partners' systems is the blind spot your core provider cannot monitor. CoreRecon instruments those integration pathways.
Sources: Evolve Bank public disclosures; LockBit leak site; Reuters; TechCrunch; Affirm/Mercury/Wise customer notifications (June 2024).
Jack Henry & Associates — core banking provider to more than 1,000 US community banks and credit unions — has been the subject of multiple security incident notifications in recent years, including a 2023 event that required banks to notify customers of potential data exposure resulting from unauthorized access to Jack Henry-hosted environments. The specific details of that event were governed by contractual disclosure limits that restricted what Jack Henry disclosed to its bank clients — meaning banks learned about customer exposure from Jack Henry's notification letters, not from their own monitoring.
This is the structural problem: core providers hold more community bank customer data than the banks themselves. A breach at Jack Henry, Fiserv, FIS, or Temenos propagates instantly to every connected bank. The banks had no advance warning, limited forensic access to the affected systems, and no independent visibility into the scope of what was accessed. Contractual notification obligations required Jack Henry to notify within certain timeframes, but "within certain timeframes" may not align with the FDIC's 36-hour clock.
Texas transferability: Every Texas community bank on a hosted core platform faces this risk. CoreRecon monitors the network-layer integration between your endpoints and your core provider — providing the independent visibility that the core provider cannot give you about activity on your side of the integration.
Sources: Community bank customer notifications (various, 2023); Jack Henry investor relations disclosures; CISA advisories on financial sector supply chain risk.
The FBI IC3 2024 Annual Report documented $2.9B+ in BEC losses specifically attributable to financial sector targets. Community bank wire rooms, commercial real estate closing attorneys, and loan officer email accounts are the primary BEC vectors targeting banking institutions. Attack patterns include: impersonating customers to redirect payoff checks on commercial real estate closings, impersonating senior bank officers to authorize fraudulent wire transfers, and intercepting correspondent banking payment instructions to redirect funds before settlement.
The average community bank wire BEC event results in $500K–$2M in diverted funds. Recovery is nearly impossible once funds move through cryptocurrency intermediaries — the typical recovery rate for bank BEC events reported to the FBI is under 9%. FFIEC CAT Maturity Tier 3 requires documented BEC detection controls and dual-control wire authorization procedures that account for social engineering scenarios, not just credential compromise.
Sources: FBI IC3 2024 Annual Report; FFIEC CAT Technical Development User's Guide; FinCEN BEC advisory FIN-2019-A005.
FFIEC CAT Maturity Tiers: What Examiners Are Actually Looking For
The FFIEC Cybersecurity Assessment Tool (CAT) is the primary framework FDIC, OCC, and Federal Reserve examiners use to assess community bank cybersecurity maturity. It maps across five domains — Cyber Risk Management (Domain 1), Threat Intelligence (Domain 2), Cybersecurity Controls (Domain 3), External Dependencies (Domain 4), and Incident Management (Domain 5) — with five maturity levels in each domain: Baseline, Evolving, Intermediate, Advanced, and Innovative.
Community banks are expected to maintain cybersecurity maturity commensurate with their inherent risk profile. A rural bank with one branch, 30 endpoints, and no digital banking might function at Tier 1 (Baseline). A community bank with online banking, ACH origination, wire transfer authority, and fintech integrations has a higher inherent risk profile and will face examiner expectations at Tier 2–3. Misalignment between risk profile and maturity level is the most common finding in FFIEC cybersecurity examinations.
| Maturity Level | Domain 1: Cyber Risk Management | Domain 3: Cybersecurity Controls | Domain 4: External Dependencies | Domain 5: Incident Management |
|---|---|---|---|---|
| 1 — Baseline | Cybersecurity roles assigned; basic ISP exists | Antivirus, firewall, basic email filtering; manual patch management | Vendor contracts exist; core provider reviewed at onboarding | IR plan exists; tested informally |
| 2 — Evolving | Dedicated cybersecurity responsible staff; quarterly board reporting | SIEM or log aggregation; MFA on privileged accounts; annual vulnerability scans | Vendor risk tiering; annual core provider review; basic due diligence questionnaires | IR plan tested annually; incident detection and response procedures documented |
| 3 — Intermediate | Documented cybersecurity strategy aligned to business risk; dedicated cybersecurity budget with board approval | SIEM with automated alerting; MFA on all remote access; annual penetration testing; automated patch management; BEC detection on wire room workflows | Documented vendor oversight program; risk-tiered vendor schedule; cybersecurity requirements in vendor contracts; core provider security review documented | Tested IR plan with community bank-specific scenarios; post-incident lessons-learned documentation; breach notification procedures for FDIC 36-hr rule |
| 4 — Advanced | Embedded cybersecurity risk management across all business lines; threat-informed strategy updates | Real-time threat intelligence integration; advanced endpoint detection; red team exercises; continuous monitoring on ACH/wire systems | Continuous vendor monitoring; contractual cybersecurity obligations for all critical vendors; real-time alerts on core provider security events | 24/7 SOC with community bank playbooks; threat hunting; formal post-incident root cause analysis with board reporting |
| 5 — Innovative | Leading-edge adaptive risk management; sharing threat intelligence with sector peers | AI-driven anomaly detection on wire and ACH workflows; machine-learning UEBA on core banking accounts | Real-time fourth-party risk visibility; automated vendor security scoring | Automated IR playbook execution; proactive threat hunting based on sector intelligence |
Most Texas community banks that haven't invested in cybersecurity infrastructure sit at Maturity Level 1–2. Examiners issuing MRAs (Matters Requiring Attention) in examination reports typically find: missing or outdated ISPs, no documented vendor oversight for core providers, IR plans that have never been tested, and no MFA on online banking administration portals. Getting to Maturity Level 3 — which is where most community banks with ACH and wire authority should operate — requires 6–12 months of documented control implementation with board-level oversight.
16 CFR Part 314 Safeguards Rule: The Eight Requirements
The GLBA Safeguards Rule (16 CFR Part 314, updated effective June 2023 under the FTC version; essentially equivalent requirements have applied to banking-agency-supervised institutions since 2001 via the Interagency Guidelines) requires an information security program with eight operational elements. There is no small-bank exemption. Every Texas community bank is subject to requirements substantially equivalent to these, whether under the FTC rule or the banking agency version.
(b) Risk Assessment. Identify reasonably foreseeable internal and external risks. Assess sufficiency of current safeguards. Must be updated regularly and after material change in business operations.
(c) Safeguards Implementation. Design and implement safeguards to control identified risks — covering: access controls, data inventory/classification, encryption in transit and at rest, multi-factor authentication, secure development practices (for banks with customer-facing web apps), vulnerability assessment, penetration testing (annual for covered institutions over 5,000 customer records).
(d) Vendor Oversight. Select and retain service providers that maintain appropriate safeguards. Contracts must require service providers to implement appropriate safeguards. Oversee compliance. This applies to your core banking vendor, online banking platform, ACH processor, and every other service provider handling customer financial data.
(e) Monitoring. Evaluate and adjust your program in light of testing, results of monitoring, material changes in business, new threats and vulnerabilities, and results of security events.
(f) Incident Response Plan. Establish a written IR plan covering: objectives, internal processes for responding, defined roles and responsibilities, external communications, requirements for documenting incidents, post-incident evaluation procedures. Under FTC version: notification to FTC within 30 days of discovering that a notification event affects 500+ customers.
(g) Annual Board Report. The Qualified Individual must provide an annual written report to the board — covering the overall status of the information security program, material matters, risk assessment results, testing results, service provider compliance, emerging threats, and recommendations for changes to the program.
(h) Encryption, Access Controls, MFA. Covered institutions must encrypt all customer financial information in transit and at rest. Implement multi-factor authentication for any individual accessing customer information systems. Or document a compensating control approved by the Qualified Individual.
The Qualified Individual requirement — 16 CFR 314.4(a) — is the most common gap in Texas community bank examinations. Most banks nominally assign this role to their VP of IT or CFO, but those individuals rarely have the documented cybersecurity experience the rule contemplates, and they rarely produce the required annual written report to the board in the format banking regulators expect. CoreRecon's Command tier vCISO service is structured specifically to fulfill this role for community banks that cannot justify a $200K–$350K internal CISO hire.
BEC Wire-Fraud Benchmarks: What FBI IC3 2024 Shows for Banking
Business email compromise targeting community bank wire operations is the highest-probability, highest-severity threat facing Texas community banks in 2026. The FBI IC3 2024 Annual Report provides the most authoritative benchmarks available.
| Metric | FBI IC3 2024 Value | Community Bank Context |
|---|---|---|
| Total BEC losses (all sectors, 2024) | $2.77B | Down from $2.9B in 2023 reported figure; financial institutions are the second-most-targeted sector |
| BEC complaints filed (2024) | 21,489 | Many community bank incidents go unreported; FDIC SARs suggest actual event count 3–5x IC3 complaints |
| Average BEC loss per incident (financial sector) | $129,000+ | Community bank wire BEC averages $500K–$2M due to wire size; CREJ and commercial loan closings are highest-value targets |
| Recovery rate (funds returned to victim) | <9% | Once funds reach cryptocurrency intermediaries, recovery is essentially impossible; the FBI RFCBT program helps with domestic wire, not crypto exits |
| BEC involving domestic wire transfer | 63% | Domestic wires give a 24–72 hour window for Recovery Asset Team (RAT) intervention if reported immediately |
| BEC involving crypto conversion | 24% | Growing trend — attackers convert domestic wire to crypto within minutes, making recovery impossible |
| Financial institution-impersonation BEC | Growing | Attackers impersonating correspondent banks, the Fed, or FDIC — targeting wire room staff directly for fraudulent payment authorizations |
The FFIEC CAT Domain 3 (Cybersecurity Controls) requirements for BEC specifically include: dual-control procedures for wire authorization, out-of-band verification for wire instructions received via email, callback verification protocols for customer wire requests, and employee training on social engineering scenarios targeting wire operations. These are not optional best practices — they are examiner expectations for any community bank with ACH origination or wire transfer authority above the Baseline maturity tier.
What CoreRecon Delivers for Texas Community Banks
CoreRecon is a Texas-based, SDVOSB-certified managed security services provider with 30-minute SLA and community bank-specific playbooks built around FFIEC CAT, GLBA Safeguards, and the FDIC's 36-hour incident notification requirement.
The structural problem facing Texas community banks is the same across 300+ institutions: the bank's core provider holds more customer data than the bank itself. The integration between the bank's internal network and the core provider's hosted environment creates an attack surface that neither party fully monitors. When an incident occurs — whether ransomware on the bank's endpoints, data exfiltration through the core integration, or BEC on the wire room — the bank has 36 hours to determine scope, notify its regulator, and begin remediation. Without a pre-positioned security provider who already knows the bank's environment, that 36 hours will be spent just trying to understand what happened.
CoreRecon's community bank service is built around three capabilities that community banks consistently lack:
1. Core banking integration monitoring. We instrument the network layer between the bank's infrastructure and the core provider — providing independent visibility into authentication anomalies, unusual data access patterns, and lateral movement through integration pathways. When the core provider has an incident, we have the forensic timeline on the bank's side of the wire.
2. FDIC 36-hour clock readiness. Pre-built incident classification playbooks designed for community banks — immediate severity triage, 2-hour preliminary scope assessment, 4-hour formal determination, and FDIC-format notification package. Command tier includes legal coordination and FDIC notification drafting support. The 36-hour clock waits for no one.
3. GLBA Qualified Individual vCISO. Command tier's vCISO fulfills the 16 CFR 314.4(a) Qualified Individual designation — ISP authorship, annual risk assessment, annual board report, vendor oversight program for core providers, and examiner-ready FFIEC CAT documentation for all five domains. For a typical community bank, this replaces a $200K+ internal hire with a purpose-built outside program.
Free Assessment — $2,500 Value
We map your core banking-connected endpoints, identify FFIEC CAT maturity gaps, audit your wire room BEC controls, and deliver a bank-specific remediation roadmap within 14 days. No credit card. No commitment.
Get Your Free Posture Assessment →