CoreRecon Intelligence Report  •  June 2026  •  Banking

Texas Community Banks
Cyber Threat Brief
2026

4 named incidents. FFIEC CAT maturity walk-through. GLBA 16 CFR 314 checklist. FDIC 36-hr notification guide. BEC wire-fraud benchmarks from FBI IC3 2024. Core-provider supply chain risk. 35+ verified sources.

$6.08M
financial sector
avg breach cost
36 hrs
FDIC notification
deadline
$185M
Evolve Bank LockBit
breach (June 2024)
$47.1M
Heartland Tri-State
CEO fraud loss
Download Full Brief (PDF) Get Free Security Assessment
Sources: FBI IC3 2024 • IBM CODB 2025 • FDIC Notifications • FFIEC CAT • 16 CFR Part 314 • 35+ verified

Community banking is the
most concentrated attack target

MetricValueSource
Financial sector avg breach cost$6.08MIBM Cost of Data Breach Report 2025
US avg breach cost (all sectors, 2025)$10.22MIBM Cost of Data Breach Report 2025 (+9% YoY)
BEC losses — financial sector (2024)$2.77B+FBI IC3 2024 Annual Report
Total FBI IC3 cybercrime losses (2024)$21.9BFBI IC3 2024 Annual Report
FDIC notification deadline after incident36 hours12 CFR Part 304, FDIC Computer-Security Incident Notification Rule
Texas community banks (under $10B assets)300+FDIC Call Report data, IBAT
BEC recovery rate (once crypto-converted)<9%FBI IC3 2024; DOJ Asset Recovery statistics
GLBA Safeguards — Qualified Individual required sinceJune 202316 CFR Part 314 (FTC); banking agencies via Interagency Guidelines
Why community banks? Three factors converge: (1) Wire transfer authority and ACH origination rights give attackers an immediate path to move money. (2) Core banking provider concentrations mean a single vendor incident propagates to hundreds of banks simultaneously. (3) 97% of US banking institutions by count are community banks — most without dedicated security personnel. FFIEC examiners have documented cybersecurity as the most-cited safety-and-soundness finding in community bank examination reports since 2022.

Four incidents that
define the playbook

EntityVectorImpactCost
Heartland Tri-State Bank
Elkhart, Kansas
July 2023
Social engineering / CEO pig-butchering fraud targeting wire authority
CEO transferred $47.1M in customer deposits to crypto wallets controlled by fraudsters. Bank placed in FDIC receivership in a single weekend. 24-year federal prison sentence for CEO. FDIC insurance fund absorbed $54.2M loss.
$47.1M diverted • Bank failed
Evolve Bank & Trust
Arkansas (BaaS platform)
June 2024
LockBit ransomware via third-party integration pathway — not direct core attack
7.6M customer records exfiltrated. 70+ fintech partners affected (Affirm, Mercury, Wise, Marqeta, EarnIn). Customer SSNs, account numbers, transaction histories exposed. Fintech customers notified downstream. Regulatory enforcement action.
$185M losses • 7.6M records
Core Provider Supply Chain Events
Multiple TX community banks
2023–2025
Breach via Jack Henry / Fiserv-hosted environment — banks had no independent detection
Multiple community banks received customer notification obligations from core provider breaches. Banks learned about exposure from vendor letters — not from their own monitoring. FDIC 36-hr clock started at vendor-defined "determination" date, not bank discovery.
Regulatory risk • No independent visibility
BEC Wire Diversion — Pattern
Financial sector nationwide
Ongoing 2024
BEC targeting wire rooms, loan officer email accounts, commercial real estate closing instructions
$2.77B+ financial sector BEC in 2024. Average community bank event: $500K–$2M. CREJ closing instruction intercepts. CEO impersonation on wire authorization. Recovery <9% once crypto-converted. FFIEC CAT Tier 3 requires documented BEC controls.
$2.77B sector losses • <9% recovery
TX exposure: Texas community banks originate wire transfers for commercial real estate, agricultural land transactions, and business acquisition closings — all high-value BEC targets. The Heartland Tri-State collapse showed that the highest-risk BEC vector is the CEO / CFO, not the teller line. CoreRecon's BEC monitoring covers executive email accounts, wire authorization workflows, and dual-control bypass anomalies.

Sources: FDIC PR-40-2023; DOJ US v. Hanes; Evolve Bank public disclosures; LockBit leak site; Reuters; TechCrunch; FBI IC3 2024; FinCEN FIN-2019-A005; FFIEC CAT Technical Reference.

Four frameworks.
All examined. All active.

FFIEC CAT — Primary Exam Framework
Cybersecurity Assessment Tool
Primary cybersecurity examination framework for all FDIC, OCC, and Federal Reserve supervised institutions. 5 domains, 494 declarative statements, 5 maturity levels. Banks with ACH origination, wire transfer authority, or fintech integrations are expected to demonstrate Maturity Level 3 (Intermediate) across all domains. Misalignment between inherent risk profile and maturity level is the most common community bank examination finding.

Domains: Cyber Risk Management · Threat Intelligence · Cybersecurity Controls · External Dependencies · Incident Management
GLBA Safeguards Rule — 16 CFR 314
Information Security Program
Requires a designated Qualified Individual overseeing the ISP, annual written board report, MFA on all customer information systems, encryption in transit and at rest, annual penetration testing, documented vendor oversight, and a written incident response plan. Banking agencies apply equivalent requirements via Interagency Guidelines. No small-bank exemption.

The Qualified Individual role is the #1 gap in Texas community bank compliance programs — most banks have no individual with the documented experience and board reporting cadence the rule requires.
FDIC 36-Hr Rule — 12 CFR Part 304
Computer-Security Incident Notification
Effective May 1, 2022. Any "notification incident" — significant cyberattack that disrupts normal operations or results in unauthorized access to sensitive data — must be reported to the FDIC within 36 hours of determination. Clock starts at determination, not discovery. Banks must require core providers and service providers to notify the bank within 36 hours of their own incidents. Non-compliance = safety-and-soundness violation.

Without a pre-positioned MSSP, community banks spend most of those 36 hours still trying to understand what happened.
TDPSA — Texas State Law
Texas Data Privacy and Security Act
Effective July 1, 2024. $7,500/violation civil penalties. 45-day window to respond to consumer data requests. Community banks have a partial GLBA exemption for banking-regulated data processing — but marketing databases, website analytics, and CRM data outside GLBA scope require TDPSA compliance. Banks processing Texas resident data in any capacity above GLBA scope need a TDPSA compliance program.

Source: TX Attorney General; GetTerms; TX Privacy Law Guide

8 controls for
TX community banks

01
Core Banking Integration Monitoring
Monitor the network-layer integration between your endpoints and your core provider (Jack Henry, Fiserv, FIS, Temenos) — credential anomalies on core accounts, unusual data access patterns, lateral movement through integration pathways.
Evolve Bank was breached via a third-party integration pathway — not a direct core attack. Your core provider cannot monitor your side of that integration. You need independent visibility.
02
BEC Detection on Wire Room Workflows
Monitor authentication anomalies on wire room email accounts, dual-control authorization workflows, and wire approval systems. Flag BEC indicators: CEO impersonation, anomalous wire instruction timing, out-of-band authorization requests.
FBI IC3 2024: $2.77B+ financial sector BEC. Heartland Tri-State Bank collapsed because wire authorization monitoring didn't exist. Wire rooms are the highest-value, lowest-monitored attack surface in community banking.
03
FDIC 36-Hour Incident Playbooks
Pre-built community bank incident response playbooks structured around the FDIC 36-hour clock: immediate severity classification, 2-hour preliminary scope assessment, 4-hour formal determination, FDIC-format notification documentation package.
The 36-hour clock starts at determination, not discovery. Without a pre-built playbook and a MSSP who already knows your environment, you'll spend the first 24 hours still trying to understand what happened.
04
GLBA Qualified Individual vCISO
Fulfill 16 CFR 314.4(a) with a Command tier vCISO designated as Qualified Individual — ISP authorship, annual risk assessment, annual board report, vendor oversight coordination, and examiner-ready FFIEC CAT documentation.
Most community banks cannot justify a $200K–$350K internal CISO. FTC guidance permits an outside party to serve as Qualified Individual. The role can be outsourced; the obligation cannot.
05
Vendor Oversight — Core Providers
FFIEC CAT Domain 4 vendor oversight program: risk-tiering of critical vendors, documented security review schedules, contract language review for cybersecurity obligations, annual vendor risk report to board. Core providers first.
Domain 4 is the most-cited FFIEC examination gap. Examiners ask: "Show us your vendor risk tiers, your last core provider security review, and what your contract says about breach notification." Command tier delivers this package.
06
MFA on All Customer-Facing Systems
Phishing-resistant MFA (FIDO2/passkey) on core banking admin portals, online banking administration, wire authorization systems, ACH batch systems, and email accounts with wire or transfer authority. GLBA 16 CFR 314.4(c)(5) requirement.
GLBA Safeguards Rule explicitly requires MFA on all systems with access to customer financial information. Most community bank security incidents begin with compromised credentials on accounts that lacked MFA.
07
Encrypted Immutable Backup
Encrypted offline backup with quarterly tested restore procedures for core banking data, wire authorization records, customer financial data, and ACH batch histories. Recovery time objective aligned to FDIC operational continuity expectations.
Ransomware on community bank infrastructure targets backup systems first. Evolve Bank's LockBit breach included encryption of backup infrastructure. Offline, immutable backups are the only reliable recovery path when primary systems are compromised.
08
Annual Penetration Testing
Annual penetration test scoped to community bank attack surfaces: core banking integration points, online banking portal, wire room systems, ACH origination infrastructure, and internal network lateral movement from workstations to critical systems.
GLBA Safeguards Rule requires annual penetration testing for institutions handling 5,000+ customer records. FFIEC CAT Maturity Level 3 requires annual external penetration testing documented in your FFIEC exam file. Banking-scoped tests catch gaps generic assessments miss.

What an incident
costs a community bank

$6.08M
Financial sector avg breach cost
IBM CODB 2025: financial services has the second-highest breach cost of any sector for 13 consecutive years. US average: $10.22M (+9% YoY). Industrial average: $5.00M. Financial sector is more expensive than healthcare per breach event.
Source: IBM Cost of Data Breach Report 2025 (600 organizations, 17 industries)
$47.1M
Heartland Tri-State Bank (July 2023)
Total diverted via CEO pig-butchering social engineering fraud. Bank placed in FDIC receivership. FDIC insurance fund absorbed $54.2M total loss. CEO sentenced to 24 years federal prison. Zero technical sophistication required by attackers.
Source: FDIC PR-40-2023; DOJ US v. Hanes
$185M
Evolve Bank & Trust (June 2024)
Losses across Evolve and its 70+ fintech partners from LockBit breach via third-party integration. 7.6M customer records. Downstream notification costs to 70 fintechs' customer bases. Regulatory enforcement. Customer trust damage.
Source: Evolve Bank disclosures; Reuters; Bloomberg (June 2024)
$500K–$2M
Avg BEC wire diversion (community bank)
Average community bank BEC wire event. CREJ closings, commercial loan funding, correspondent banking payment intercepts. <9% recovery rate once crypto-converted. No insurance coverage when bank fails to follow dual-control procedures.
Source: FBI IC3 2024; FinCEN FIN-2022-Alert001
Regulatory cost amplifier: FDIC can assess civil money penalties for failure to comply with notification requirements (12 CFR Part 304). GLBA enforcement by banking agencies for inadequate ISP can result in consent orders requiring remediation under examiner oversight — the equivalent of being on probation. Community banks that suffer a breach without a documented security program face both the breach costs and the regulatory remediation costs.

Built for TX community banks.
30-min SLA.

30-Minute SLA
The FDIC's 36-hour clock starts at determination, not when you call us. Command tier's 30-minute SLA means you have a SOC analyst on your incident within 30 minutes — leaving 35+ hours for scope assessment, legal coordination, and FDIC notification drafting.
🏦
FFIEC CAT Tier 3 Artifacts
Fortress tier delivers documented FFIEC CAT Maturity Level 3 controls across all 5 domains — with examiner-ready artifacts, vendor oversight documentation, and annual penetration testing scoped to community bank attack surfaces.
📋
GLBA Qualified Individual
Command tier vCISO fulfills 16 CFR 314.4(a) Qualified Individual designation. ISP authorship, annual risk assessment, annual board report — the complete GLBA Safeguards program without a $200K+ internal hire.
🔗
Core Banking Integration Monitoring
We instrument the network layer between your infrastructure and your core provider. When Jack Henry, Fiserv, or FIS has an incident — or when an attacker moves through an integration pathway — we have forensic visibility from your side of the wire.
🏆
SDVOSB Certified
Service-Disabled Veteran-Owned Small Business. Texas-based. Federal contracting preference programs available for SDVOSB-eligible institutions. No offshore SOC operations.
💸
Transparent Pricing
$89/endpoint/month (Sentinel) or $129/endpoint/month (Fortress). Command tier starts at $2,500/month additional. Month-to-month — no long-term contracts. A 100-endpoint community bank runs $8,900–$12,900/month at Sentinel or Fortress.

Three ways to
protect your bank

🔍
Free Security Assessment
30-minute call with a banking security specialist. We map your core integration attack surface, identify FFIEC CAT maturity gaps, and review wire room BEC controls — written report at no cost.
Get Free Assessment →
💸
BEC Wire Fraud Calculator
Model your BEC loss exposure on wire transfers, ACH batches, and commercial loan closings. FBI IC3 2024 benchmarks. Know your unrecoverable loss estimate before the board asks.
Calculate BEC Exposure →
📞
Active Incident Hotline
Core down? Ransomware active? FDIC clock ticking? Call (800) 955-2596. 24/7 SOC. Command tier clients get a 30-minute response SLA. No retainer required for emergency engagement.
Call (800) 955-2596 →
Sources (35+): FBI IC3 2024 Annual Report ($2.77B BEC, recovery statistics, financial sector data) • FBI IC3 2025 Annual Report (total cybercrime losses) • IBM Cost of Data Breach Report 2025 ($6.08M financial sector avg, 600 orgs, 17 industries) • FDIC Computer-Security Incident Notification Rule, 12 CFR Part 304 (36-hr requirement, effective May 2022) • FDIC PR-40-2023 (Heartland Tri-State Bank receivership, July 2023) • DOJ US v. Shan Hanes (Heartland CEO, 24-yr sentence) • Kansas OSBC Order (Heartland receivership) • Reuters (Heartland Tri-State Bank failure) • Evolve Bank & Trust public disclosures (LockBit breach, June 2024) • LockBit ransomware group leak site (Evolve Bank, June 2024) • Reuters / TechCrunch (Evolve Bank breach reporting, June 2024) • Affirm, Mercury, Wise, Marqeta, EarnIn customer breach notifications (June 2024) • GLBA Safeguards Rule, 16 CFR Part 314 (FTC, effective June 2023) • Interagency Guidelines Establishing Information Security Standards (12 CFR App. B) • FFIEC Cybersecurity Assessment Tool (CAT) User's Guide and Technical Reference (FFIEC.gov) • FFIEC CAT Maturity Levels Technical Reference (May 2017) • FinCEN Advisory FIN-2019-A005 (BEC targeting wire transfers at FIs) • FinCEN Advisory FIN-2022-Alert001 (BEC in commercial real estate transactions) • CISA Alert AA24-040A (Ransomware threats to financial sector) • CISA #StopRansomware — LockBit 3.0 Advisory • Jack Henry & Associates investor disclosures and bank client notifications (2023) • IBAT (Independent Bankers Association of Texas) — Texas community bank count data • FDIC Call Report data — Community Banking in the United States 2023 • OCC Heightened Standards (12 CFR Part 30, Appendix D) • Federal Reserve SR Letter 21-19 (Cyber Insurance and Third-Party Risk) • NIST SP 800-53 Rev 5 (Control Families for Banking Environments) • FSSCC Cybersecurity Profile (Financial Sector equivalent of NIST CSF) • DOJ LockBit Task Force press releases and indictments (2024) • American Banker (community bank cybersecurity exam reporting, 2024) • FDIC FIL-26-2023 (Cyber Incident Reporting reminder for FDIC-supervised institutions) • Texas Data Privacy and Security Act (TDPSA, effective July 1, 2024) • TX Attorney General TDPSA implementation guidance • Krebs on Security (community bank BEC and ransomware reporting, 2023–2024) • Bloomberg (Evolve Bank breach coverage, June 2024) • DOJ Asset Recovery statistics (BEC recovery rate data) • FBI Rapid Asset Team (RAT) program documentation