> ## Content Index
> Fetch the complete content index at: https://www.thecybersignal.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Citizens Bank Hit With Two Federal Lawsuits After Everest Ransomware Attack
- URL: https://www.thecybersignal.com/citizens-bank-hit-with-two-federal-lawsuits-after-everest-ransomware-attack/
- Published: 2026-04-23T19:22:00.000Z
- Updated: 2026-08-27T21:53:38.000Z
- Author: Nicholas Robert
- Tags: Data Breaches, Risk Management, Data Governance, PII (Personally Identifiable Information), Trending, Legal, Policy & Government

Following our initial report on the [Everest ransomware group's claims](https://www.thecybersignal.com/vendor-vulnerability-citizens-financial-manages-data-incident-amid-everest-ransomware-claims/), Citizens Financial Group now faces a dual-front battle as federal litigation arrives in Rhode Island.

**Update (August 26, 2026):** The litigation has expanded beyond the two original suits described below. By April 29, 2026, American Banker counted four federal complaints against Citizens in the U.S. District Court for the District of Rhode Island, alongside two state-court petitions against Frost Bank in Texas. Citizens has since issued breach notifications offering affected customers two years of Equifax Credit Watch Gold membership, and told American Banker that the complaints’ claims “are generally inaccurate.”

**PROVIDENCE, RI** — The legal fallout from the Everest ransomware group’s alleged breach of Citizens Bank has accelerated with the filing of two separate federal class action lawsuits in the US District Court for the District of Rhode Island. The litigation, filed on April 22, 2026, follows a "data incident via a third-party vendor" that the bank confirmed earlier this week.

The named plaintiffs, Jillian Russell Hauser and Lorien Hansford, represent a potentially massive class of customers whose names, Social Security numbers (SSNs), dates of birth, and financial account details were allegedly exposed. While Everest claims to have exfiltrated 3.4 million records, Citizens maintains that the vast majority of the data involved was "masked test data" rather than live production records.

---

## Breach Audit: Litigation Timeline

The speed of these filings — arriving just days after the initial threat actor claim — underscores a new reality in [risk management](https://www.thecybersignal.com/tag/risk-management/): the litigation window has closed to near-zero.

| Incident to Litigation Timeline (April 2026) |                                                                                                                                                                                   |
| -------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Date                                         | Event Details                                                                                                                                                                     |
| April 20                                     | Everest ransomware group lists Citizens Bank on its dark web leak site.                                                                                                           |
| April 21                                     | Citizens confirms an incident involving a third-party vendor environment.                                                                                                         |
| April 22                                     | Two federal class actions filed: attorney Peter N. Wasylyk on behalf of plaintiff Jillian Russell Hauser, and attorney Jules D’Allesandro on behalf of plaintiff Lorien Hansford. |

---

## Allegations of Negligence

The 40-page complaint — filed by Rhode Island attorney Peter N. Wasylyk of the Law Offices of Peter N. Wasylyk, with national counsel Raina C. Borrelli of Strauss Borrelli PLLC, on behalf of Jillian Russell Hauser — and the 34-page complaint filed by Jules D’Allesandro on behalf of Lorien Hansford both allege that Citizens failed to implement industry-standard security measures, specifically citing a lack of multi-factor authentication (MFA) and IP-based restrictions on the vendor’s database. Counsel for the plaintiffs argue that the bank breached its fiduciary duty by allowing sensitive PII to remain vulnerable in a non-production environment.

Citizens has pushed back, stating that "operations continue as normal" and that there is no evidence of a compromise within their core internal network. However, the legal focus remains on [vendor vulnerability management](https://www.thecybersignal.com/vendor-vulnerability-citizens-financial-manages-data-incident-amid-everest-ransomware-claims/), a pattern we have seen in other recent [systemic fragility incidents](https://www.thecybersignal.com/systemic-fragility-humana-discloses-second-major-data-breach-in-two-months/).

---

## The CyberSignal Analysis

### Signal 01 — The "Masked Data" Defense

Citizens' primary defense rests on the claim that the stolen data was "masked." In [data governance](https://www.thecybersignal.com/tag/data-governance/) terms, if the masking was insufficient or reversible, the bank still faces full liability. The lawsuits will likely force a discovery process to determine if the "test data" was actually pseudonymized production data — a frequent oversight in financial DevOps cycles.

### Signal 02 — The Escalation of Vendor Liability

This case highlights the growing trend of "vendor-leaping," where threat actors bypass a bank’s hardened perimeter by targeting softer third-party partners. For CISOs, this means cyber essentials must be enforced not just on partners, but specifically on the testing and staging environments those partners use.

---

## Sources

| Type              | Source                                                                                                                                                                                              |
| ----------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Legal Report      | [GoLocalProv: Class Action Details](https://www.golocalprov.com/business/citizens-bank-hit-with-two-federal-lawsuits-after-cyberattack?ref=thecybersignal.com)                                      |
| Threat Intel      | [Cybernews: Everest Ransomware Claim Against Frost and Citizens](https://cybernews.com/security/everest-ransomware-frost-citizens-bank-breach/?ref=thecybersignal.com)                              |
| Industry News     | [Morningstar: Legal Investigations](https://www.morningstar.com/news/pr-newswire/20260422ph41820/citizens-bank-data-breach-edelson-lechtzin-llp-launches-investigati?ref=thecybersignal.com)        |
| Company Statement | [Citizens Financial Group: April 21, 2026 Statement](https://investor.citizensbank.com/about-us/newsroom/latest-news/2026/2026-04-21.aspx?ref=thecybersignal.com)                                   |
| Litigation Update | [American Banker: Customers Sue Citizens, Frost Over Third-Party Data Breach](https://www.americanbanker.com/news/customers-sue-citizens-frost-over-third-party-data-breach?ref=thecybersignal.com) |
| Original Cover    | [The CyberSignal: Initial Coverage](https://www.thecybersignal.com/vendor-vulnerability-citizens-financial-manages-data-incident-amid-everest-ransomware-claims/)                                   |