Hilltop Bank reopens most branches following cybersecurity incident, warns of call center spoofing | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


CASPER, Wyo. — Hilltop Bank has reopened all but one of its locations throughout Wyoming following a cybersecurity breach the prior week, with bank officials reporting to Oil City News that customer accounts remain secure as recovery efforts continue.

Hilltop Bank and True Companies spokesperson Bill Salvin said Monday that every bank branch except the Cheyenne Prairie one have reopened for business, following substantial progress made by technical teams over the weekend. At time of publication, he did not have an estimate for when the final branch is expected to reopen.

Salvin stressed that no evidence of compromise to customer accounts have been found, and people’s deposits are safe.

However, in-person services remain limited to receiving direct deposits, withdrawals and deposits, cashing Hilltop-originated checks and receiving limited cash back on non-Hilltop originated check deposits, according to the bank’s update website. The bank created the website last week to share information with customers as it became available.

Salvin also warned that scammers have begun spoofing the bank’s customer service call line, 307-265-2740. He warned customers not to divulge any personal information if they receive a call claiming to be from the bank.

“Hilltop employees cannot and will not make outgoing calls from that number,” he said. “If customers see that number, our advice is not to answer the call.”

The network disruption began Sept. 8 after bank personnel detected IT infrastructure degradation, leading officials to take online banking, mobile applications and phone systems offline early Sept. 9 to isolate the network and protect data. Select bank branches reopened with limited transactions possible on Sept. 10.

On Monday, the Wyoming Bankers Association issued a formal statement in response to public concern, emphasizing that financial institutions work under regulatory safeguards and contingency frameworks meant to protect consumers and financial systems.

In the release, WBA official Scott Meier asked community members to allow the bank the time to complete its technical assessment and find answers.

“Wyoming community banks are part of the communities they serve, and they understand the importance of protecting the people, businesses and relationships that depend on them,” Meier wrote. “Customers deserve care, clarity, and a responsible response.”

On Friday, Salvin told Oil City News that the bank would not disclose the nature of the cybersecurity breach when determined, such as whether it involved malware, phishing or another method.

“In terms of the nature of the breach, that’s just something we’re not going to be able to talk about,” he said.

Salvin on Monday thanked customers for their continued patience.

“We are so grateful for the understanding and support of our customers,” he said. “We’ve had a lot of really kind notes from our customers and that means the world to us.”

The WBA statement can be read below:



——————————————————-


Click Here For The Original Source.