Ransomware exposure for financial-services firms operating in California, United States, across the supplier chain, the state's privacy and breach-notification regime and federal reporting and sanctions duties, assessed as at 3 September 2026.
The standard defence against ransomware is to harden the firm's own network and buy a cyber-insurance policy to carry what gets through. For a financial firm in California, both halves of that plan have gaps, and not because the firm did anything wrong.
The attack rarely comes through the front door any more. It comes through a software vendor, a file-transfer tool or a phone call to the help desk, and it steals customer data before it encrypts anything, which turns every incident into a mandatory-disclosure event. A firm can hold strong internal controls and still be taken offline by a supplier it never audited.
And the ransom, when it comes, is rarely the biggest number. Behind it sits California's newly compressed disclosure clock, an active privacy enforcement regime, an insurance policy that pays only if the firm can prove its controls ran, and a payment decision that can itself break federal sanctions law.
So the useful question is not whether the firewall holds. It is whether the firm can see the suppliers that will actually let the attacker in, prove to an insurer that its controls were running on the day, and survive a legal cascade that moves faster than its own forensics. This is the anatomy of that exposure, and why the ransom is the cheapest part.
Five ways it bites, ranked by how badly
1. The supplier nobody audited. The recurring route in. A ransomware attack on Marquis, a marketing and communications vendor to banks and credit unions, detected in August 2025, reached files holding personal information from at least 25 of its bank and credit-union customers, according to its notice to the Iowa Attorney General. The customer institution, not the vendor, carries the notification bill.
2. The regulator as a second front. The largest cost, and it runs in parallel with the recovery. Since 1 January 2026, California requires notice to residents within 30 days of discovery (Cal. Civ. Code §1798.82), with a sample of that notice due to the Attorney General within 15 calendar days of notifying residents, where more than 500 California residents are affected. Civil penalties run up to $2,663 per violation, or $7,988 per intentional violation.
3. The backstop that may not pay. A cyber policy is a contract with conditions the firm must prove it met. Claims are most often contested over a security control the firm attested to but could not prove it ran, and a nation-state attribution exclusion can let a carrier decline a claim outright.
4. The help desk. The cheapest attacker effort defeats the most expensive control. Groups such as Scattered Spider phone the IT service desk, impersonate staff and talk an agent into resetting credentials and multi-factor devices. The intrusion succeeds at the point where a person can override a technical control.
5. Paying can be the second crime. The ransom decision is a compliance event. A payment to a sanctioned group can breach US sanctions on a strict-liability basis, with any licence to pay reviewed under a presumption of denial, and the payment itself triggers suspicious-activity reporting. Several of the most common variants raise exactly this exposure.
Buy the full report
Cyber-security
How Exposed Am I to Ransomware?
54 pages
- Country
- United States
- State
- California
- Industry
- Financial Services
Built to orderUSD 49
Order this reportThe attack comes in through someone else
Supplier compromise recurs across the incidents below. Smaller institutions in particular outsource core processing, statements, insurance products and file transfer, and inherit the security posture of firms they do not control.
In August 2025 Marquis, a marketing and communications vendor to banks and credit unions, reported a ransomware attack in which files holding personal information received from its bank and credit-union customers may have been acquired, according to its notice to the Iowa Attorney General. That notice put the institutions affected at no fewer than 25. The same pattern recurred when a third-party vendor's file-transfer software exposed data held by Western Alliance Bank, and again when the insurance-products supplier TruStage took its network offline on 11 July 2026 after identifying a cybersecurity issue.
A specific and repeated flavour of this is the managed file-transfer tool, the software financial firms use to move statements, loan tapes and payment files. These sit at the seams between organisations, hold bulk sensitive data and are often patched more slowly than customer-facing systems. The practical consequence is that a California institution can suffer a reportable breach, a member-notification bill and reputational damage without its own systems ever being touched.
The regulator is the second front
What makes California exposure distinct is that a breach invites a second enforcement track, independent of the attack itself, and it now moves faster than the forensic investigation. Since 1 January 2026 an amended statute (Cal. Civ. Code §1798.82) requires notice to affected residents within 30 calendar days of discovering a breach, replacing the old open-ended standard, with a sample of that notice due to the Attorney General within 15 calendar days of notifying residents, where more than 500 California residents are affected. Forensic scoping, working out which stolen files held whose personal data, routinely takes longer than 30 days, yet the clock starts at discovery.
Behind the clock sits an active enforcement regime. In May 2026 the Attorney General, with district attorneys and the California Privacy Protection Agency, announced a $12.75 million penalty, the largest under the CCPA to date, in a case about the sale of consumer data rather than a breach. The penalty design rewards prior investment and punishes its absence: the consumer damages claim applies only where the breach resulted from a failure to maintain reasonable security, so a firm that maintained it stands outside that claim, while one that did not faces civil penalties of up to $2,663 per violation, or $7,988 per intentional violation, and, for a breach caused by a failure to maintain reasonable security, consumer statutory damages of $107 to $799 per consumer per incident. New rules also require an annual independent cybersecurity audit, certified by a member of executive management under penalty of perjury, which pushes the exposure out of the IT function and onto people. The audit regime phases in, with the first certifications due from 2028.
Material breaches typically draw coordinated, multi-regulator responses, and federal supervisors and, for public issuers, the SEC can open their own files on the same event. For a federally insured credit union, the NCUA requires notice of a reportable cyber incident within 72 hours (12 CFR 748.1(c)).
| Front | The clock or exposure | Source |
|---|---|---|
| California residents | Notify within 30 calendar days of discovery | Cal. Civ. Code §1798.82 |
| California Attorney General | Submit sample notice within 15 days of resident notice if more than 500 affected | Cal. Civ. Code §1798.82 |
| Federal regulator (credit unions) | Notify within 72 hours | 12 CFR 748.1(c) |
| State civil penalty | Up to $2,663 per violation, $7,988 per intentional violation (CCPA §1798.155, §1798.199.90) | CCPA; CPPA CPI adjustment |
| Consumer class action | $107 to $799 per consumer per incident, or actual damages if greater (CCPA §1798.150) | CCPA §1798.150 |
| The ransom | Sanctions presumption of denial; suspicious-activity report | OFAC advisory; FinCEN |
Note. The ransom is one line, and rarely the largest. A single California breach opens several files at once, on clocks that run in days. Data covered by the federal Gramm-Leach-Bliley Act is exempt from the CCPA except for the consumer damages claim under §1798.150 (§1798.145(e)), so for many financial firms the class-action row applies even where the penalty rows do not.
The backstop that may not pay
The risk-transfer safety net is thinner than many boards assume. The policy is not an unconditional backstop; it is a contract with conditions the firm must be able to prove it met.
Denials cluster around a short list: a security control the policyholder attested to but did not maintain, most often enforced multi-factor authentication; unpatched systems; undisclosed pre-existing vulnerabilities; and ransomware sub-limits set well below a plausible demand. A nation-state attribution exclusion can let a carrier decline a ransomware claim attributed to a state-sponsored group. Because finance is a frequent state target, an attack can convert a covered loss into an uncovered one on the strength of an attribution the firm cannot contest.
The warning signs are visible at renewal, long before any claim: application answers that overstate the real security posture, broad exclusions with a low evidentiary bar, sub-limits below plausible extortion demands, and legacy remote access that underwriters increasingly reject outright. The protection is only as good as the controls the firm can evidence it operated on the day.
The help desk, and the trap in paying
The most damaging intrusions of 2025 and 2026 began with a phone call or an email, not a technical exploit. The group tracked as Scattered Spider, the subject of a federal advisory issued jointly with allied agencies and revised in July 2025 (CISA AA23-320A), has made social engineering the point of entry: it phones the IT service desk, impersonates a locked-out employee, and talks the agent into resetting credentials and enrolling a new multi-factor device, defeating an otherwise strong control at the one point where a human can override it. The advisory describes the group as targeting large companies and their contracted IT help desks. Closer to home, in 2024 a ransomware attack on Patelco Credit Union took banking services offline.
When systems are down and backups are missing or unverified, the board faces the ransom decision. Facilitating a payment to a sanctioned group can breach US sanctions on a strict-liability basis, and the Treasury's Office of Foreign Assets Control reviews any licence to make such a payment under a presumption of denial where a sanctions nexus exists. Several of the most prolific variants carry exactly that attribution. Separately, a financial institution that makes or facilitates a payment owes suspicious-activity reporting under the Bank Secrecy Act (FinCEN advisory FIN-2021-A004). A rushed payment can therefore layer a second violation on top of the breach, while prompt reporting to law enforcement counts as voluntary self-disclosure and a significant mitigating factor in OFAC's enforcement response.
The controls at issue are help-desk identity verification, phishing-resistant multi-factor authentication, a board-approved ransom-payment policy with sanctions screening, and restore-tested backups.
Note. The size of a typical extortion transaction rose in 2023 and eased in 2024. The number to watch is not this one; it is the notification, penalty and insurance stack it sets off.
Exposure falls with evidence, not intention
Exposure for a California financial firm is high by default, and it falls only with evidence, not good intentions. Three factors set where a firm sits within that exposure: whether it maps, monitors and contractually binds the suppliers that have become the primary breach route; whether it can actually meet a 30-day resident deadline and a 72-hour regulator deadline, having rehearsed the decisions rather than discovering them mid-incident; and whether it can prove, at claim time, that it met the security conditions its policy requires.
Those three matter so much because they are the same list. In California the annual cybersecurity audit, once phased in, covers access controls, multi-factor authentication and backup integrity, which maps almost exactly onto the vectors attackers exploit. So a firm that fails the audit standard is also the firm most likely to be breached and least likely to be insured. The same control gaps drive the attack, the regulatory penalty and the insurance denial at once.
The wider lesson travels well beyond banking and beyond California. In any business that runs on suppliers and buys insurance against the worst day, the exposure is set by what a firm can prove, not by what it intended, and the largest cost is rarely the headline event. The open questions are which supplier could take a firm offline, whether it can prove its controls were running when an insurer asks, and who owns the first hour of an incident.
Drawn from TheRiskAgent's cyber ransomware risk briefing on financial services in California (September 2026). Figures checked against the issuing official sources in October 2026: FinCEN, the US Treasury's Office of Foreign Assets Control, CISA, the NCUA, the California Attorney General, the California Privacy Protection Agency and breach notices filed with state attorneys general. Reference material, not advice. The full analysis is at theriskagent.com.

