Cyber-security

The ransom is the cheapest part

In California financial services, the ransom is rarely the biggest cost, and your own perimeter is rarely the way in. The exposure runs through your suppliers.

TheRiskAgent18 September 202610 min read

Ransomware exposure for financial-services firms operating in California, United States, across the supplier chain, the state's privacy and breach-notification regime and federal reporting and sanctions duties, assessed as at 3 September 2026.

The standard defence against ransomware is to harden your own network and buy a cyber-insurance policy to carry what gets through. For a financial firm in California, both halves of that plan are quietly failing, and not because the firm did anything wrong.

The attack rarely comes through the front door any more. It comes through a software vendor, a file-transfer tool or a phone call to the help desk, and it steals customer data before it encrypts anything, which turns every incident into a mandatory-disclosure event. A firm can hold strong internal controls and still be taken offline by a supplier it never audited.

And the ransom, when it comes, is rarely the biggest number. Behind it sits California's newly compressed disclosure clock, the most aggressive privacy regulator in the country, a hardening insurance market that increasingly declines to pay, and a payment decision that can itself break federal sanctions law.

So the useful question is not whether the firewall holds. It is whether the firm can see the suppliers that will actually let the attacker in, prove to an insurer that its controls were running on the day, and survive a legal cascade that moves faster than its own forensics. This is the anatomy of that exposure, and why the ransom is the cheapest part.

Five ways it bites, ranked by how badly

1. The supplier you never audited. The dominant route in. A single ransomware attack on the financial-software vendor Marquis in August 2025 reached more than 74 US banks and credit unions, with filings later putting the exposed population between 672,000 and 1.35 million people. The customer institution, not the vendor, carries the notification bill, and a third-party risk service had flagged that vendor a month before the attack.

2. The regulator as a second front. The largest cost, and it runs in parallel with the recovery. Since 1 January 2026, California requires notice to residents within 30 days of discovery, and to the Attorney General within 15 days where 500 or more are affected. Its privacy regulator is mid-enforcement blitz, the record state settlement is $12.75 million, and over 90 per cent of breach enforcement is multistate.

3. The backstop that may not pay. Cyber premiums are rising 15 to 20 per cent in 2026, financial services already priced around half above the market, and roughly 21 per cent of claims were denied in 2025, most often for a security control the firm attested to but could not prove it ran. A nation-state attribution exclusion lets a carrier decline a claim outright.

4. The help desk. The cheapest attacker effort defeats the most expensive control. Groups such as Scattered Spider phone the IT service desk, impersonate staff and talk an agent into resetting credentials and multi-factor devices. The weakest link is a stressed help-desk agent, not a technical gap.

5. Paying can be the second crime. The ransom decision is a compliance event. A payment to a sanctioned group can breach US sanctions on a strict-liability basis, with any licence to pay reviewed under a presumption of denial, and the payment itself triggers suspicious-activity reporting. Several of the most common variants raise exactly this exposure.

Buy the full report

Cyber-security

How Exposed Am I to Ransomware?

54 pages

Country
United States
State
California
Industry
Financial Services

This published copyUSD 49

Order this report

The attack comes in through someone else

The single most common way a California bank, credit union or wealth manager is hit in 2026 is not through its own perimeter but through a supplier. Smaller institutions in particular outsource core processing, statements, insurance products and file transfer, and inherit the security posture of firms they do not control. Regulated finance is attacked not despite its defences but through the third parties it depends on and cannot fully see.

The Marquis case is the clearest illustration. In August 2025 the core financial-software provider was compromised by Akira ransomware through an unpatched firewall, and the fallout eventually touched more than 74 US banks and credit unions, with regulatory filings estimating between 672,000 and 1.35 million people affected. A third-party risk-rating service had flagged the vendor's susceptibility about a month before the attack, so the warning existed and went unactioned. The same pattern recurred through the Cleo file-transfer zero-day that reached Western Alliance Bank, disclosed via a securities filing, and again in July 2026 when the insurance-products supplier TruStage was taken offline, disrupting claims across credit unions nationally.

A specific and repeated flavour of this is the managed file-transfer tool, the software financial firms use to move statements, loan tapes and payment files. These sit at the seams between organisations, hold bulk sensitive data and are often patched more slowly than customer-facing systems, which is exactly why extortion crews hunt them. The practical consequence is that a California institution can suffer a reportable breach, a member-notification bill and reputational damage without its own systems ever being touched.

People affected by recent incidents touching US financial firms Marquis software vendor (Akira, upper est.) 1,350,000 people Patelco Credit Union (RansomHub) 726,000 people Western Alliance (Cleo / Clop) 21,899 people
Source: SEC filings; BleepingComputer; The Record, 2025 to 2026.

Note. The sector's dominant loss pattern in one picture. One supplier compromise reaches far more people than a direct hit on a single institution, and the customer institution, not the vendor, carries the notification bill.

The regulator is the second front

What makes California exposure distinct is that a breach invites a second enforcement track, independent of the attack itself, and it now moves faster than the forensic investigation. Since 1 January 2026 an amended statute requires notice to affected residents within 30 calendar days of discovering a breach, replacing the old open-ended standard, with notice to the Attorney General due within 15 days where 500 or more residents are affected. Forensic scoping, working out which stolen files held whose personal data, routinely takes longer than 30 days, yet the clock starts at discovery.

Behind the clock sits an active enforcer. California's privacy regulator issued more than $4.22 million in penalties in the first quarter of 2026 alone, and the largest such settlement in state history, $12.75 million, followed in May. The penalty design rewards prior investment and punishes its absence: a firm that maintained reasonable safeguards can raise an affirmative defence, while one that did not faces civil penalties of up to $150,000 per breach on top of per-consumer penalties that scale with the record count. New rules also require an annual independent cybersecurity audit, certified by named executives under penalty of perjury, which pushes the exposure out of the IT function and onto people.

California also rarely acts alone. A review of more than 220 breach enforcement matters found over 90 per cent were pursued as multistate actions, which is why a single credit-union breach in the state generated disclosures to five states at once. A California financial firm should assume any material breach draws a coordinated, multi-regulator response, not a single inquiry, and that federal financial supervisors and, for public issuers, securities regulators open their own files on the same event.

What a single California breach sets running, in parallel
FrontThe clock or exposureSource
California residentsNotify within 30 days of discoverySB 446
California Attorney GeneralNotify within 15 days if 500+ affectedSB 446
Federal regulator (credit unions)Notify within 72 hoursNCUA
State civil penaltyUp to $150,000 per breach, plus $2,663 per consumerCCPA / SB 446
Consumer class actionStatutory damages, no proof of loss requiredCCPA private right
The insurerDenial rate around 21 per cent; nation-state exclusionCyber market, 2025 to 2026
The ransomSanctions presumption of denial; suspicious-activity reportOFAC / FinCEN
Source: California SB 446 and CCPA; NCUA; OFAC and FinCEN guidance; cyber-insurance market data, 2026.

Note. The ransom is one line, and rarely the largest. A single California breach opens several files at once, on clocks that run in days.

The backstop that may not pay

The risk-transfer safety net is thinner than many boards assume. After two years of softening, cyber premiums are rising again in 2026, forecast up 15 to 20 per cent, with financial services already priced around 50 per cent above the market average. More importantly, the policy is no longer a reliable backstop; it is a contract with conditions the firm must be able to prove it met.

Denials are rising in parallel, reaching roughly 21 per cent of cyber claims in 2025, and they cluster around a short list: a security control the policyholder attested to but did not maintain, most often enforced multi-factor authentication; unpatched systems; undisclosed pre-existing vulnerabilities; and ransomware sub-limits set well below a plausible demand. The sharpest edge is the nation-state attribution exclusion, which lets a carrier decline a ransomware claim attributed to a state-sponsored group on objectively reasonable evidence. Because finance is a frequent state target, an attack can convert a covered loss into an uncovered one on the strength of an attribution the firm cannot contest.

The warning signs are visible at renewal, long before any claim: application answers that overstate the real security posture, broad exclusions with a low evidentiary bar, sub-limits below plausible extortion demands, and legacy remote access that underwriters increasingly reject outright. In California's premium-priced market the protection is only as good as the controls the firm can evidence it operated on the day.

The help desk, and the trap in paying

The most damaging intrusions of 2025 and 2026 began with a phone call or an email, not a technical exploit. The group tracked as Scattered Spider, the subject of an updated federal advisory issued jointly with allied agencies, has made social engineering the point of entry: it phones the IT service desk, impersonates a locked-out employee, and talks the agent into resetting credentials and enrolling a new multi-factor device, defeating an otherwise strong control at the one point where a human can override it. The advisory names financial services as a sector vital to national security. The clearest in-state precedent, a 2024 attack on a roughly $9 billion California credit union that forced banking systems offline and affected 726,000 people, was traced to a phishing email against what commentators called a soft target.

When systems are down and backups are missing or unverified, the board faces the ransom decision, and it is a legal problem disguised as an operational one. Facilitating a payment to a sanctioned group can breach US sanctions on a strict-liability basis, and the Treasury reviews any licence to make such a payment under a presumption of denial where a sanctions nexus exists. Several of the most prolific variants carry exactly that attribution. Separately, a financial institution that makes or facilitates a payment owes suspicious-activity reporting under the Bank Secrecy Act. A rushed payment can therefore layer a second violation on top of the breach, while prompt reporting to law enforcement is treated as a mitigating factor.

Both pressure points are cheap to close and expensive to ignore. Help-desk identity verification that cannot be talked around, phishing-resistant multi-factor authentication, and a ransom-payment policy agreed by the board in advance, with sanctions screening in the payment path and restore-tested backups that keep a do-not-pay option open, are the controls that separate a contained response from a compounding one.

Median single ransomware-related transaction, US financial system, $000s 2023 175 2024 155 2022 124
Source: FinCEN Bank Secrecy Act analysis.

Note. The size of a typical extortion transaction rose then plateaued. The number to watch is not this one; it is the notification, penalty and insurance stack it sets off.

Exposure you pull down with evidence, not intention

Put the pieces together and the verdict is uncomfortable but actionable. Exposure for a California financial firm is high by default, and it can only be lowered through evidence, not good intentions. Three things decide where within that band a firm sits, and a board can inspect each of them now: whether it maps, monitors and contractually binds the suppliers that have become the primary breach route; whether it can actually meet a 30-day resident deadline and a 72-hour regulator deadline, having rehearsed the decisions rather than discovering them mid-incident; and whether it can prove, at claim time, that it met the security conditions its policy requires.

The reason those three matter so much is that they are the same list. In California the annual cybersecurity audit covers access controls, multi-factor authentication and backup integrity, which maps almost exactly onto the vectors attackers exploit. So a firm that fails the audit standard is also the firm most likely to be breached and least likely to be insured. The same control gaps drive the attack, the regulatory penalty and the insurance denial at once, which is why closing them pays three times over.

The wider lesson travels well beyond banking and beyond California. In any business that runs on suppliers and buys insurance against the worst day, the exposure is set by what you can prove, not by what you intended, and the largest cost is rarely the headline event. So it is worth asking, before an incident rather than during one: which supplier could take you offline tomorrow, could you prove your controls were running if an insurer asked, and does anyone own the first hour before the clock starts?

Figures drawn from TheRiskAgent's cyber ransomware risk briefing on financial services in California (September 2026): FinCEN Bank Secrecy Act analysis, SEC filings, CISA and FBI advisories, California Privacy Protection Agency and NCUA material. Produced with AI research tools and reviewed before release. Reference material, not advice. The full analysis is at theriskagent.com.

Create your own Risk report

Pick a report type, configure it to your situation, and receive a fully sourced briefing. Research, not advice.

Pick the specific risk question you want a report on.

The following fields are optional. Providing them produces a more tailored report. Leave as "No preference" for a general report.

Your report download link will be sent to this email.

Secure payment via StripeDelivered within 40 minutes to 4 hours

Your career is a risk position

byAxeRocket

Career and job-loss risk is researched by AxeRocket, TheRiskAgent's sister platform. The Client Report is a complete executive-grade strategic dossier, built from your own answers and delivered to your inbox.

  • Up to 65 adaptive questions an intelligent intake that branches around your answers.
  • 122 industries, 1,258 sub-sectors we pinpoint exactly where you sit, never a vague category.
  • 41 professions, 351 specific roles your actual job title, not a job family.
  • Every country and jurisdiction, 470 states and regions intelligence local to where you are, or where you are headed next.
  • 36 specialist AI agents each section written by a purpose-built model, not one generic prompt.

Your Report: 8 parts, up to 29 sections, 50 to 70 pages

  1. 1Understanding Your Situation
  2. 2Global Industry Intelligence
  3. 3Global Profession Intelligence
  4. 4AI and the Future of Work
  5. 5Career Risk Assessment
  6. 6Strategic Career Options
  7. 7Personal Action Plan
  8. 8Local Resources and Support

Every claim fully referenced, with the source URLs provided.

USD 49

One-time, sold by AxeRocket. Includes 12 months of Client Zone access.

Generate your Client ReportHow the Client Report works

This link opens AxeRocket. Research, not advice.

#ransomware#cyber-security#financial services#California#third-party risk#data breach#cyber insurance#privacy enforcement
More TRA Insights

Insights are short summaries that introduce a paid research asset. They are not a substitute for the underlying report. Always consult a qualified adviser before acting on contents.