Ransomware exposure for financial-services firms operating in California, United States, across the supplier chain, the state's privacy and breach-notification regime and federal reporting and sanctions duties, assessed as at 3 September 2026.
The standard defence against ransomware is to harden your own network and buy a cyber-insurance policy to carry what gets through. For a financial firm in California, both halves of that plan are quietly failing, and not because the firm did anything wrong.
The attack rarely comes through the front door any more. It comes through a software vendor, a file-transfer tool or a phone call to the help desk, and it steals customer data before it encrypts anything, which turns every incident into a mandatory-disclosure event. A firm can hold strong internal controls and still be taken offline by a supplier it never audited.
And the ransom, when it comes, is rarely the biggest number. Behind it sits California's newly compressed disclosure clock, the most aggressive privacy regulator in the country, a hardening insurance market that increasingly declines to pay, and a payment decision that can itself break federal sanctions law.
So the useful question is not whether the firewall holds. It is whether the firm can see the suppliers that will actually let the attacker in, prove to an insurer that its controls were running on the day, and survive a legal cascade that moves faster than its own forensics. This is the anatomy of that exposure, and why the ransom is the cheapest part.
Five ways it bites, ranked by how badly
1. The supplier you never audited. The dominant route in. A single ransomware attack on the financial-software vendor Marquis in August 2025 reached more than 74 US banks and credit unions, with filings later putting the exposed population between 672,000 and 1.35 million people. The customer institution, not the vendor, carries the notification bill, and a third-party risk service had flagged that vendor a month before the attack.
2. The regulator as a second front. The largest cost, and it runs in parallel with the recovery. Since 1 January 2026, California requires notice to residents within 30 days of discovery, and to the Attorney General within 15 days where 500 or more are affected. Its privacy regulator is mid-enforcement blitz, the record state settlement is $12.75 million, and over 90 per cent of breach enforcement is multistate.
3. The backstop that may not pay. Cyber premiums are rising 15 to 20 per cent in 2026, financial services already priced around half above the market, and roughly 21 per cent of claims were denied in 2025, most often for a security control the firm attested to but could not prove it ran. A nation-state attribution exclusion lets a carrier decline a claim outright.
4. The help desk. The cheapest attacker effort defeats the most expensive control. Groups such as Scattered Spider phone the IT service desk, impersonate staff and talk an agent into resetting credentials and multi-factor devices. The weakest link is a stressed help-desk agent, not a technical gap.
5. Paying can be the second crime. The ransom decision is a compliance event. A payment to a sanctioned group can breach US sanctions on a strict-liability basis, with any licence to pay reviewed under a presumption of denial, and the payment itself triggers suspicious-activity reporting. Several of the most common variants raise exactly this exposure.
Buy the full report
Cyber-security
How Exposed Am I to Ransomware?
54 pages
- Country
- United States
- State
- California
- Industry
- Financial Services
This published copyUSD 49
Order this reportThe attack comes in through someone else
The single most common way a California bank, credit union or wealth manager is hit in 2026 is not through its own perimeter but through a supplier. Smaller institutions in particular outsource core processing, statements, insurance products and file transfer, and inherit the security posture of firms they do not control. Regulated finance is attacked not despite its defences but through the third parties it depends on and cannot fully see.
The Marquis case is the clearest illustration. In August 2025 the core financial-software provider was compromised by Akira ransomware through an unpatched firewall, and the fallout eventually touched more than 74 US banks and credit unions, with regulatory filings estimating between 672,000 and 1.35 million people affected. A third-party risk-rating service had flagged the vendor's susceptibility about a month before the attack, so the warning existed and went unactioned. The same pattern recurred through the Cleo file-transfer zero-day that reached Western Alliance Bank, disclosed via a securities filing, and again in July 2026 when the insurance-products supplier TruStage was taken offline, disrupting claims across credit unions nationally.
A specific and repeated flavour of this is the managed file-transfer tool, the software financial firms use to move statements, loan tapes and payment files. These sit at the seams between organisations, hold bulk sensitive data and are often patched more slowly than customer-facing systems, which is exactly why extortion crews hunt them. The practical consequence is that a California institution can suffer a reportable breach, a member-notification bill and reputational damage without its own systems ever being touched.
Note. The sector's dominant loss pattern in one picture. One supplier compromise reaches far more people than a direct hit on a single institution, and the customer institution, not the vendor, carries the notification bill.
The regulator is the second front
What makes California exposure distinct is that a breach invites a second enforcement track, independent of the attack itself, and it now moves faster than the forensic investigation. Since 1 January 2026 an amended statute requires notice to affected residents within 30 calendar days of discovering a breach, replacing the old open-ended standard, with notice to the Attorney General due within 15 days where 500 or more residents are affected. Forensic scoping, working out which stolen files held whose personal data, routinely takes longer than 30 days, yet the clock starts at discovery.
Behind the clock sits an active enforcer. California's privacy regulator issued more than $4.22 million in penalties in the first quarter of 2026 alone, and the largest such settlement in state history, $12.75 million, followed in May. The penalty design rewards prior investment and punishes its absence: a firm that maintained reasonable safeguards can raise an affirmative defence, while one that did not faces civil penalties of up to $150,000 per breach on top of per-consumer penalties that scale with the record count. New rules also require an annual independent cybersecurity audit, certified by named executives under penalty of perjury, which pushes the exposure out of the IT function and onto people.
California also rarely acts alone. A review of more than 220 breach enforcement matters found over 90 per cent were pursued as multistate actions, which is why a single credit-union breach in the state generated disclosures to five states at once. A California financial firm should assume any material breach draws a coordinated, multi-regulator response, not a single inquiry, and that federal financial supervisors and, for public issuers, securities regulators open their own files on the same event.
| Front | The clock or exposure | Source |
|---|---|---|
| California residents | Notify within 30 days of discovery | SB 446 |
| California Attorney General | Notify within 15 days if 500+ affected | SB 446 |
| Federal regulator (credit unions) | Notify within 72 hours | NCUA |
| State civil penalty | Up to $150,000 per breach, plus $2,663 per consumer | CCPA / SB 446 |
| Consumer class action | Statutory damages, no proof of loss required | CCPA private right |
| The insurer | Denial rate around 21 per cent; nation-state exclusion | Cyber market, 2025 to 2026 |
| The ransom | Sanctions presumption of denial; suspicious-activity report | OFAC / FinCEN |
Note. The ransom is one line, and rarely the largest. A single California breach opens several files at once, on clocks that run in days.
The backstop that may not pay
The risk-transfer safety net is thinner than many boards assume. After two years of softening, cyber premiums are rising again in 2026, forecast up 15 to 20 per cent, with financial services already priced around 50 per cent above the market average. More importantly, the policy is no longer a reliable backstop; it is a contract with conditions the firm must be able to prove it met.
Denials are rising in parallel, reaching roughly 21 per cent of cyber claims in 2025, and they cluster around a short list: a security control the policyholder attested to but did not maintain, most often enforced multi-factor authentication; unpatched systems; undisclosed pre-existing vulnerabilities; and ransomware sub-limits set well below a plausible demand. The sharpest edge is the nation-state attribution exclusion, which lets a carrier decline a ransomware claim attributed to a state-sponsored group on objectively reasonable evidence. Because finance is a frequent state target, an attack can convert a covered loss into an uncovered one on the strength of an attribution the firm cannot contest.
The warning signs are visible at renewal, long before any claim: application answers that overstate the real security posture, broad exclusions with a low evidentiary bar, sub-limits below plausible extortion demands, and legacy remote access that underwriters increasingly reject outright. In California's premium-priced market the protection is only as good as the controls the firm can evidence it operated on the day.
The help desk, and the trap in paying
The most damaging intrusions of 2025 and 2026 began with a phone call or an email, not a technical exploit. The group tracked as Scattered Spider, the subject of an updated federal advisory issued jointly with allied agencies, has made social engineering the point of entry: it phones the IT service desk, impersonates a locked-out employee, and talks the agent into resetting credentials and enrolling a new multi-factor device, defeating an otherwise strong control at the one point where a human can override it. The advisory names financial services as a sector vital to national security. The clearest in-state precedent, a 2024 attack on a roughly $9 billion California credit union that forced banking systems offline and affected 726,000 people, was traced to a phishing email against what commentators called a soft target.
When systems are down and backups are missing or unverified, the board faces the ransom decision, and it is a legal problem disguised as an operational one. Facilitating a payment to a sanctioned group can breach US sanctions on a strict-liability basis, and the Treasury reviews any licence to make such a payment under a presumption of denial where a sanctions nexus exists. Several of the most prolific variants carry exactly that attribution. Separately, a financial institution that makes or facilitates a payment owes suspicious-activity reporting under the Bank Secrecy Act. A rushed payment can therefore layer a second violation on top of the breach, while prompt reporting to law enforcement is treated as a mitigating factor.
Both pressure points are cheap to close and expensive to ignore. Help-desk identity verification that cannot be talked around, phishing-resistant multi-factor authentication, and a ransom-payment policy agreed by the board in advance, with sanctions screening in the payment path and restore-tested backups that keep a do-not-pay option open, are the controls that separate a contained response from a compounding one.
Note. The size of a typical extortion transaction rose then plateaued. The number to watch is not this one; it is the notification, penalty and insurance stack it sets off.
Exposure you pull down with evidence, not intention
Put the pieces together and the verdict is uncomfortable but actionable. Exposure for a California financial firm is high by default, and it can only be lowered through evidence, not good intentions. Three things decide where within that band a firm sits, and a board can inspect each of them now: whether it maps, monitors and contractually binds the suppliers that have become the primary breach route; whether it can actually meet a 30-day resident deadline and a 72-hour regulator deadline, having rehearsed the decisions rather than discovering them mid-incident; and whether it can prove, at claim time, that it met the security conditions its policy requires.
The reason those three matter so much is that they are the same list. In California the annual cybersecurity audit covers access controls, multi-factor authentication and backup integrity, which maps almost exactly onto the vectors attackers exploit. So a firm that fails the audit standard is also the firm most likely to be breached and least likely to be insured. The same control gaps drive the attack, the regulatory penalty and the insurance denial at once, which is why closing them pays three times over.
The wider lesson travels well beyond banking and beyond California. In any business that runs on suppliers and buys insurance against the worst day, the exposure is set by what you can prove, not by what you intended, and the largest cost is rarely the headline event. So it is worth asking, before an incident rather than during one: which supplier could take you offline tomorrow, could you prove your controls were running if an insurer asked, and does anyone own the first hour before the clock starts?
Figures drawn from TheRiskAgent's cyber ransomware risk briefing on financial services in California (September 2026): FinCEN Bank Secrecy Act analysis, SEC filings, CISA and FBI advisories, California Privacy Protection Agency and NCUA material. Produced with AI research tools and reviewed before release. Reference material, not advice. The full analysis is at theriskagent.com.

