
Bakersfield, California-based Mission Bank said that the data security incident it suffered in December compromised the sensitive personal information and bank account numbers of account holders.
In a data security incident notice filed with the Attorney General of California, Mission Bank said that on December 2, it identified unauthorised access to its internal network. The bank immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
The investigation, which concluded on December 18, confirmed that the sensitive personal information of Mission Bank’s customers was accessed during the incident. The compromised data included names, Social Security numbers, dates of birth, addresses, telephone numbers, driver’s license numbers, other state-issued identification numbers, passport numbers, and financial account numbers.
Mission Bank has, however, clarified that its core banking system, account balances and transactions, and mobile and online banking user IDs and passwords were not affected by the incident.
“As a result of this incident, we are reviewing technical safeguards and looking into enhancements to prevent a similar incident,” reads the notice.
While the bank found no evidence of the compromise data being misused, it has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and state attorney general.
It has also offered one year of complimentary identity protection and credit monitoring services through Cyberscout to all affected individuals.
The infamous RansomHub ransomware group recently claimed responsibility for the ransomware attack on Mission Bank and listed it as a victim on its data leak site. The group claimed to be in possession of 2.7 TB data stolen from the organisation.
The group claims that it gave Mission Bank a period of eight days to pay a ransom, threatening to leak the stolen data if the ransom isn’t paid. It is unclear if the company negotiated with the ransomware group or paid a ransom.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543