Centennial Bank, including its division Happy State Bank, notified customers that a third-party vendor error resulted in a customer file being sent to the wrong recipient. The bank says it has no indication the information has been misused, and it is offering affected customers complimentary identity monitoring services as a precaution.
Centennial Bank’s Data Breach Investigation
According to the notification letter sent to affected customers, Centennial Bank and Happy State Bank, a division of Centennial Bank, use a third-party service provider called Fidelity Information Services (FIS) to assist with certain banking operations, including customer due diligence processes. On August 7, 2026, an FIS associate preparing a secure email containing a customer file for the bank inadvertently sent the file to an unintended recipient, an employee at another regulated financial institution who happened to share the same first name as the intended recipient at the bank.
On August 10, 2026, the unintended recipient opened the file, realized it did not pertain to their institution, closed it, and promptly notified FIS of the mistake. FIS reported the incident to Centennial Bank on August 17, 2026. Upon learning of the incident, FIS and the bank say they took immediate steps to minimize potential harm: FIS recalled the email, terminated access to the file, and its privacy incident response team opened a formal investigation. FIS also sent a formal deletion request to the unintended recipient, who confirmed the file was deleted on August 14, 2026, and the recipient institution later issued a certificate of destruction on August 26, 2026 confirming no copies were retained, used, or transferred elsewhere.
This incident is a reminder that a bank’s own security controls are only part of the picture when it comes to protecting customer data. Banks routinely rely on third-party vendors like FIS for due diligence, compliance, and back-office processing, which means customer information can pass through systems and staff outside the bank’s direct control. A simple human error, such as sending an email to the wrong person, can expose sensitive financial and identifying information even when the bank’s own network was never compromised and no hacker was involved.
Because the unintended recipient was an employee at another regulated financial institution bound by confidentiality obligations, the practical risk of misuse in this specific case may be lower than in a breach involving an unknown or malicious third party. Even so, the range of information involved, including account numbers, tax identification numbers, and dates of birth, is exactly the kind of data that can enable identity theft or account fraud if it were to end up in the wrong hands, which is why affected customers are still being offered credit monitoring and encouraged to stay vigilant.
Vendor-related incidents like this one also highlight why regulators increasingly expect financial institutions to maintain oversight of the third parties that handle customer data on their behalf. Banks are generally required to conduct due diligence on vendors and monitor their data-handling practices, but even a well-vetted vendor can still make a simple human error, such as sending a file to the wrong recipient. Because the recipient in this case was an employee at another regulated financial institution rather than an unrelated third party, the bank and FIS were able to secure a formal certificate of destruction relatively quickly, which is a materially different outcome than an incident where sensitive data ends up with an unknown party or on the open internet.
The scope of information involved here, spanning identifying details, account data, and tax identification numbers, is broader than what is typically involved in a single stolen-password or phishing-based breach, since it reflects the kind of detailed customer-due-diligence file banks are required to compile and retain for regulatory compliance purposes. This means the practical exposure, if the file had ended up somewhere less secure, could have been more significant than a narrower breach involving only login credentials. Affected customers should weigh the credit monitoring and identity protection features offered here accordingly, rather than assuming a vendor-error incident is automatically lower-risk than a hacking incident.
When Did This Breach Occur?
The misdirected file was sent by an FIS associate on August 7, 2026. The unintended recipient opened the file on August 10, 2026, and notified FIS of the error shortly after. FIS reported the incident to Centennial Bank on August 17, 2026, and the recipient institution confirmed destruction of the file on August 14, 2026, with a formal certificate of destruction issued August 26, 2026.
What Information Was Breached?
The misdirected file may have included full name, mailing address, date of birth, account information (including date opened, account number, balance, transaction type, and status), customer and entity identification numbers, citizenship, tax information (including federal taxpayer ID for some individuals), mailing preference, customer details such as occupation and familial relations, and bank branch details.
What You Can Do
Centennial Bank is offering affected customers a 24-month complimentary membership to identity monitoring services through Epiq Credit Monitoring Solutions. Affected customers should consider the following steps:
- Activate the complimentary Epiq credit monitoring membership using the activation code in your letter
- Regularly review your account statements and free credit reports for unauthorized activity
- Consider placing a fraud alert or security freeze with the three major credit bureaus
- Order a free copy of your credit report annually at annualcreditreport.com
- Contact Centennial Bank’s dedicated response line with any questions about this incident
File a Data Breach Lawsuit Against Centennial Bank
Customers whose personal or financial information may have been exposed in this incident may have legal options worth exploring. An attorney experienced in data breach litigation can help evaluate whether affected customers have grounds to pursue compensation.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.