Were you recently affected by a data breach?

Centennial Bank Data Breach

Centennial Bank, including its division Happy State Bank, notified customers that a third-party service provider, Fidelity Information Services, inadvertently sent a file containing customer information to the wrong recipient. Affected customers are being offered free credit monitoring.

Centennial Bank
Date of Breach: August 7-10, 2026
CAU logo

Who was affected:

Clients of Centennial Bank

Impacted Data:

Full name, mailing address, date of birth, account information, customer and entity identification numbers, citizenship, tax information, mailing preference, customer details, and bank branch details

Centennial Bank, including its division Happy State Bank, notified customers that a third-party vendor error resulted in a customer file being sent to the wrong recipient. The bank says it has no indication the information has been misused, and it is offering affected customers complimentary identity monitoring services as a precaution.

Centennial Bank’s Data Breach Investigation

According to the notification letter sent to affected customers, Centennial Bank and Happy State Bank, a division of Centennial Bank, use a third-party service provider called Fidelity Information Services (FIS) to assist with certain banking operations, including customer due diligence processes. On August 7, 2026, an FIS associate preparing a secure email containing a customer file for the bank inadvertently sent the file to an unintended recipient, an employee at another regulated financial institution who happened to share the same first name as the intended recipient at the bank.

On August 10, 2026, the unintended recipient opened the file, realized it did not pertain to their institution, closed it, and promptly notified FIS of the mistake. FIS reported the incident to Centennial Bank on August 17, 2026. Upon learning of the incident, FIS and the bank say they took immediate steps to minimize potential harm: FIS recalled the email, terminated access to the file, and its privacy incident response team opened a formal investigation. FIS also sent a formal deletion request to the unintended recipient, who confirmed the file was deleted on August 14, 2026, and the recipient institution later issued a certificate of destruction on August 26, 2026 confirming no copies were retained, used, or transferred elsewhere.

This incident is a reminder that a bank’s own security controls are only part of the picture when it comes to protecting customer data. Banks routinely rely on third-party vendors like FIS for due diligence, compliance, and back-office processing, which means customer information can pass through systems and staff outside the bank’s direct control. A simple human error, such as sending an email to the wrong person, can expose sensitive financial and identifying information even when the bank’s own network was never compromised and no hacker was involved.

Because the unintended recipient was an employee at another regulated financial institution bound by confidentiality obligations, the practical risk of misuse in this specific case may be lower than in a breach involving an unknown or malicious third party. Even so, the range of information involved, including account numbers, tax identification numbers, and dates of birth, is exactly the kind of data that can enable identity theft or account fraud if it were to end up in the wrong hands, which is why affected customers are still being offered credit monitoring and encouraged to stay vigilant.

Vendor-related incidents like this one also highlight why regulators increasingly expect financial institutions to maintain oversight of the third parties that handle customer data on their behalf. Banks are generally required to conduct due diligence on vendors and monitor their data-handling practices, but even a well-vetted vendor can still make a simple human error, such as sending a file to the wrong recipient. Because the recipient in this case was an employee at another regulated financial institution rather than an unrelated third party, the bank and FIS were able to secure a formal certificate of destruction relatively quickly, which is a materially different outcome than an incident where sensitive data ends up with an unknown party or on the open internet.

The scope of information involved here, spanning identifying details, account data, and tax identification numbers, is broader than what is typically involved in a single stolen-password or phishing-based breach, since it reflects the kind of detailed customer-due-diligence file banks are required to compile and retain for regulatory compliance purposes. This means the practical exposure, if the file had ended up somewhere less secure, could have been more significant than a narrower breach involving only login credentials. Affected customers should weigh the credit monitoring and identity protection features offered here accordingly, rather than assuming a vendor-error incident is automatically lower-risk than a hacking incident.

When Did This Breach Occur?

The misdirected file was sent by an FIS associate on August 7, 2026. The unintended recipient opened the file on August 10, 2026, and notified FIS of the error shortly after. FIS reported the incident to Centennial Bank on August 17, 2026, and the recipient institution confirmed destruction of the file on August 14, 2026, with a formal certificate of destruction issued August 26, 2026.

What Information Was Breached?

The misdirected file may have included full name, mailing address, date of birth, account information (including date opened, account number, balance, transaction type, and status), customer and entity identification numbers, citizenship, tax information (including federal taxpayer ID for some individuals), mailing preference, customer details such as occupation and familial relations, and bank branch details.

What You Can Do

Centennial Bank is offering affected customers a 24-month complimentary membership to identity monitoring services through Epiq Credit Monitoring Solutions. Affected customers should consider the following steps:

  • Activate the complimentary Epiq credit monitoring membership using the activation code in your letter
  • Regularly review your account statements and free credit reports for unauthorized activity
  • Consider placing a fraud alert or security freeze with the three major credit bureaus
  • Order a free copy of your credit report annually at annualcreditreport.com
  • Contact Centennial Bank’s dedicated response line with any questions about this incident

File a Data Breach Lawsuit Against Centennial Bank

Customers whose personal or financial information may have been exposed in this incident may have legal options worth exploring. An attorney experienced in data breach litigation can help evaluate whether affected customers have grounds to pursue compensation.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: July 20, 2026 (discovered); notification letters mailed August 26, 2026
Date of Breach: Not publicly disclosed
Date of Breach: Not publicly disclosed
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.