A cyberattack had already kept Hilltop National Bank’s customers locked out of online banking for a full week by the time the outage made national news, and the disruption ran considerably longer before every system came back. The Casper, Wyoming, bank first noticed its systems degrading on September 8, 2026, and confirmed overnight that it was dealing with a cybersecurity incident rather than a routine technical failure; a week later, with online banking, mobile banking and the bank’s website all still dark, the $1.14 billion institution capped debit withdrawals at $1,000 a day while it worked through the damage.
Hilltop operates eight offices across Wyoming and held roughly $987.6 million in deposits at the time of the attack. For that entire first week, its full customer base had no way to bank online at all, forced instead into branch visits and a debit-card ceiling that made anything beyond routine spending impossible — and the outage did not fully end there.
A midnight discovery turned into a branch-by-branch shutdown
American Banker’s original report, published exactly a week after the attack began, captured Hilltop still locked out of every digital channel: online banking, mobile banking and the bank’s public website had all stayed down since a cybersecurity incident was confirmed overnight heading into September 9, and scheduled bill payments were halted because the systems needed to process them were offline along with everything else. Phone service was the one exception, restored on September 10.
Hilltop National Bank chief executive Darren Cantlay described the restoration process as “specific and detailed work that takes time,” a characterization the bank’s own timeline bears out: five branches reopened with limited services on September 10, every ATM location came back online by September 14, and it took until September 19 for management to announce a target date for restoring online banking at all.
A $1,000 daily cap stood in for normal banking
Throughout the outage, customers could still use debit cards, but only up to $1,000 per day across every location and ATM the bank operates. Hilltop’s own incident-updates site shows personal mobile banking did not return until September 21, personal online banking followed on September 22, and business banking services caught up two days after that, on September 24 — sixteen days after the attack began.
The bank said it would reimburse customers for late fees or penalties tied to missed or delayed payments caused by the outage, and it repeatedly stressed that account balances were untouched throughout. No customer funds were reported lost, and Hilltop said there was no evidence the intrusion had altered any account balance.
The outage reached beyond individual account holders. The nearby town of Bar Nunn, which banks with Hilltop, could not get its Friday payroll processed through the frozen systems, forcing town officials to scramble for a workaround days into the shutdown. Bank spokesman Bill Salvin told local reporters the bank could still issue paper payroll checks even with its systems down, noting employees “can deposit them or they can cash them” once a check was in hand — a manual fallback for a problem the bank’s own digital infrastructure could not solve that week.
A bank that has nearly tripled in size since its last exam
Hilltop’s growth over the past several years gives the outage more weight than a single bad week for a small-town lender. An Office of the Comptroller of the Currency evaluation from 2021 put the bank’s total assets at roughly $778 million as of December 2019, spread across five branches, four of them in Casper and one in nearby Glenrock. By the time of the September 2026 attack, the bank had grown to $1.14 billion in assets and eight offices, expansion that also means a cyber incident now reaches a customer base substantially larger than the one regulators evaluated five years earlier.
Federal rules gave the bank 36 hours to notify regulators
Banks in Hilltop’s position operate under a specific federal clock. A joint rule from the FDIC, the Federal Reserve and the OCC requires banking organizations to notify their federal regulator “as soon as possible and no later than 36 hours” after determining that an incident has materially disrupted their ability to deliver banking products and services to a material portion of customers — a description that matches a week-long shutdown of every digital banking channel a bank offers. Neither Hilltop nor its regulators have said publicly whether that 36-hour notification was made or what, if anything, the review has found so far.
The bank leaned on a separate federal backstop to reassure customers during the blackout: deposits stayed protected the entire time by standard FDIC deposit insurance, which covers up to $250,000 per depositor, per bank, for each account ownership category, regardless of whether the bank’s own systems are online or offline. That coverage addressed solvency, not access — it did nothing to get a scheduled mortgage payment out the door while the bank’s payment systems sat dark for more than two weeks.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- A handful of car engines are so tough mechanics say they almost never wear out
- The NSA is again telling phone owners to switch off one location setting
- Supplements now rank as the fifth-leading cause of death from liver disease.
- Herbal supplements are landing Americans in the hospital with liver damage, doctors warn