Skip to content

Sawyer Savings Bank Network and Branch Disruption

Summary

Sawyer Savings Bank logo

Sawyer Savings Bank closed all four Ulster County branches after an August 3, 2026, network disruption that it later called a likely data security incident involving a vendor vulnerability, while digital banking remained available. The bank reopened all branches August 10 after affected systems were restored and tested, though its investigation into possible data impact continued. A separate Storm claim provides additional cyber evidence but does not establish ransomware, actor responsibility or data theft.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Facility closure

    One or more offices, schools, clinics, stores, plants, branches, or other facilities closed because of the incident.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Sawyer Savings Bank experienced a material network and branch disruption beginning Aug. 3, 2026. Cyber involvement is confirmed because the bank’s Aug. 6 update said its investigation indicated the disruption was likely a data security incident involving a vendor vulnerability. Under DysruptionHub’s assessment standard, that qualified, cyber-specific victim wording is concrete public evidence; it does not establish malicious access, the identity of the vendor or a specific attack method.

Ransomware.live separately recorded a stable claim associating Sawyer Savings Bank with an operation labeled Storm. The claim is additional external cyber evidence, not proof that Storm caused the disruption or that ransomware, encryption, a ransom demand or data theft occurred.

Operational significance

The disruption affected portions of Sawyer’s network and forced the temporary closure of branches in Saugerties, Highland, New Paltz and Marlboro. The bank’s initial service notice said ATMs and online and mobile banking remained fully operational. A follow-up notice offered limited appointments for transactions that could not be completed through those channels and directed customers toward ATMs, remote deposit capture, mobile check capture and digital banking.

The incident caused a partial banking-service outage rather than a complete loss of account access. Customers could continue deposits, withdrawals, balance inquiries and digital banking, and debit cards remained available, but normal walk-in branch access was unavailable. Closing every branch materially restricted services that depend on in-person identity verification, document handling, cash services or staff assistance.

Disclosure posture

Sawyer initially described the event as a technical issue Aug. 3 and as a network disruption Aug. 4. The Aug. 6 statement was the bank’s first dated cyber-specific characterization. The public record does not establish when the Storm listing first appeared, so it cannot determine whether the external claim preceded or followed Sawyer’s statement.

Current status

Sawyer announced Aug. 9 that third-party specialists had securely restored and tested all affected systems and that all four branches would reopen Aug. 10. The notice supports an Aug. 10 end to the documented operational disruption and resolved status. The bank’s data-impact investigation continued, however, and it had not determined what data, if any, was affected or to whom it belonged.

Confidence and uncertainty

Confidence is high in the operational impact and recovery because Sawyer directly documented the network disruption, four-branch closure, alternate channels, secure restoration, testing and reopening. Confidence is high that concrete public cyber evidence exists. Confidence is medium that a vendor vulnerability caused the incident because that remains the bank’s preliminary investigative finding, not a completed forensic conclusion.

Data impact remains unknown. The bank said it had seen no evidence that customer accounts were directly affected or that Sawyer or customer data had been maliciously used, but it was still determining what data, if any, was affected and to whom it belonged. The statement does not affirmatively rule out unauthorized access, copying or exposure.

Ransomware involvement and Storm attribution are assessed with low confidence. The ransomware.live listing supports a claim record and leak-site indicator, but no victim, regulator, law-enforcement source, technical investigator or independent report corroborates Storm’s responsibility. The public record does not establish encryption, a ransom demand, data theft, negotiation, payment or publication of stolen material.

Analytic gaps

The public record does not identify the vendor, vulnerable product or service, initial access vector, affected internal systems, attacker activity, malware, encryption, dwell time, containment actions, restoration sequence or responsible actor. It also does not establish whether customer, employee or operational data was accessed, altered, copied or exposed; how many records or people could be involved; or whether regulators or law enforcement are participating in the investigation.

The available evidence does not establish when the Storm claim was published, what Storm allegedly obtained, whether it communicated with Sawyer or whether the claim was connected to the bank’s disruption. Without a claim publication date, the public chronology cannot resolve whether Sawyer or the external claimant first characterized the event as cyber-related.

Threat actor and claim

Listed as: Sawyer Savings BankSource: ransomware.liveDiscovered:

Claim details

Ransomware.live recorded a Storm claim associated with Sawyer Savings Bank. The bank has not attributed the incident to Storm or confirmed ransomware, encryption, a ransom demand or data theft, and no independent authoritative source corroborates the claim.

Organizations involved

Impacted locations

Sources

Sawyer Savings Bank of New York keeps branches closed amid possible data security incident

DysruptionHub reported that Sawyer’s four Ulster County branches remained closed after an August 3 network disruption that the bank said was likely tied to a vendor vulnerability. Digital banking, ATMs and debit cards remained available, while affected data, the vendor, attack type, actor and reopening date were unresolved.

Important Service Update

Sawyer said all branch offices were closed because of a technical issue while ATMs, online banking and mobile banking remained fully operational and customer-service representatives remained available.

Important Branch Service Update

Sawyer said portions of its network were affected, all branches remained temporarily closed, and a limited number of appointments were available for transactions not possible through ATMs or digital banking. The bank listed ATMs, remote deposit capture, online and mobile banking, and mobile check capture as alternatives.

Technical Disruption Update

Sawyer said an August 3 disruption affected portions of its network and temporarily closed its branches. The bank said the issue was likely a data security incident involving a vendor vulnerability, restoration and investigation were ongoing, and investigators were determining what data, if any, was affected.

Branch Service Disruption Update - Branches to Open Monday, August 10, 2026

Sawyer Savings Bank said all branches would reopen August 10 after third-party specialists securely restored and tested all affected systems. The bank said its investigation into what data, if any, may have been affected remained ongoing.

Sawyer Savings Bank homepage branch-closure notice

On August 8, Sawyer Savings Bank’s homepage continued to state that all branches were temporarily closed. It said online banking, mobile banking and debit cards remained available and directed customers to the bank’s technical-disruption update.

Sawyer Savings Bank claim record

The ransomware.live record identifies Sawyer Savings Bank as a claimed victim associated with an operation labeled Storm. It does not independently establish that Storm caused the bank’s disruption.

See something that needs correction?

Signed-in members can report an error, update, or missing source.