Skip to content

Sawyer Savings Bank of New York keeps branches closed amid possible data security incident

The Ulster County bank says a vendor vulnerability may be behind the disruption, while online and mobile banking and debit cards remain available.

Exterior of Sawyer Savings Bank at 87 Market St. in Saugerties, New York, with Sawyer Savings signage and a 24-hour ATM.
Sawyer Savings Bank’s branch in Saugerties, New York. (Sawyer Savings Bank)

Sawyer Savings Bank closed all four of its New York branches this week after a network disruption that the bank says is likely tied to a data security incident involving a vendor vulnerability.

The disruption began Monday, Aug. 3, affecting portions of the bank’s network and forcing the temporary closure of branches in Saugerties, Highland, New Paltz and Marlboro. The bank had not announced a reopening date as of Friday afternoon.

In a Facebook post Aug. 3, Sawyer initially described the problem as a “technical issue” and said ATMs, online banking and mobile banking remained fully operational.

By Aug. 4, the bank described the problem as a technical disruption affecting portions of its network. It also said it was offering a limited number of in-person appointments for transactions that could not be completed through ATMs or digital banking.

Sawyer Savings Bank notice stating that all branches are temporarily closed because of a technical disruption, with ATMs and online and mobile banking still available and limited in-person appointments offered.
Sawyer Savings Bank told customers in an Aug. 4 Facebook post that all branches were temporarily closed because of a technical disruption, while ATMs and online and mobile banking remained available. (Sawyer Savings Bank/Facebook)

In an Aug. 6 update, President and CEO James P. Whitaker said the bank had brought in third-party specialists when the disruption began to help restore affected systems and investigate the cause.

As the investigation progressed, Whitaker said, the bank learned the disruption was likely the result of a data security incident involving a vulnerability at one of its vendors. Sawyer has not identified the vendor or disclosed a specific attack type.

Customers can continue using ATMs for deposits, withdrawals and balance inquiries, along with online and mobile banking. Debit cards also remain available.

“We have seen no evidence to date that customer accounts have been directly affected by this situation, nor have we seen any evidence of malicious use of data from Sawyer Savings Bank or its customers,” Whitaker said.

The bank said investigators are still determining what, if any, data was affected and who it belongs to. Sawyer said it would notify and support affected people if investigators determine sensitive information was involved.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

The bank has not disclosed confirmed data theft, a ransom demand or a threat actor. It also has not publicly identified which internal systems were affected beyond saying the disruption involved portions of its network.

Sawyer Savings Bank, a Saugerties-based mutual savings bank founded in 1871, operates branches across Ulster County.

Recent cyber incidents at other regional financial institutions have caused broader disruptions. Monticello Banking Company in Kentucky restricted ATMs, online and mobile banking, cash management systems and regular phone service after a June 2025 cyberattack.

River Financial Corporation said ransomware affected some operations at Alabama-based River Bank & Trust in June, though it did not identify which customer services were disrupted. In 2024, a ransomware attack at California’s Patelco Credit Union knocked online banking, its mobile app and other day-to-day banking systems offline for roughly two weeks.

Sawyer’s website continued to list all branches as temporarily closed Friday afternoon and directed customers needing assistance to call its customer service department.

The cause and scope of the incident remain under investigation. The bank has not said when its branches will reopen or whether investigators have determined that customer or employee information was accessed.

Attribution note: DysruptionHub credits upstream reporting and primary sources—see citations above. If this report informed your coverage, please cite DysruptionHub with a link.
DysruptionHub Staff

DysruptionHub Staff

A collaborative project to bring you the latest cyberattacks impacting the availability of services and goods in the United States.

All articles

More in Critical Infrastructure

See all

More from DysruptionHub Staff

See all