Third Coast Bancshares Data Breach

Alleged

Ransomware claim involving Third Coast Bancshares

Published: Aug 18, 2026 INC Ransom
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Third Coast Bancshares
Industry
Finance
Threat Actor
INC Ransom
Date of Incident
Aug 18, 2026

Executive Summary

INC Ransom added Third Coast Bancshares to its leak portal on August 18, 2026. Third Coast Bancshares, a Texas-based bank holding company operating under the domain thirdcoast[.]bank, is now listed among the victims of INC Ransom. This listing is significant as it places a U.S.-regulated financial institution within INC Ransom’s active portfolio. The inclusion of a financial institution is noteworthy due to the mandatory breach notification obligations and increased regulatory scrutiny that accompany cybersecurity incidents within the banking sector. INC Ransom has been particularly active, claiming 42 other victims in the past 60 days. The group’s primary targets have been in Professional Services, Healthcare, and Business Services, with a concentration of victims in the United States, UAE, and Canada. Financial institutions are considered high-value targets for ransomware groups, as the sensitive customer data they hold, coupled with regulatory pressure, can increase the likelihood of a negotiation and payout. Notable recent victims in the financial or similarly regulated sectors include SpearFin Ltd, VantagePoint Management & Autoclear, and Lansing Urgent Care.

Technical Analysis

SOCRadar’s stealer-log telemetry did not yield any matching records for the domain thirdcoast[.]bank. It is common for banking institutions to have more robust security measures, including stricter endpoint controls, which can result in a lower signal in stealer-log datasets compared to commercial organizations. This lack of matching records does not confirm the absence of credential exposure. The queried dataset is paginated, and it is possible that credentials may exist under employee personal accounts or on sibling domains not included in this specific sample. The absence of direct stealer-log findings for thirdcoast[.]bank is anticipated for a well-secured financial environment and does not diminish the risk posed by the listing on the ransomware group’s leak site. Such findings do not rule out potential compromise or the use of compromised credentials for initial access or lateral movement. The possibility of credentials existing in feeds outside the queried dataset or having been used and rotated prior to indexing remains. The incident highlights the importance of continuous monitoring. Organizations should audit authentication logs for anomalous remote-access activity, particularly for Microsoft 365 and VPN sign-in logs, looking for access from external or unusual IP addresses. It is also advisable to assess staff personal email addresses against known stealer-log datasets and to have robust incident response plans in place that align with applicable financial sector regulatory requirements.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.