Tri Counties Bank Listed by blackbasta Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Tri Counties Bank Listed by blackbasta Ransomware Group (reported March 19, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
When a bank appears on a ransomware group's leak site, the immediate concern for customers and employees is straightforward: whether personal or financial information left the institution's systems, and what that could mean for identity theft, fraud, or unwanted contact. Public reporting on 19 March 2023 stated that Tri Counties Bank had been listed by the blackbasta ransomware group, with internal files described as exfiltrated. The number of people affected remains unknown, and precise details about what left the network have not been confirmed in available accounts.
For ordinary account holders and staff, the practical stakes centre on the kinds of records a regional bank routinely maintains—names, contact details, account identifiers, and related internal documents—and the possibility that some of those materials could surface or be misused. Until fuller disclosure occurs, the prudent response is to treat the listing as a serious claim that warrants monitoring rather than panic.
Inside the incident
According to the reported information, Tri Counties Bank was listed by the blackbasta ransomware group on 19 March 2023. The available summary states that internal files were exfiltrated in a ransomware attack. No confirmed figure for the number of people affected has been published. Timing of the intrusion itself, the initial access method, the duration of any attacker presence, and the full scope of systems involved are not detailed in the public record surrounding the listing.
What is known is limited to the group's claim that data was taken and that the bank appeared on its leak site. No independent confirmation of the volume, specific file names, or exact categories beyond "internal files" has been supplied in the facts at hand. Organisations in this position sometimes negotiate, restore from backups, or both; none of those outcomes is documented here. The incident is therefore best understood as an asserted ransomware event involving claimed data theft, with most operational particulars still undisclosed.
The group behind it: blackbasta
Blackbasta is a ransomware operation that emerged in public reporting in 2022 and has been associated with double-extortion tactics: encrypting systems while also copying data and threatening to publish it if a ransom is not paid. The group has typically targeted mid-sized and larger organisations across multiple sectors, using leak sites to pressure victims by listing their names and, in some cases, samples of stolen material. Public analyses have linked blackbasta activity to common initial-access routes such as compromised credentials, phishing, or exploitation of exposed services, followed by lateral movement and data staging before encryption.
In this instance, the group claims Tri Counties Bank as a victim and asserts that internal files were exfiltrated. That listing constitutes an unverified claim unless separately confirmed by the organisation or regulators. No statements attributed to blackbasta beyond the fact of the listing and the description of internal-file exfiltration are part of the available record for this specific case. Like other ransomware crews, blackbasta's public posture is designed to create urgency; readers should treat any such claims as allegations pending corroboration.
Who is Tri Counties Bank?
Tri Counties Bank is a California-based community and commercial bank established in 1975. It operates as a wholly-owned subsidiary of TriCo Bancshares (NASDAQ: TCBK), headquartered in Chico, California, and has reported assets of approximately $10 billion. The bank provides personal, small-business, and commercial banking services across California through a branch network, online and mobile channels, and access to a large ATM network.
Institutions of this type sit at the centre of everyday financial life for individuals, families, and local businesses. They hold customer identity and account data, transaction histories, lending files, and internal operational records. A ransomware incident affecting such an organisation is consequential because the data it manages can be directly useful for fraud, and because disruption or disclosure can erode trust and create regulatory and operational costs. The bank's regional footprint means any confirmed exposure would primarily affect California communities and the people who bank or work there.
What was likely exposed
The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of data types—such as customer names, Social Security numbers, account numbers, employee records, or specific document categories—has been disclosed. The exact contents therefore remain unconfirmed.
Banks of this kind typically maintain customer onboarding and KYC information, account and transaction data, loan and credit files, employee personnel records, and a range of internal operational and correspondence documents. It is reasonable to expect that some mixture of those categories could be present in "internal files," yet it would be inaccurate to assert that any particular field or record set was taken. Until the organisation or official notices specify otherwise, the exposed material should be described only as claimed internal files whose precise composition is unknown.
The real-world impact
For individuals, the primary risks associated with a bank-related data claim are financial fraud, identity theft, and targeted phishing that references real account or personal details. Even when full customer databases are not confirmed stolen, fragments of internal files can still enable convincing social-engineering attempts. Credit monitoring, careful scrutiny of account statements, and scepticism toward unexpected requests for credentials or payments are concrete, proportionate responses.
For the organisation, a ransomware listing can bring operational disruption, investigative and recovery costs, potential regulatory scrutiny, and reputational pressure. Customers may seek reassurance or move relationships; employees may face heightened social-engineering risk. Because the number of people affected is unknown and the data types are only broadly described, the scale of downstream harm cannot be quantified from public facts alone. The impact is real in the sense that any confirmed exfiltration of banking-related internal material elevates fraud risk; it is not, on present information, a fully mapped incident with published victim counts or itemised data inventories.
If your data was in this claimed breach
If you hold accounts with Tri Counties Bank or have been an employee or close business partner, begin with basic hygiene: monitor statements and credit reports for unfamiliar activity, enable strong multi-factor authentication on financial and email accounts, and treat unsolicited messages that reference the bank or this incident with caution. Consider placing a fraud alert or credit freeze if you have reason to believe sensitive identifiers were involved. Official notices from the bank, if issued, should take precedence over third-party summaries.
You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That step does not confirm or deny involvement in this specific incident, but it provides a practical way to see whether your addresses or related credentials appear in previously compiled collections and to decide on further monitoring.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
fairmontfcu.com Listed by blackbasta Ransomware GroupTAMMAC Listed by blackbasta Ransomware GroupAdvance America Listed by blackbasta Ransomware Groupmigonline.com Listed by blackbasta Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Tri Counties Bank Listed by blackbasta Ransomware Group →
Publicly posted by blackbasta — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.