Centennial Bank / Happy State Bank data incident (2026): what was reported and what to do
We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.
The Texas Attorney General’s register lists a data-security report for Centennial Bank, including its Happy State Bank division, published September 17, 2026. It records 2,050 affected Texas residents and notice by U.S. mail. That count is specific to Texas and is not a confirmed national total.
What the public record establishes
The filing names these potentially involved categories: name, address, Social Security information, driver’s license and other government-issued ID numbers, financial account or payment-card information, health insurance information, date of birth and an unspecified “Other” category.
The listing does not provide an incident timeline or explain how access or disclosure occurred. It also does not identify which categories applied to each recipient. Your individual notice is the best record of your own exposure and any offered assistance.
This page does not infer that every Centennial or Happy State Bank customer was affected. It also does not treat a tracker’s different headcount as the filing’s national total.
Sources
- Texas Attorney General: Data-security breach reports, Centennial Bank row, published September 17, 2026; checked October 2, 2026.
- FTC: Credit freezes and fraud alerts
- IdentityTheft.gov
What to do now
- Keep your notice. It identifies the data categories that applied to you and any enrollment deadline.
- Verify the notice through the organization’s official website or a contact number you already trust. Do not use an unexpected message’s links or share passwords or one-time codes.
- If Social Security or other identity information was involved, consider a free credit freeze with each of the three major U.S. bureaus. A freeze helps restrict new credit; it does not stop transactions on existing accounts.
- Review bank and card statements. Contact the institution about unfamiliar transactions. If health information was involved, also check insurance statements for unfamiliar claims.
- Use IdentityTheft.gov if someone is using your identity. Enroll in any monitoring offer through the verified notice’s instructions.
For help interpreting a letter, see a company emailed me about a breach.
What a Delist scan can tell you
A free Delist scan checks personal-data exposure on the sources we cover. It does not inspect this organization’s systems, establish whether your record was involved in this incident, or erase breach dumps. Paid listing-removal work requires separate authorization.
This summary is compiled from public notices and reporting available when this page was last updated. Figures may change as investigations continue. Confirm your own exposure and any assistance offer with the organization named in your notice.
Inclusion is a record of a publicly reported incident, not an allegation of wrongdoing or negligence.
Does the Texas report establish a national total or an attack method?
No. The Texas Attorney General register lists 2,050 affected Texas residents. It does not establish a nationwide total, incident timeline or access method. Check your individual notice for the data categories that applied to you.
Frequently asked questions
Was every Centennial or Happy State Bank customer affected?
The public listing does not establish that. A state filing count cannot identify whether an individual customer was involved; use your verified notice or a trusted bank contact channel.
Can Delist determine whether my bank record was involved?
No. Delist checks separate sources of personal-data exposure. It does not inspect bank systems, confirm incident membership or erase breach files.
What to do after a breach
- A company emailed me about a breach: what should I do?
- Dark web data versus data brokers
- What to do after a data breach
- DriveWealth data breach (2026)
- TransUnion data breach (2025)
- 700Credit data breach (2025)
- Infutor-linked exposure (2026)
- Aesto Health data breach (2026)
- First 48 hours after a data breach
- How to freeze your credit
A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.
More breaches
Free personal data exposure scan
We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.