Cyberattacks on Small Banks and the Impact on Local Banking Markets
What this paper finds — and why it matters
This paper studies what happens to local banking markets when a small bank suffers a successful cyberattack, using a stacked difference-in-differences design on 16 cyber incidents at small U.S. banks drawn from the Privacy Rights Clearinghouse database over 2005–2017. Attacked small banks experience a deposit growth rate roughly 22 percentage points lower than matched control banks in the two years following a breach, reflecting depositors’ loss of confidence in the targeted institution’s cybersecurity capacity. The deposit attrition is sharply stronger in counties with lower digital literacy, consistent with less-informed depositors placing disproportionate weight on a visible security failure. Deposit losses do not flow evenly to all competitors: positive spillovers accrue only to the dominant or largest banks in the local market, not to other small banks, concentrating market share toward large incumbents. Affected small banks subsequently attract riskier mortgage borrowers — proxied by higher loan-to-value ratios and lower FICO scores — suggesting that the deposit-cost pressure from a cyberattack induces yield-seeking behavior. The aggregate effect is a reduction in credit access for informationally opaque small borrowers that slows local small-establishment growth.
Summary of a forthcoming paper, AI-assisted and human-reviewed. See the linked original for the authoritative claims and full conditions.
Q1. What is the identification strategy and what variation does it exploit?
The paper uses a stacked difference-in-differences design that stacks sub-experiments around each of the 16 cyberattack events, comparing the attacked small bank against a matched set of control banks in the same local market that did not experience a breach, with the event window centered on the quarter of the reported breach. The primary data source for cyber incidents is the Privacy Rights Clearinghouse (PRC) database, which records data breaches across industries; the paper restricts attention to incidents at U.S. commercial banks with total assets below a size threshold that classifies them as small. The stacking design allows each attack event to contribute its own two-by-two (pre/post, treated/control) comparison while controlling for time fixed effects across all events, which is important because cyberattacks cluster in certain periods. Identification relies on the parallel-trends assumption: absent the cyberattack, the deposit growth trajectory of the attacked bank would have evolved like that of matched local competitors. The paper validates this assumption with pre-trend tests and provides a battery of robustness checks including alternative matching procedures and excluding events that coincide with other bank-specific news.
Q2. How large is the deposit effect at attacked small banks and what is the direction of deposit flows?
Attacked small banks see deposit growth rates approximately 22 percentage points lower than control banks over the two years following a breach, a decline that is economically large relative to the unconditional mean deposit growth rate in the sample. The market-share impact is of the order of 1 percentage point lower for the attacked bank. Crucially, the deposit outflows do not disperse evenly to all rivals: the paper finds positive and statistically significant deposit spillovers only at the dominant large bank (or banks) in the local market, with no measurable increase at competing small banks. This asymmetric spillover is consistent with depositors fleeing to scale — perceiving large banks as having the technological resources and regulatory scrutiny to maintain cybersecurity — rather than simply seeking any alternative.
Q3. What role does digital literacy play in moderating the deposit response?
The deposit effect is significantly stronger in counties with below-median digital literacy, measured using population-weighted indices of internet connectivity and self-reported computer use from the American Community Survey, suggesting that less-digitally-literate depositors rely more heavily on observable security signals — such as a publicized breach — when assessing bank safety. In high-digital-literacy counties, the average customer may already have some prior belief about cyber risk across institutions and may discount a single breach as less informative, dampening the flight-to-quality response. In low-digital-literacy counties, the breach is a more salient and credibility-destroying event. The heterogeneity is quantitatively meaningful and survives controlling for MSA-level income, education, and urbanization.
Q4. How does the competitive position of large banks in the local market moderate the spillover?
When a large bank holds a dominant market position prior to the attack — measured by having a market share above the 75th percentile of the local deposit distribution — the positive deposit spillover to that large bank is more than 30 percentage points larger than in markets where large banks hold a weaker position, pointing to a flight-to-incumbency effect that operates on top of the flight-to-scale effect. This finding implies that cyberattacks on small banks are particularly concentrating in markets where large banks are already dominant: the attack accelerates an existing market-share gradient rather than creating a new one. The result has policy relevance for local banking market competition: communities that already have concentrated banking sectors are more exposed to structural concentration following cyber events.
Q5. Do deposit rates at attacked small banks rise or fall, and does this signal a funding-cost channel?
Deposit rate evidence in the working paper suggests that attacked small banks do not uniformly raise deposit rates to retain customers, which is consistent with the deposit outflows being driven by non-price concerns about security rather than competitive pricing, and which rules out a simple funding-cost-through-repricing mechanism. The absence of a strong deposit-rate increase at the attacked bank indicates that depositors are responding to a qualitative signal about the bank’s cybersecurity capacity rather than being price-insensitive. This matters for the economic interpretation: the mechanism is loss of depositor confidence rather than increased funding costs passed through from the attack’s direct remediation expenses.
Q6. What happens to the loan portfolio and borrower risk profile of attacked small banks after a breach?
In the post-attack period, affected small banks shift their mortgage originations toward riskier borrowers, with originations showing higher average loan-to-value ratios and lower average FICO scores relative to the pre-attack period and relative to control banks, consistent with yield-seeking behavior driven by the deposit-funding squeeze. This borrower-quality deterioration implies a second-order financial stability concern beyond the immediate deposit loss: attacked banks may take on more risk in the loan book at precisely the moment when their funding base is weakening. The evidence is thus consistent with a mechanism in which the cyberattack triggers a cascade — deposit loss → funding pressure → reach-for-yield → loan-quality deterioration.
Q7. What are the real-economy consequences at the local market level?
Counties that experience a cyberattack on a local small bank show lower subsequent small-establishment growth relative to control counties, measured using County Business Patterns data on establishments with fewer than 20 employees, consistent with reduced small-business credit availability as small banks contract lending. Large banks that absorb deposit inflows from the attacked institution do not offset this credit reduction: the deposit inflows do not translate into proportionate increases in small-business or small-mortgage lending, reflecting the well-documented diseconomy of scale in relationship lending by large institutions. The real-economy effect is concentrated in counties where small banks had a larger pre-attack share of local deposits and credit, consistent with the mechanism that the effect operates through credit-supply disruption rather than demand shocks.
Q8. How does this paper relate to the literature on bank runs and financial contagion?
Unlike classic bank-run models in which depositor withdrawals are self-fulfilling or triggered by sunspot-like coordination failures, this paper’s results suggest that cyberattacks constitute an information event that rationally updates depositors’ beliefs about the attacked bank’s technological competence, generating a fundamentals-based run on the specific institution rather than systemic panic. The results complement the emerging literature on cyber risk in financial institutions (e.g., Kashyap and Wetherilt 2019, Eisenbach et al. 2022) by documenting market-level spillovers and real effects beyond the attacked institution. The finding that large banks absorb deposits following attacks on small banks also connects to the “too-big-to-fail” literature by showing that size confers a competitive advantage in moments of localized financial stress.
Key Concepts
stacked difference-in-differences : an event-study design in which multiple treatment events are each assigned their own pre/post comparison window, the sub-experiments are then stacked into a single dataset, and pooled regressions with event-by-period fixed effects estimate the average treatment effect; used in this paper to exploit variation across 16 separate cyberattack events at small banks.
Privacy Rights Clearinghouse (PRC) database : a publicly available database of data-breach incidents across industries in the United States, which the paper uses as the primary source for identifying confirmed cyberattacks on commercial banks; the paper restricts to incidents classified as hacking or skimming rather than physical theft or accidental exposure.
deposit spillover : the increase in deposit inflows to competitor banks in the same local market following a cyberattack on a rival institution; in this paper, measured as the change in deposit growth at non-attacked banks relative to their own pre-attack trends.
flight-to-scale : the pattern in which depositors shift funds from smaller to larger banks following a cyber incident, driven by the belief that larger banks have superior cybersecurity resources; the paper documents that this flight benefits only the largest local bank rather than all large banks.
digital literacy : a county-level index measuring residents’ familiarity with digital technologies, internet access, and computer use; used in the paper to test whether depositor reactions to cyberattacks are stronger where depositors have less prior information about cyber risk.
reach-for-yield : the tendency of a bank with a weakened funding base to shift its loan portfolio toward higher-yielding, riskier borrowers to maintain net interest margins; documented in this paper as a behavioral response of attacked small banks in the post-breach period.