{"schema_version":"secwatch.filing_event.v1","accession":"0001104659-23-077393","form_type":"8-K","ticker":"HTH","cik":"0001265131","company_name":"Hilltop Holdings Inc.","filed_at":"2023-07-03T23:59:59+00:00","discovered_at":"2026-05-14T18:03:33.389603+00:00","generated_at":"2026-06-13T13:07:34.593592+00:00","sec_items":["8.01","9.01"],"event_type":"cyber","sentiment":"negative","materiality_score":0.85,"calibrated_materiality_score":0.85,"confidence":"high","headline":"Hilltop Holdings data breach at vendor exposes SSNs, account numbers of substantially all bank customers","bullets":["Third-party vendor of PlainsCapital Bank confirmed June 27 that SSNs and account numbers for substantially all customers were likely taken via MOVEit zero-day vulnerability.","No indication of impact on Hilltop's own systems or customer access credentials; no material business interruption.","Bank will offer complimentary credit monitoring and identity restoration services to affected customers.","Company expects to incur expenses for response, remediation, and investigation; faces potential litigation and regulatory scrutiny."],"urls":{"canonical":"https://secwatch.observer/filing/0001104659-23-077393","json":"https://secwatch.observer/filing/0001104659-23-077393.json","markdown":"https://secwatch.observer/filing/0001104659-23-077393.md","text":"https://secwatch.observer/filing/0001104659-23-077393.txt","edgar_index":"https://www.sec.gov/Archives/edgar/data/1265131/000110465923077393/0001104659-23-077393-index.htm","edgar_primary_document":"https://www.sec.gov/Archives/edgar/data/1265131/000110465923077393/tm2320416d1_8k.htm"},"model":{"generated_by":"deepseek-v4-flash:cloud@v2","generated_at":"2026-06-13T13:07:34.593592+00:00"},"review":{"review_status":"machine_generated","human_reviewed":false,"corrected":false,"correction_note":null,"correction_timestamp":null,"superseded_by":null,"related_filings":[]},"source_grounded_claims":[],"license":"Source filings: public domain (SEC EDGAR). Summaries (headline + bullets): CC-BY-4.0; attribute https://secwatch.observer"}