Quick Answer — On March 10, 2023, Silicon Valley Bank collapsed under a deposit run — the second-largest bank failure in US history at the time. For the tech sector it was an overnight operational emergency: payroll frozen, cards dead, runway calculations stale for thousands of companies, security vendors included. On March 26 (our peg for the retrospective), with depositors largely backstopped, the sector was still tallying the operational-security fallout: a spike in fraud and phishing targeting SVB-displaced customers, vendor-portability scrambles, and a re-learning of concentration risk. The lesson: your bank is a security dependency — single-vendor treasury concentration is an availability-and-integrity risk, and panic windows are prime fraud terrain.
What happened
- The run: March 9–10, 2023 — deposit flight after markdown announcements; California regulators closed SVB; the FDIC took receivership. The systemic-backstop announcements (all depositors whole) came over the following weekend.
- Tech’s exposure: SVB banked roughly half of US venture-backed startups by common estimates; payroll processors, benefits rails, and corporate cards strained within hours. Security startups and CISO-owned vendors were on both sides: exposed customers and disrupted suppliers.
- The fraud wave: From day one, scammers spun up SVB-themed phishing, fake “FDIC recovery” portals, BEC-style “our banking details changed” mail, and donation frauds piggybacking on stranded-payroll stories — a textbook exploitation of operational chaos (per contemporaneous reporting).
- The continuity scramble: Treasury teams opened emergency bank accounts, re-pointed payroll, re-routed billing, and rewired vendor payment instructions — every step a chance for an attacker to interject a “new account details” email of their own.
Why a bank run is a security event
| Vector | Mechanism |
|---|---|
| BEC on migration confusion | Mass legit “we changed banks” traffic = perfect camouflage for attacker versions |
| Fake recovery portals | Urgency + FDIC branding + displaced customers = credential harvest |
| Payroll diversion | HR/help desks overwhelmed; direct-deposit change requests get less scrutiny |
| Vendor compromise cascade | Suppliers’ own disruption degrades their security ops simultaneously |
| Secret sprawl | Emergency account openings and access grants bypass normal review |
Timeline
| Date | Event |
|---|---|
| 2023-03-08 → 09 | Markdown announcement; deposit run begins; stock halted |
| 2023-03-10 | FDIC receivership; accounts frozen; payroll panic peaks |
| 2023-03-12 → 13 | Systemic backstop: all depositors made whole; wire rails reopen |
| 2023-03 → 04 | Fraud waves crest: phishing, fake portals, “banking details changed” BEC; portability + multi-bank architecture becomes boardroom topic |
| 2023 → 2024 | Sector consolidation; vendor-risk questionnaires gain “banking concentration” lines; TPR programs absorb the lesson |
Defensive lessons
- Treasury concentration is an availability risk. One-bank architecture converts any single institution’s stress into your outage; multi-bank rails with pre-tested fallback beat heroic weekend scrambles.
- Payment-detail changes need out-of-band verification always — most of all during migrations. The SVB window saw thousands of legitimate “new account” emails; the only defense is a callback protocol attackers can’t spoof.
- Pre-draft the panic playbook. Payroll continuity, emergency spend authority, and comms templates written calmly beforehand save the first 48 hours for real problems.
- Watch the fraud curve, not just the finance curve. Fraud pressure at the exact edge of panic is a pattern (bank runs, disasters, layoffs); interdict by pre-warning treasury and HR inboxes before news cycles peak.
- Vendor review includes survival. Concentration risk applies to the supply side too — a critical vendor’s bank outage becomes your incident; ask about payment resilience, not just security certifications.
The Monday-after math
Backstop or not, the operating reality for tech security teams in the following weeks was a masterclass in degraded-mode operations: payment verification processes improvised, finance staff making novelty-sized decisions on no sleep, help desks authorizing exceptions at panic speed, and vendors asking customers to re-key billing details en masse. Fraudsters read the same news. The defending insight from that Monday-after: your controls are weakest precisely when your business is strangest — so pre-build the degraded-mode playbooks (who may approve what, via which verified channel, under which emergency authority) before the run starts, not during it.
Why it still matters in 2026
SVB dragged operational-resilience thinking out of ops-and-into-security’s remit: the fraud waves and BEC camouflage of March 2023 are now standard chapters in business-continuity training, and third-party-risk questionnaires routinely probe concentration dependencies (banking, cloud, one-man SaaS). In 2026’s landscape — regional-bank stress episodically recurring, deepfake-enhanced BEC industrialized, and treasury-fraud tooling commoditized — the SVB lesson compounds: every operational panic is an attacker’s product launch. The orgs that rehearsed treasury continuity like they rehearse ransomware found March 2023 merely expensive. The rest found it instructive.
Were security companies specifically hurt?
As customers and as vendors, yes in operational terms: payroll and billing disruption hit startups across the stack, and several security vendors publicly disclosed SVB exposure while reassuring customers about service continuity. No headline breach of a security firm via SVB itself materialized — the damage class was availability, cash access, and fraud exposure, which is precisely why it belongs in a security-timeline: integrity and availability are security properties.
What did the fraud campaigns actually look like?
Per contemporaneous reporting: lookalike domains riding SVB and FDIC names, “account verification” portals harvesting corporate banking credentials, urgent “update our wire instructions” email sent to finance staff of presumably affected firms, and donation scams targeting goodwill around stranded-payroll stories. Nothing technologically novel — the novelty was the scale-of-opportunity: thousands of distracted treasurers making real account changes at speed.
Is banking concentration now handled?
Partially, culturally more than formally. Many startups adopted multi-bank setups and treasury-ops playbooks; some regulators and enterprise buyers added resilience questions to due diligence. But inertia re-concentrates: convenience, fees, and integration gravity pull back toward single rails over time. Continuity is not a project with an end date; it’s a discipline that decays without rehearsal.
Part of the hmmnm.com security-timeline series — one event per month, 2021–2024, indexed here.
