Skip to content

Propagation of Cyberattacks through the Financial System: Kotidis & Schreft (2025)

Distilled by claude-sonnet-4-6 · extracted Jun 3, 2026, last verified Jun 4, 2026

JEL (IAR-assigned): G21, E42, G28 · assigned from the abstract, not the journal

Full structured metadata (methods, scope, relatesTo, topics, datasets): raw Markdown (.md)

paper-summarycybersecurityfinancial-stabilitypayment-systemsbankingcontagiondifference-in-differencespanel-regressionpeer-reviewedunreplicateddata:fedwiredata:fed-funds-confidentialdata:discount-window-confidentialdata:call-reportsdata:tsp-user-list

What this is. The paper’s core results, the empirical design (DiD with confidential Federal Reserve data), and the estimating equations: enough to know what was found and how, without reading all 46 pages. To replicate or extend it, read the full source at the original.

This paper is the first to quantify propagation of an actual multiday cyberattack on a major technology service provider (TSP) to the banking sector through the Fedwire payment system. The attack impaired user banks’ ability to send payments (first-round effect): on the worst day, users sent 33% fewer payments by number (45% by value) relative to nonusers. Business continuity plans (BCPs) and Fedwire extended hours reduced this by more than half. Exposed nonuser banks (receiver-banks) experienced a liquidity shortfall from reduced incoming payments (second-round effect), which they addressed by borrowing in the discount window or federal funds market, drawing down reserves, and sending payments during extended Fedwire hours. These actions averted broader contagion (third-round effect). Large banks responded more effectively than small ones throughout.

Magnitudes and significance are as reported; */**/*** = 10%/5%/1%. Locators point into the source PDF.

#ResultLocatorMagnitude
R1Users sent significantly fewer payments than nonusers on every day of the attack (first-round effect)Table II col. (3) and (7), p. 3332First day: -33% in number (t-stat implied by -0.395***); -45% in value. Mid-period: -13% (number), -19% (value). Last day: -10% (number), -16% (value). All significant at 1%.
R2Without BCPs (no switching to alternative Fedwire access methods), the first-day drop would have been 100% for users and system-wide disruption would have been twice as large§V.B, pp. 3333-3334Share of all Fedwire payments disrupted: 0.3% observed (0.45%*0.6%); counterfactual 0.6% (0.6%*1.0%).
R3Large users sent substantially fewer payments than small users did relative to nonusers; large users sent 26% fewer payments by value on the first day, versus 63% fewer for small usersTable IV col. (4), pp. 3337-3338Small users: -63% value, first day (col. (4) row 1). Large users: -26% (sum of rows 1 and 3, col. (4)). Difference statistically significant.
R4A 1-percentage-point increase in a receiver-bank’s exposure to users is associated with a 0.7% decrease in incoming payments on the first day of the attack (second-round effect)Table V col. (1), p. 3342Coefficient -0.689*** (SE 0.109). Effect halves in the mid-period (-0.403***) and is insignificant on the last day (-0.059).
R5The contagion was larger for small receiver-banks than large ones; exposure to large users protected large receivers because large users’ BCPs were more effectiveTable V col. (2)-(3), p. 3342; Table VI, pp. 3344-3345Large receivers: -0.389** (SE 0.183) on day 1. Small receivers: -0.667*** (SE 0.112). Receivers primarily exposed to large users experienced smaller or reversed drops (Table VI).
R6Exposed small receiver-banks with low reserves were more likely to borrow at the discount window; a 1-pp increase in exposure raised the probability of discount-window borrowing by 0.03% on day 1Table VII col. (6), p. 3347Coefficient 0.025*** (SE 0.006). For small banks with high reserves: 0.014** (SE 0.005). Large banks: -0.165** (SE 0.066), i.e., less likely.
R7Large exposed receivers with high reserves drew them down; a 1-pp increase in exposure is associated with an 18% decrease in reserves on the first dayTable IX col. (1), p. 3350Coefficient -18.095*** (SE 3.735) on log(Reserves). Mid-period -6.749 (insignificant).
R8Exposed receiver-banks sufficiently compensated for the liquidity shortfall and sent normal payments; no significant third-round effect on payment outflows was detectedTable X col. (1) and (3), p. 3351Exposure * First Day coefficient -0.267* (SE 0.141); mid-period 0.050 (insignificant); last day -0.020 (insignificant). Large banks sent significantly more payments on the last day (coefficient 1.692**, col. (2)).

Overall (paper’s conclusion). The cyberattack had a material impact on individual financial institutions directly and indirectly connected to the TSP, but did not impair the overall financial system. BCPs by users and the TSP, combined with Federal Reserve operational support (Fedwire extended hours, discount window lending), were the primary mitigants. Large banks were more agile in implementing BCPs throughout. The TSP lost approximately 11% of its customers in the year after the attack and another 29% the following year, though other developments may have contributed to these departures.

The paper has no formal economic model. The analysis tests three hypotheses about propagation through the payment network:

  1. The cyberattack disrupts user banks’ ability to send Fedwire payments (the common-shock, first-round effect), and BCPs partially offset this disruption.
  2. Nonuser banks that normally receive payments from users experience a liquidity shortfall (the contagion, second-round effect), because banks rely on incoming payments to fund outgoing payments (building on Afonso, Kovner, and Schoar (2011)).
  3. Unless receiver-banks can obtain alternative funding or rely on reserves, their inability to send their own payments creates further contagion to yet other banks (the third-round effect).

The identification strategy is a difference-in-differences design exploiting the common shock to users: the TSP taking its systems offline is a plausibly exogenous shock to user banks only. Nonusers faced no similar operational disruption. The analysis is in the spirit of Eisenbach, Kovner, and Lee (2022), who develop an ex-ante framework for measuring cyber risk in the US financial system; the present paper provides the first ex-post quantification using an actual event. Acemoglu, Ozdaglar, and Tahbaz-Salehi (2015) provide the theoretical backdrop for systemic risk and stability in financial networks.

The main threat to identification is selection: low-quality customers may match to TSPs with poor cybersecurity and also be less adept at implementing BCPs. To mitigate this, robustness tests restrict the control group to banks that use a competing TSP of similar revenue size, and match on log(assets) via propensity-score matching (pp. 3331, 3317). The paper states that full causal identification is not established (p. 3317). The event is also more severe than the hypothetical cyber run analyzed by Duffie and Younger (2019) because it is multiday and involves operational disruption, not only funding pressure. Crosignani, Macchiavelli, and Silva (2023) study propagation of the NotPetya cyberattack through firm supply chains; the present paper differs by focusing on a financial-sector TSP and Fedwire payment contagion.

The payment-network structure matters for the second-round analysis: large receiver-banks were primarily exposed to large users, while small receiver-banks were more uniformly exposed. Because large users implemented BCPs more effectively, large receivers fared better (pp. 3341, 3343).

The paper applies a panel difference-in-differences estimator to confidential daily transaction-level Fedwire data. There is no proposed novel method; the contribution is the first quantification of actual (not hypothetical) multiday cyberattack propagation using regulatory micro-data. The design builds on difference-in-differences, panel-regression, and event-study techniques.

First-round estimator (Equation 1, p. 3330). The dependent variable is the log change in the number or dollar value of Fedwire payments sent by sender-bank ss to receiver-bank rr on day tt relative to the same day one week earlier:

Δlog(Payments)srt=β1×Userss×FirstDayt+β2×Userss×MidPeriodt+β3×Userss×LastDayt+FE+εsrt(1)\Delta \log(\text{Payments})_{srt} = \beta_1 \times \text{Users}_s \times \text{FirstDay}_t + \beta_2 \times \text{Users}_s \times \text{MidPeriod}_t + \beta_3 \times \text{Users}_s \times \text{LastDay}_t + FE + \varepsilon_{srt} \tag{1}

where Userss\text{Users}_s is one if sender ss was a user of the TSP, FirstDayt\text{FirstDay}_t (LastDayt\text{LastDay}_t) is one on the first (last) day of the event, and MidPeriodt\text{MidPeriod}_t is one between first and last days. Fixed effects are added progressively. The preferred specification includes receiver-bank-by-day and sender-bank-by-receiver-bank fixed effects. Standard errors are two-way clustered at the sender-bank and day level (Bertrand, Duflo, and Mullainathan (2004)).

The log difference uses the day-before-the-same-weekday convention to account for weekly seasonality in Fedwire flows (Treasury settlement days on Thursdays, mid-month, and end-of-month); the upper 99th percentile of transactions is winsorized (p. 3330).

Second-round estimator (Equation 2, p. 3342). For exposed receiver-banks, the dependent variable is the log change in the value of incoming Fedwire payments:

Δlog(Payments)rt=days(βday×Exposurer×DayDummyt)+FE+εrt(2)\Delta \log(\text{Payments})_{rt} = \sum_{\text{days}} \left( \beta_{\text{day}} \times \text{Exposure}_r \times \text{DayDummy}_t \right) + FE + \varepsilon_{rt} \tag{2}

where Exposurer\text{Exposure}_r is the share of receiver-bank rr‘s total incoming payments (over a look-back window before the attack) originating from user banks. The model includes receiver-bank and day fixed effects. Standard errors are two-way clustered at the receiver-bank and day level.

Third-round estimator (p. 3351). Table X regresses the log change in the value of payments sent by exposed receiver-banks (now acting as senders) on the same exposure measure interacted with day dummies, controlling for receiver-bank-by-day FE and sender-bank-by-receiver-bank FE. The large-bank triple interaction isolates size heterogeneity.

Size heterogeneity (Equation 1 extended, pp. 3335-3336). Equation (1) is augmented with a LargeBanks\text{LargeBank}_s dummy and its interactions with the day dummies and the Users\text{Users} dummy to form a triple difference-in-differences. This captures the additional payment drop for small versus large users (Table IV).

First-round result (R1, Table II). Specification: Equation (1). Preferred columns (3) and (7) include receiver-bank-by-day FE and sender-bank-by-receiver-bank FE. Three-month window. U.S. G-SIBs excluded from the sender group (included in robustness, Internet Appendix Table IA.I). Sample: all Fedwire sender-receiver pairs with at least one payment in the window; 546,631 observations.

Mitigant analysis (R2, Table III). Identical to Table II but payments after 6:30 p.m. are excluded to isolate normal business-hour effects; the extended-hours contribution is inferred by comparison. Table II column (3) vs. Table III column (3): -0.395 vs. -0.393 first-day effect in number; -0.590 vs. -0.695 in value (Table II col. (7) vs. Table III col. (7)), showing extended hours raised value sent by about 5 percentage points.

Size heterogeneity (R3, Table IV). Triple DiD version of Equation (1). Dependent variable: log change in value (columns (4)-(6)) or number (columns (1)-(3)) of payments. Large bank is above-sample-average log(assets). Key interaction terms: Users×LargeBank×FirstDay\text{Users} \times \text{LargeBank} \times \text{FirstDay}; Users×FirstDay\text{Users} \times \text{FirstDay}. Columns (5)-(6) use extended Fedwire hours; (2)-(3) and (5)-(6) include individual user and TSP adaptation controls.

Second-round: contagion (R4-R5, Table V). Specification: Equation (2). Dependent variable: Δlog(Value of Payments received)\Delta \log(\text{Value of Payments received}). Three columns: all receivers, large receivers only, small receivers only. Receiver-bank FE and day FE. Two-way clustered at receiver-bank and day. Observations: 58,357 (all), 5,673 (large), 52,684 (small).

Contagion by user size (R5, Table VI). Augments Equation (2) with a second exposure layer: the share of the receiver’s user-originated payments coming from large versus small users, at threshold levels of 80%, 50%, 20%. This decomposes the asymmetric contagion finding (pp. 3343-3346).

Discount window borrowing (R6, Table VII). LPM regression: P(DWrt>0DWt1=0)=Exposurer×DayDummiest+ReceiverBank FE+FedReservDistrict×Day FE+εrtP(\text{DW}_{rt} > 0 | \text{DW}_{t-1} = 0) = \text{Exposure}_r \times \text{DayDummies}_t + \text{ReceiverBank FE} + \text{FedReservDistrict} \times \text{Day FE} + \varepsilon_{rt}. Dependent variable is the dummy for first-time discount-window borrowing at time tt conditional on no prior use at t1t-1. Split by bank size and reserve-to-asset ratio (columns (1)-(6)).

Reserve drawdowns (R7, Table IX). Regression of log(Reservesrt)\log(\text{Reserves}_{rt}) on Exposurer×DayDummiest\text{Exposure}_r \times \text{DayDummies}_t for the subset of large banks with relatively high reserves (those from Table VIII column (4)). Receiver-bank FE and day FE; 82 observations.

Third-round: payments sent by exposed receivers (R8, Table X). Regression of Δlog(Value of Payments sent)rt\Delta \log(\text{Value of Payments sent})_{rt} on Exposurer×DayDummiest\text{Exposure}_r \times \text{DayDummies}_t, with receiver-bank-by-day FE and sender-bank-by-receiver-bank FE, 304,663 observations. Extended and normal business hours compared across columns.

DatasetRole in paperWiki page
Fedwire Funds Service transaction-level data (confidential)Daily sender-receiver-pair payment flows; treatment and outcome for first- and third-round DiDNo page yet
List of users of the TSP (confidential)Treatment-group indicator (user vs. nonuser); identifies which banks could not access normal TSP servicesNo page yet
Federal funds loan-level data (Furfine algorithm, confidential)Interbank borrowing outcome for large exposed receiver-banks; cross-checked against FR 2420 and FHLB 10-KsNo page yet
Discount window daily borrowing records (confidential)Discount-window borrowing outcome for small exposed receiver-banksNo page yet
Federal Reserve confidential reserve accounting recordsEnd-of-day reserves held at the Federal Reserve; used for reserve-drawdown analysis (Table IX)No page yet
Call Reports (FFIEC / FDIC)Balance sheet data (total assets) for size classificationCall Reports (public)

Sample: event window is a confidential multiday period (not disclosed to protect anonymity of the TSP and the event). The three-month analysis window spans the month before, the event days, and the month after. Frequency: daily payment flows; balance sheet data matched at quarterly frequency.

Use the original if you are: designing business continuity or third-party risk management requirements for banks or TSPs; studying payment-system contagion and the role of central-bank operational support; extending the empirical design to other cyber events (Internet Appendix Tables IA.I-IA.IV have robustness results and summary statistics); or evaluating whether larger or smaller banks should hold larger liquidity buffers as a first line of defence against operational disruptions. The locators above point to the exact tables.

Source: peer-reviewed, The Journal of Finance 80(6), December 2025. This distillation was extracted by an LLM on 2026-06-03 and is not human-verified or independently reproduced. The underlying data are confidential Federal Reserve records and cannot be reproduced outside the Federal Reserve. Redistribution is extract-only (Wiley VOR terms outside the USA).

Kotidis, Antonis, and Stacey L. Schreft. “The Propagation of Cyberattacks through the Financial System: Evidence from an Actual Event.” The Journal of Finance 80, no. 6 (December 2025): 3313-3358. DOI: 10.1111/jofi.13475. This article is a U.S. Government work and is in the public domain in the USA. Extract-only outside the USA (Wiley VOR terms and conditions).

Found an error or want a topic covered? Open an issue, use the Edit page link above, or email contact@instituteforautomatedresearch.org. Edits are reviewed before publishing; provenance and accuracy are the point.