Breach taxonomy
Summary
On May 5, 2026, Community Bank (subsidiary of CB Financial Services) discovered an internal incident in which non-public customer information was handled using an unauthorized AI-based software application. The Bank determined the event material on May 7, 2026 due to the volume and sensitivity of data involved, which included customer names, Social Security numbers, and dates of birth. The incident did not disrupt operations, customer account access, payment systems, or core IT infrastructure. The Bank engaged external cybersecurity advisors, notified regulators, and is conducting required customer notifications.
Tagging rationale
ThreatNon Priv Insider
Filing characterizes the event as an 'internal incident involving the handling of certain non-public customer information using an unauthorized artificial intelligence-based software application,' indicating an insider used unauthorized tooling rather than an external attacker. No indication of privileged/admin access misuse -> NON-PRIV-INSIDER.
MethodsData Leakage
Disclosure occurred through routine handling of customer data via an unauthorized (shadow-IT/AI) application rather than active attacker exfiltration; no malicious external actor described -> DATA-LEAKAGE rather than DATA-EXFIL.
AssetsPersonal Data
Filing states the disclosed customer information includes 'customer names, social security numbers and dates of birth' -> PERSONAL-DATA.
EffectsInfo Privacy Loss
Filing confirms PII (names, SSNs, DOBs) was disclosed but explicitly notes 'no disruption to the Bank's operations, customer access to accounts or services, payment systems, or core information technology infrastructure' -> INFO-PRIVACY-LOSS only.
Business continuityNot Required
Filing explicitly states the incident 'did not involve a disruption to the Bank's operations, customer access to accounts or services, payment systems, or core information technology infrastructure' -> no continuity procedures needed.
Impact
PII (names, SSNs, DOBs) was disclosed but no operational disruption occurred, volume not quantified, and the Company stated the incident is not expected to have a material impact on consolidated financial condition -> low impact (2).
InsuranceNot disclosed
Filing makes no mention of cyber insurance or insurance proceeds -> null.
Read the original SEC filing excerpt
Item 1.05. Material Cybersecurity Incidents On May 5, 2026, Community Bank (the "Bank"), the wholly-owned subsidiary of CB Financial Services, Inc. (the "Company"), became aware of an internal incident involving the handling of certain non-public customer information using an unauthorized artificial intelligence-based software application. Upon discovery, the Bank promptly took steps to secure the information at issue and initiated an internal investigation with the assistance of external cybersecurity advisors. The investigation into the incident, including the scope and root cause, remains ongoing. The incident did not involve a disruption to the Bank's operations, customer access to accounts or services, payment systems, or core information technology infrastructure; however, due to the volume and sensitive nature of the non-public information at issue, on May 7, 2026, the Company determined the event to be material. Among the customer information the Bank has determined was disclosed are customer names, social security numbers and dates of birth. The Company is evaluating the customer data that was affected and is conducting notifications as required by applicable federal and state laws and regulatory guidance. The Company has been, and continues to be, in communication with relevant banking and financial regulators regarding the incident. The Company has taken, and continues to take, actions designed to contain and remediate the incident. The Company remains committed to protecting its customers' data and is taking measures designed to prevent future similar incidents, including but not limited to, strengthening existing controls, implementing additional controls and enhancing monitoring measures. As of the date of this disclosure, this incident has not had, and is not expected to have, a material impact on the Company's consolidated financial condition or results of operations. 2