Breach taxonomy
Summary
Orrstown Financial Services received notice on May 21, 2026 from a third-party vendor that the vendor experienced a cybersecurity incident in which a third party gained unauthorized access to sensitive personal information of certain Orrstown customers. Orrstown is one of a number of organizations affected by the vendor's incident. The company's own systems were not accessed or affected, no misuse of customer information has been indicated, and impacted customers are being offered credit monitoring. Filed under Item 8.01; company does not expect a material impact.
Tagging rationale
ThreatUnknown
Filing refers only to 'a third-party [that] gained unauthorized access' with no attribution -> UNKNOWN.
MethodsData ExfilSupply Chain
Breach occurred at an unnamed third-party vendor affecting multiple organizations -> DATA-EXFIL + SUPPLY-CHAIN.
AssetsPersonal Data
A third party 'gained unauthorized access to sensitive personal information of certain of the Company's customers' -> PERSONAL-DATA.
EffectsInfo Privacy Loss
Only effect disclosed is exposure of customer PII held by the vendor; Orrstown's systems 'have not been accessed, compromised or affected' -> INFO-PRIVACY-LOSS.
Business continuityNot Required
No operational disruption; incident confined to the vendor's environment -> Not Required.
Impact
Vendor-side PII exposure with no indication of misuse, no system impact, and no expected material financial effect -> score 1.
InsuranceNot disclosed
Filing makes no mention of insurance -> null.
Read the original SEC filing excerpt
Item 8.01 Other Events. (b) On May 21, 2026, the Company received notice from a third-party vendor that such vendor had experienced a cybersecurity incident whereby a third-party gained unauthorized access to sensitive personal information of certain of the Company's customers. The Company is one of a number of organizations that have been affected by this vendor's cybersecurity incident. Based on the Company's investigation to date, the Company's information systems and networks have not been accessed, compromised or affected by the incident. The vendor has informed the Company that there is currently no indication that the Company's customer information has been misused. Impacted customers will be notified of the incident and offered credit monitoring services. The incident has not had and is not expected to have a material impact on the Company's operations, and the Company does not currently anticipate that this incident will have a material impact on its financial condition or results of operations.