Breach taxonomy
Summary
SR Bancorp disclosed that Mercadien, P.C., a vendor providing internal audit-related services to Somerset Regal Bank, suffered a data security incident in which an unauthorized actor accessed and acquired files on Mercadien's servers containing bank customer data including names, Social Security numbers, account numbers, identification documents and dates of birth. The bank's own systems and operations were not impacted. Filed under Item 8.01; materiality not determined as a 1.05 incident.
Tagging rationale
ThreatUnknown
Filing refers only to 'an unauthorized actor' with no attribution -> UNKNOWN.
MethodsData ExfilSupply Chain
An unauthorized actor 'accessed and acquired certain files' on the servers of third-party vendor Mercadien -> DATA-EXFIL + SUPPLY-CHAIN.
AssetsPersonal Data
Compromised files 'included the name, social security number, account numbers, identification documents and/or date of birth for certain Bank customers' -> PERSONAL-DATA.
EffectsInfo Privacy Loss
Only effect disclosed is exposure of customer PII held by the vendor; no disruption to bank operations, payments, or IT infrastructure -> INFO-PRIVACY-LOSS.
Business continuityNot Required
Filing states the incident 'did not involve a disruption to the Bank's operations, customer access to accounts or services, payment systems, or core information technology infrastructure' -> Not Required.
Impact
Sensitive customer PII including SSNs and account numbers acquired via a vendor, but no operational impact and no expected material financial effect -> score 2.
InsuranceNot disclosed
Filing makes no mention of insurance -> null.
Read the original SEC filing excerpt
Item 8.01 Other Events. Mercadien, P.C. CPAs ("Mercadien"), which provides internal audit-related services to SR Bancorp, Inc (the "Company") and Somerset Regal Bank (the "Bank"), has discovered a data security incident in which an unauthorized actor accessed and acquired certain files on Mercadien's computer servers, which included certain Bank customer data. Somerset Regal Bank's business systems were not involved in or impacted by the incident. The incident did not involve a disruption to the Bank's operations, customer access to accounts or services, payment systems, or core information technology infrastructure. The information that Mercadien had on its computer servers included the name, social security number, account numbers, identification documents and/or date of birth for certain Bank customers. The Bank is providing customer notifications through Mercadien, as required by applicable federal and state laws and regulatory guidance. The Company remains committed to protecting its customers' data. As of the date of this disclosure, this incident has not had a material impact.