Open report — full analysis, no account required.

Sign up to generate reports and read filings that aren't on the open list.

Sign up free

Get notified when ORRF files again. Create a free account and we'll email you the moment its next filing is analyzed.

Get filing alerts
NASDAQ: ORRF ORRSTOWN FINANCIAL SERVICES INC 8-K

Orrstown to redeem $31M subordinated notes; discloses vendor data breach

Filed May 29, 2026 · Period ending May 29, 2026 · ~1 min read

3 key changes 1 section

Key Changes

  • medium

    Company will redeem all $31 million of 4.5% fixed-to-floating subordinated notes on June 30, 2026 at par plus accrued interest, eliminating debt assumed in 2024 Codorus Valley merger currently costing 7.72%.

  • medium

    Third-party vendor breach exposed customer personal information on May 21, 2026; Orrstown's own systems unaffected, no evidence of data misuse, affected customers receiving credit monitoring.

  • low

    Management states vendor incident not expected to materially impact operations or financial results, though acknowledges potential legal and regulatory risks.

Summary

Orrstown announced two unrelated developments: a debt redemption and a vendor cybersecurity incident. The company will retire $31 million in subordinated notes on June 30, 2026, paying par plus accrued interest. These notes, inherited from the 2024 Codorus Valley acquisition, currently carry a 7.72% floating rate—eliminating this obligation reduces interest expense going forward.

Separately, a third-party vendor suffered a breach that exposed some customer data. Orrstown emphasizes its own systems remain secure and there's no evidence the stolen information has been misused. The company is providing credit monitoring to affected customers and does not expect material financial impact, though it acknowledges potential legal and reputational exposure. For retail holders, the debt redemption modestly strengthens the balance sheet while the breach appears contained at the vendor level with limited direct exposure to Orrstown.

Section-by-Section Diff

Event · Item 8.01 — Other Events

~800 words

Item 8.01 — Other Events filed; see Key Changes for terms.

2 Added
Added Vendor cybersecurity incident medium

Added in current filing · verify on EDGAR →

On May 21, 2026, the Company received notice from a third-party vendor that such vendor had experienced a cybersecurity incident whereby a third-party gained unauthorized access to sensitive personal information of certain of the Company’s customers. The Company is one of a number of organizations that have been affected by this vendor’s cybersecurity incident.

A third-party vendor experienced a cybersecurity breach that exposed sensitive personal information of some Orrstown customers. The company emphasizes its own systems were not compromised, there is no current indication of data misuse, and affected customers will receive credit monitoring. Orrstown states the incident is not expected to materially impact operations or financial results.

Show 1 minor / wording change
Added Cybersecurity incident impact assessment low

Added in current filing · verify on EDGAR →

Based on the Company’s investigation to date, the Company’s information systems and networks have not been accessed, compromised or affected by the incident. ... The vendor has informed the Company that there is currently no indication that the Company’s customer information has been misused. ... The incident has not had and is not expected to have a material impact on the Company’s operations, and the Company does not currently anticipate that this incident will have a material impact on its financial condition or results of operations.

The company's own systems remain secure and uncompromised. While customer data was accessed at the vendor level, there is no evidence of misuse to date. Management does not expect material financial or operational impact, though the filing acknowledges potential legal, reputational, and regulatory risks.

Was this report useful?

Figures/quotes linked to EDGAR · Narrative written by AI · Jun 21, 2026 · How we verify