Open report — full analysis, no account required.
Sign up to generate reports and read filings that aren't on the open list.
Get notified when ORRF files again. Create a free account and we'll email you the moment its next filing is analyzed.
Get filing alertsOrrstown to redeem $31M subordinated notes; discloses vendor data breach
Filed May 29, 2026 · Period ending May 29, 2026 · ~1 min read
Key Changes
-
medium
Company will redeem all $31 million of 4.5% fixed-to-floating subordinated notes on June 30, 2026 at par plus accrued interest, eliminating debt assumed in 2024 Codorus Valley merger currently costing 7.72%.
Item 8.01 verify on EDGAR → -
medium
Third-party vendor breach exposed customer personal information on May 21, 2026; Orrstown's own systems unaffected, no evidence of data misuse, affected customers receiving credit monitoring.
Item 8.01 verify on EDGAR → -
low
Management states vendor incident not expected to materially impact operations or financial results, though acknowledges potential legal and regulatory risks.
Item 8.01 verify on EDGAR →
Summary
Orrstown announced two unrelated developments: a debt redemption and a vendor cybersecurity incident. The company will retire $31 million in subordinated notes on June 30, 2026, paying par plus accrued interest. These notes, inherited from the 2024 Codorus Valley acquisition, currently carry a 7.72% floating rate—eliminating this obligation reduces interest expense going forward.
Separately, a third-party vendor suffered a breach that exposed some customer data. Orrstown emphasizes its own systems remain secure and there's no evidence the stolen information has been misused. The company is providing credit monitoring to affected customers and does not expect material financial impact, though it acknowledges potential legal and reputational exposure. For retail holders, the debt redemption modestly strengthens the balance sheet while the breach appears contained at the vendor level with limited direct exposure to Orrstown.
Section-by-Section Diff
Event · Item 8.01 — Other Events
Item 8.01 — Other Events filed; see Key Changes for terms.
Added in current filing · verify on EDGAR →
On May 21, 2026, the Company received notice from a third-party vendor that such vendor had experienced a cybersecurity incident whereby a third-party gained unauthorized access to sensitive personal information of certain of the Company’s customers. The Company is one of a number of organizations that have been affected by this vendor’s cybersecurity incident.
A third-party vendor experienced a cybersecurity breach that exposed sensitive personal information of some Orrstown customers. The company emphasizes its own systems were not compromised, there is no current indication of data misuse, and affected customers will receive credit monitoring. Orrstown states the incident is not expected to materially impact operations or financial results.
Show 1 minor / wording change
Added in current filing · verify on EDGAR →
Based on the Company’s investigation to date, the Company’s information systems and networks have not been accessed, compromised or affected by the incident. ... The vendor has informed the Company that there is currently no indication that the Company’s customer information has been misused. ... The incident has not had and is not expected to have a material impact on the Company’s operations, and the Company does not currently anticipate that this incident will have a material impact on its financial condition or results of operations.
The company's own systems remain secure and uncompromised. While customer data was accessed at the vendor level, there is no evidence of misuse to date. Management does not expect material financial or operational impact, though the filing acknowledges potential legal, reputational, and regulatory risks.
Thanks — your feedback helps us improve report quality.
Figures/quotes linked to EDGAR · Narrative written by AI · Jun 21, 2026 · How we verify