Open report — full analysis, no account required.

Sign up to generate reports and read filings that aren't on the open list.

Sign up free

Get notified when SRBK files again. Create a free account and we'll email you the moment its next filing is analyzed.

Get filing alerts
NASDAQ: SRBK SR Bancorp, Inc. 8-K

SR Bancorp discloses vendor data breach exposing customer SSNs and account numbers

Filed July 10, 2026 · Period ending July 10, 2026 · ~1 min read

3 key changes 1 high relevance 1 section

Key Changes

  • high

    Internal audit vendor Mercadien suffered unauthorized access to files containing customer names, SSNs, account numbers, ID documents, and dates of birth for certain bank customers.

  • medium

    The breach occurred on Mercadien's servers; Somerset Regal Bank's own systems, operations, payment infrastructure, and customer account access were not impacted.

  • medium

    Management does not expect a material impact on consolidated financial condition or results, though forward-looking statements acknowledge potential legal, regulatory, and reputational risks.

Summary

SR Bancorp disclosed that Mercadien, its internal audit services vendor, experienced a data security incident in which an unauthorized actor accessed files containing sensitive customer information including social security numbers, account numbers, identification documents, and dates of birth. The breach occurred on Mercadien's servers, not the bank's own infrastructure.

Somerset Regal Bank's business systems, operations, customer account access, payment systems, and core IT infrastructure were not involved or impacted. Customer notifications are being provided through Mercadien as required by law.

While management states the incident is not expected to materially affect the company's financial condition or results, the exposure of SSNs and account data creates identity theft and fraud risks for affected customers. The company's forward-looking statements acknowledge potential legal, regulatory, reputational, and financial risks that could emerge from the incident. Retail holders should monitor for any regulatory actions, customer litigation, or remediation costs that may arise, as well as any updates on the number of customers affected and the scope of the compromised data.

Section-by-Section Diff

Event · Item 8.01 — Other Events

~500 words

Item 8.01 — Other Events filed; see Key Changes for terms.

2 Added
Added Data security incident at vendor high

Added in current filing · verify on EDGAR →

Mercadien, P.C. CPAs (“Mercadien”), which provides internal audit-related services to SR Bancorp, Inc (the “Company”) and Somerset Regal Bank (the “Bank”), has discovered a data security incident in which an unauthorized actor accessed and acquired certain files on Mercadien’s computer servers, which included certain Bank customer data.

The company's internal audit vendor Mercadien experienced a data breach where an unauthorized actor accessed files containing customer data. The breach occurred on Mercadien's systems, not the bank's own infrastructure. Customer notifications are being provided through Mercadien as required by law.

Added Customer data compromised high

Added in current filing · verify on EDGAR →

The information that Mercadien had on its computer servers included the name, social security number, account numbers, identification documents and/or date of birth for certain Bank customers.

The compromised data includes highly sensitive personal information: names, social security numbers, account numbers, identification documents, and dates of birth for certain bank customers. This type of data exposure creates identity theft and fraud risks for affected customers.

Was this report useful?

Figures/quotes linked to EDGAR · Narrative written by AI · Jul 13, 2026 · How we verify