Breach taxonomy
Summary
On or about March 2, 2026, Heritage Financial Corporation detected unauthorized access to an internal file share server used by employees, with files potentially containing personal information exfiltrated. Customer accounts and bank operations were not impacted. The company initiated its security incident response plan, took the affected system offline, and engaged an independent forensic investigation firm. Banking regulators, law enforcement, and the cyber insurance carrier were notified; as of the filing date the company has not determined the incident to be material. Filed under Item 8.01; materiality not yet determined as of filing date.
Tagging rationale
ThreatUnknown
Filing does not attribute the incident to a specific actor → UNKNOWN.
MethodsData Exfil
Filing describes 'exfiltration of files from that file share server' — deliberate data theft by an unauthorized party with no mention of ransomware or malware → DATA-EXFIL.