Breach taxonomy
Summary
Orrstown Financial Services received notice on May 21, 2026 from a third-party vendor that the vendor experienced a cybersecurity incident in which a third party gained unauthorized access to sensitive personal information of certain Orrstown customers. Orrstown is one of a number of organizations affected by the vendor's incident. The company's own systems were not accessed or affected, no misuse of customer information has been indicated, and impacted customers are being offered credit monitoring. Filed under Item 8.01; company does not expect a material impact.
Tagging rationale
ThreatUnknown
Filing refers only to 'a third-party [that] gained unauthorized access' with no attribution -> UNKNOWN.
MethodsData ExfilSupply Chain
Breach occurred at an unnamed third-party vendor affecting multiple organizations -> DATA-EXFIL + SUPPLY-CHAIN.