Item 8.01
Other Events
Mercadien, P.C. CPAs (“Mercadien”), which provides internal audit-related services to SR Bancorp, Inc (the “Company”) and Somerset Regal Bank (the “Bank”), has discovered a data security incident¹ in which an unauthorized actor accessed and acquired certain files on Mercadien’s computer servers, which included certain Bank customer data²,³,⁴.
Somerset Regal Bank’s business systems were not involved in or impacted by the incident. The incident did not involve a disruption to the Bank’s operations, customer access to accounts or services, payment systems, or core information technology infrastructure.⁵ The information that Mercadien had on its computer servers included the name, social security number, account numbers, identification documents and/or date of birth for certain Bank customers.⁶
The Bank is providing customer notifications through Mercadien, as required by applicable federal and state laws and regulatory guidance.⁷
The Company remains committed to protecting its customers’ data.
As of the date of this disclosure, this incident has not had, and is not expected to have, a material impact on the Company’s consolidated financial condition or results of operations⁸,⁹.
Forward Looking Statements
This Current Report on Form 8-K contains forward-looking statements within the meaning of the federal securities laws, including, without limitation: the Company’s current beliefs, understanding, and expectations regarding the incident; statements regarding the nature and scope of the incident; the Company’s ongoing assessment of the extent, categories and volume of data that was accessed or exfiltrated; the Company’s ongoing efforts to assess and contain the threat, including the Company’s assessment of whether there is any ongoing unauthorized access to its systems; the availability and adequacy of the Company’s insurance coverage; and the reasonably likely impact of the incident on the Company’s business, operations, financial condition and results of operations. These statements are based on current information, estimates and assumptions and are subject to known and unknown risks and uncertainties. Actual results may differ materially from those expressed or implied by these forward-looking statements. Factors that could cause actual results to differ from those expressed in these forward-looking statements include the ongoing assessment of the incident; the potential publication or misuse of affected data by the threat actor or other parties; legal, regulatory, reputational, and financial risks resulting from the incident or additional cybersecurity incidents; and the risks described in the Company’s Annual Report on Form 10-K for the year ended June 30, 2025 and subsequent Quarterly Reports on Form 10-Q. Except as required by law, the Company undertakes no obligation to update these statements.