Business Context and Reporting Period
Company: CB Financial Services, Inc. (CBFV)
Filing Type: Form 8-K (Current Report)
Date of Report: May 7, 2026
Reporting Entity: The Company and its wholly-owned subsidiary, Community Bank.
Event: Disclosure of a material cybersecurity incident involving unauthorized use of AI software to handle non-public customer information.
Key Financial Metrics
This filing is a current report regarding a specific event and does not contain periodic financial statements. Consequently, the filing text does not provide clear values for revenue, profit, cash flow, margins, debt, or liquidity.
Material Changes and Incident Details
- Incident Date: Discovered on May 5, 2026.
- Cause: Internal incident involving the handling of non-public customer information using an unauthorized artificial intelligence-based software application.
- Data Compromised: Customer names, social security numbers, and dates of birth.
- Operational Impact: No disruption to the Bank's operations, customer access to accounts, payment systems, or core IT infrastructure.
- Materiality: The Company determined the event to be material due to the volume and sensitive nature of the disclosed information.
Management Commentary, Risks, and Outlook
Response Actions: The Bank secured the information, initiated an internal investigation with external cybersecurity advisors, and is notifying affected customers as required by law. The Company is in communication with banking and financial regulators.
Remediation: The Company is strengthening existing controls, implementing additional controls, and enhancing monitoring measures to prevent future incidents.
Financial Impact: As of the date of disclosure, the incident has not had, and is not expected to have, a material impact on the Company's consolidated financial condition or results of operations.
Risks: Ongoing investigation into the scope and root cause; potential regulatory scrutiny; costs associated with customer notification and remediation (though not currently deemed material).
Investor Verification Checklist
- Verify the scope of the investigation and the total number of customers affected.
- Monitor for updates on regulatory communications and potential enforcement actions.
- Review future filings for any changes to the assessment of financial impact regarding remediation costs or legal liabilities.
- Confirm the status of the unauthorized AI software and the effectiveness of new security controls.