Business Context and Reporting Period
This Form 8-K is filed by TRIO-TECH INTERNATIONAL (NYSE American: TRT), a California corporation with principal executive offices in Singapore. The report date is March 18, 2026, covering a material cybersecurity incident that escalated on this date following an initial discovery on March 11, 2026.
Key Financial Metrics
The filing does not provide specific financial metrics such as revenue, profit, cash flow, margins, debt, or liquidity figures. The document focuses exclusively on the status of a cybersecurity event. Management states that as of the filing date, the incident has not resulted in any material disruption to operations or the Company's business.
Material Changes and Incident Details
- Incident Type: Ransomware attack affecting a subsidiary in Singapore.
- Timeline:
- March 11, 2026: Incident identified; files encrypted. Initially deemed not material.
- March 18, 2026: Incident escalated due to unauthorized disclosure of certain Company data. Management concluded the event may now constitute a material cybersecurity event.
- Response Actions: The subsidiary took its network offline, engaged third-party cybersecurity professionals, notified Singapore law enforcement, and activated cyber insurance protocols.
- Current Status: The investigation is ongoing. The full scope of affected data has not been determined. Affected parties are being notified as required by law.
Outlook, Risks, and Management Commentary
Management does not expect the incident to have a material impact on the Company's financial results or operations for the three months ended March 31, 2026. However, the filing includes a Safe Harbor Statement noting that forward-looking statements are subject to uncertainties, including the possibility that containment and remediation efforts may be unsuccessful. The full scope and impact remain unknown and could result in a future determination of materiality to financial statements.
Investor Verification Checklist
- Verify the final scope of data disclosed and the specific types of information compromised.
- Monitor for updates on regulatory fines or penalties from Singaporean authorities.
- Track the status of cyber insurance claims and potential out-of-pocket remediation costs.
- Review future quarterly reports for any material adjustments to financial results attributed to this incident.
- Confirm the timeline for full restoration of affected systems and network operations.