Business Context and Reporting Period
This Form 8-K is filed by STAR GROUP, L.P. on September 24, 2021, reporting a security incident that occurred on July 17, 2021. The registrant is a Delaware limited partnership with common units trading on the New York Stock Exchange under the symbol SGU.
Key Financial Metrics
The filing text does not provide specific values for revenue, profit, cash flow, margins, debt, or liquidity. This report focuses exclusively on a non-financial operational event.
Material Changes
The material event reported is a cybersecurity incident involving the encryption and/or disabling of certain information technology systems. While the incident affected employee data, the company states that customer personal information was not involved. There were no reported interruptions to customer service or business continuity.
Outlook, Risks, and Management Commentary
- Impact Assessment: Management does not anticipate a material adverse effect on business, operations, or financial results.
- Data Breach Scope: An unauthorized third party accessed or extracted personal and protected health information belonging to employees of one or more operating subsidiaries. Customer data was not compromised.
- Response Actions: The company engaged a data forensics expert, notified law enforcement, and informed affected employees. Security measures are currently being evaluated for strengthening.
- Financial Mitigation: The company maintains insurance coverage for expenses and liabilities related to such incidents and expects to pursue coverage for a significant portion of the costs.
- Risks: The company acknowledges uncertainty regarding the prevention of future cyber-attacks or system failures, which could potentially be material.
Investor Verification Checklist
- Verify the extent of employee data exposure and the specific subsidiaries affected.
- Monitor future filings for updates on the forensic investigation and any regulatory penalties.
- Confirm the actual costs incurred versus the insurance coverage limits for this incident.
- Assess the timeline for the implementation of strengthened information security measures.