Business Context and Reporting Period
Company: Heritage Financial Corporation (HFWA)
Filing Type: Form 8-K (Current Report)
Date of Report: March 20, 2026
Event Date: On or about March 2, 2026
Context: The Company reported a cybersecurity incident involving an internal file share server used by employees.
Key Financial Metrics
The filing does not provide specific revenue, profit, cash flow, margin, debt, or liquidity figures. This report focuses on a specific event rather than periodic financial results.
Material Changes and Event Details
- Incident Nature: Unauthorized exfiltration of files from an internal file share server potentially containing personal information.
- Operational Impact: No disruption to operations; customer accounts, systems, and operations were not impacted.
- Response Actions: The affected system was taken offline; the security incident response plan was initiated.
- Investigation: External advisors, including an independent forensic firm and legal counsel, have been engaged.
- Notifications: Banking regulators, law enforcement, and the cyber insurance carrier have been notified.
- Materiality Assessment: As of the filing date, the Company has not determined the incident to be material to its financial condition or results of operations.
Guidance, Outlook, and Risks
Management Commentary: Management states that operations continue in the ordinary course. The investigation is ongoing, and the final financial and operational impact remains uncertain.
Risks and Contingencies:
- Forward-looking statements regarding insurance coverage and impact assessments are subject to risks and uncertainties.
- Actual results may differ materially from current expectations due to the inherent challenges of assessing cyber incidents.
- The financial impact could be more severe than currently anticipated.
Key Facts for Investor Verification
- Verify the scope of data exfiltration once the forensic investigation concludes.
- Monitor future filings for updates on the materiality determination of the incident.
- Review the extent of cyber insurance coverage applicable to this specific incident.
- Check for any regulatory penalties or enforcement actions resulting from the notification to banking regulators.