Business Context and Reporting Period
This Form 8-K was filed by PCB Bancorp on October 7, 2021. The report serves as a Regulation FD disclosure updating a previous announcement regarding a cybersecurity incident affecting Pacific City Bank, the Company's wholly owned banking subsidiary.
Key Financial Metrics
The filing text does not provide specific values for revenue, profit, cash flow, margins, debt, or liquidity. This report focuses exclusively on a material event regarding data security rather than financial performance metrics.
Material Changes and Incident Details
- Incident Timeline: Unusual network activity was identified on August 30, 2021. On September 7, 2021, the Company confirmed an external actor accessed or acquired certain data.
- Scope of Breach: The incident impacted files containing customer information, including personal data such as names, addresses, social security numbers, tax withholdings, and Form W-2 information for customers and their employees.
- Response Actions: The Company disabled the activity, engaged third-party forensic investigators, notified law enforcement, and is notifying all identified impacted individuals.
- Remediation: Free Equifax Complete Premier credit monitoring and identity theft protection services are being offered to all impacted individuals.
Outlook, Risks, and Management Commentary
Management expressed sincere apologies for the incident and the resulting concerns. The filing highlights significant risks associated with the event, including:
- Legal, reputational, and financial risks resulting from the cybersecurity incident.
- Uncertainty regarding the full scope of data accessed and the ability to fully remedy the incident.
- Broader risks related to data loss, security breaches, and the general economic uncertainty caused by the COVID-19 pandemic.
Forward-looking statements in the report are subject to these risks and uncertainties, and actual results may differ materially from expectations.
Investor Verification Checklist
- Verify the total number of individuals notified and the specific categories of data compromised.
- Monitor for updates on the forensic investigation's conclusion regarding the full scope of the breach.
- Assess potential legal liabilities, regulatory fines, and litigation costs arising from the incident.
- Review future filings for any material financial impact or changes in cybersecurity insurance coverage.