Business Context and Reporting Period
Company: CB Financial Services, Inc. (CBFV)
Filing Type: Form 8-K (Current Report)
Date of Report: May 7, 2026
Reporting Period: Event occurred on May 5, 2026; Report signed May 11, 2026.
Business Context: The Company is a financial holding company with a wholly-owned subsidiary, Community Bank. This filing discloses a material cybersecurity incident involving the unauthorized use of AI software to handle non-public customer information.
Key Financial Metrics
The filing does not provide specific financial data such as revenue, profit, cash flow, margins, debt, or liquidity figures. The document focuses exclusively on the disclosure of a cybersecurity event.
Material Changes
Cybersecurity Incident: On May 5, 2026, the Bank discovered an internal incident where non-public customer information was processed using an unauthorized artificial intelligence-based software application.
Data Compromised: Customer names, Social Security numbers, and dates of birth.
Operational Impact: No disruption to operations, customer account access, payment systems, or core IT infrastructure.
Materiality: The Company determined the event to be material due to the volume and sensitive nature of the disclosed information.
Outlook, Management Commentary, and Risks
- Management Actions: The Bank secured the information, initiated an internal investigation with external cybersecurity advisors, and is notifying affected customers as required by law.
- Regulatory Engagement: The Company is in communication with relevant banking and financial regulators.
- Remediation: Actions are underway to contain and remediate the incident, including strengthening existing controls, implementing additional controls, and enhancing monitoring measures.
- Financial Impact: As of the disclosure date, the incident has not had, and is not expected to have, a material impact on the Company's consolidated financial condition or results of operations.
- Risks: Ongoing investigation into the scope and root cause; potential future costs related to customer notifications and remediation (though currently deemed not materially impactful).
Investor Verification Checklist
- Verify the scope of the investigation and the root cause of the unauthorized AI software usage.
- Monitor future filings for updates on the volume of affected customers and the status of regulatory communications.
- Watch for any subsequent announcements regarding material financial impacts, such as legal settlements, fines, or increased cybersecurity expenditures.
- Confirm the effectiveness of the new controls and monitoring measures implemented to prevent recurrence.