FEDERALItem 1.05 · mandatoryThird-Party / Supply ChainFinancial ServicesFinanceSupply Chain (3P Vendor)Customer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
BayFirst National Bank
bd_87c2682fd28511f5 · schema v1 · pii pii-v1
Full breach record for BayFirst National Bank →BayFirst National Bank, a subsidiary of BayFirst Financial Corp., disclosed in a Form 8-K Item 1.05 that on August 14, 2025 it was notified of a cybersecurity incident at a third-party marketing services provider. On October 28, 2025, the provider confirmed that personal information of some BayFirst customers — including names, dates of birth, and Social Security/tax identification numbers — was accessed without authorization. The incident was limited to the third-party provider's environment. Financial impact has not been quantified.
SEC clockMateriality determined Oct 28, 2025 → Filed Oct 30, 20252d ✓ SEC 4-day OK11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1649739/000164973925000246/bafn-20251028.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 30, 2025
- Raw hash
- 3382896502729cb75cdd81d6ffb33f841ea15a53228883525f1c1bd4754e0a8d
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- BayFirst Financial Corp.norm: bayfirst financial
- SEC CIK
- 0001649739
- Domain
- bayfirstfinancial.com
Victim entity
- Name
- BayFirst National Banknorm: bayfirst national bank
- Domain
- bayfirstfinancial.com
- Industry
- Financial Servicesllm
Incident
- Discovered
- Aug 14, 2025
- Materiality determined
- Oct 28, 2025
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- Threat actor
- External
- Regulator citations
- Third-party provider notified law enforcement
- Initial access
- supply_chain
Compliance
- Time to disclose
- 11 weeks(77 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 2d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Oct 28, 2025→ Filed: Oct 30, 20252d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.