FEDERALItem 8.01 · voluntaryHackingData ExfiltratedPIILowActive
Heritage Financial Corporation
bd_d74d56aac9509413 · schema v1 · pii pii-v1
Full breach record for Heritage Financial Corporation →Heritage Financial Corporation (CIK 0001046025) filed an 8-K on March 20, 2026, reporting a cybersecurity incident detected on March 2, 2026. The incident involved unauthorized access to an internal file share server and subsequent exfiltration of files potentially containing personal information. Customer accounts and operations were not impacted. The company took the system offline, engaged forensic investigators and legal counsel, and notified regulators and law enforcement. The company stated the incident was not material.
SEC clockMateriality determined Mar 20, 2026 → Filed Mar 23, 20263d ✓ SEC 4-day OK21 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1046025/000162828026020261/hfwa-20260320.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 23, 2026
- Raw hash
- 4108760495d402a98723153fa644527c685f8479d7bfdf66e79a5a3488a07b4c
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Heritage Financial Corporationnorm: heritage financial
- SEC CIK
- 0001046025
Victim entity
- Name
- Heritage Financial Corporationnorm: heritage financial
- SEC CIK
- 0001046025
Incident
- Discovered
- Mar 2, 2026
- Materiality determined
- Mar 20, 2026
- Notification sent
- Mar 20, 2026
- Affected individuals
- Not disclosed
- Data types
- PII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 ChannelT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- notified its banking regulatorsnotified law enforcement
Compliance
- Time to disclose
- 21 days(21 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 3d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Mar 20, 2026→ Filed: Mar 23, 20263d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.