Sound Financial Bancorp, Inc.
ent_142d1a8d09ab86418ec97112
Disclosures
2
SEC 10-K Item 1C · SEC 8-K · 1 jurisdiction
Incidents
1
filings grouped by incident
Max affected reported
16,000
as filed · SEC 8-K FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Sound Financial Bancorp, Inc.
- Normalized
- sound financial bancorp— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-03-18
Sound Financial Bancorp, Inc. filed Item 1C of Form 10-K disclosing its cybersecurity risk management program. The filing explicitly states that the company has not identified significant compromises, substantial data losses, or major financial setbacks from cybersecurity attacks. The document describes governance, NIST framework adherence, and third-party risk management, but reports no specific breach incident.
- FEDERALSEC 8-Kas reporting2023-07-14
Sound Financial Bancorp disclosed that its subsidiary Sound Community Bank was affected by the MOVEit Transfer zero-day vulnerability (Progress Software) via a third-party vendor providing account hosting and transaction processing. The vendor used MOVEit to transfer data on approximately 16,000 of the Bank's mobile and online banking customers. Vendor forensics indicate the data was downloaded once during a valid transfer; investigation ongoing. Law enforcement and banking regulators notified.