Skip to main content
Back to overview
High

SR Bancorp Discloses Data Security Incident at Internal Audit Provider Mercadien, Exposing Somerset Regal Bank Customer Data

SR Bancorp, Inc.

Key points

  • Unauthorized actor accessed files on Mercadien's servers.
  • Compromised data includes names, Social Security numbers, account numbers, identification documents, and dates of birth of Somerset Regal Bank customers.
  • SR Bancorp's own systems were not impacted, and operations were not disrupted.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Confidentiality impact

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality

Published
Jul 10, 2026
Updated
Jul 26, 2026
Confidence
High
Evidence
5 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch exposure paths that could affect data, operations or third-party trust.

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

SrbancorpData DisclosureInternal Audit Provider MercadienExposing Somerset Regal Bank CustomerIncMercadienP.C. CPAs. AnSomerset Regal Bank. TheImportantlySR Bancorp

Quick context

Questions about this signal

What happened in this signal?

SR Bancorp, Inc. reported a data security incident on July 10, 2026, involving its internal audit service provider, Mercadien, P.C. CPAs. An unauthorized actor accessed and acquired files from Mercadien's servers that contained sensitive customer data belonging to Somerset Regal Bank. The compromised information included customer names, Social Security numbers, account numbers, identification documents, and dates of birth. Importantly, SR Bancorp confirmed that the bank's own business systems, payment systems, customer access to accounts, and core information technology infrastructure were not directly impacted or disrupted by this incident. The company is coordinating customer notifications through Mercadien as required by applicable federal and state laws and regulatory guidance. While the incident exposes SR Bancorp to regulatory notification requirements, reputational risk, and potential legal liability, the company has initially assessed the financial impact as immaterial to its consolidated financial condition or results of operations. However, this assessment could change if the data is published or misused, or if further cybersecurity incidents occur. This event highlights the inherent risks associated with third-party vendors handling sensitive customer information.

When was this signal reported?

Shadow Tier lists Jul 10, 2026 as the signal date.

Which organization is connected to this signal?

Srbancorp is the organization connected to this public signal.

Explore Srbancorp
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence
Which sector context is relevant?

This signal is connected to current banking cyber incidents.

Explore current banking cyber incidents