Skip to main content
Back to overview
High

SR Bancorp's Internal Audit Provider, Mercadien, Experiences Data Security Incident

Mercadien, P.C.

Key points

  • Unauthorized actor accessed files on Mercadien's servers.
  • Compromised data includes names, Social Security numbers, account numbers, identification documents, and dates of birth of Somerset Regal Bank customers.
  • SR Bancorp's internal systems were not impacted.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Confidentiality impact

Threat source not confirmed

03

Potential impact

Potential data exposure

Confidentiality

Published
Jul 10, 2026
Updated
Jul 27, 2026
Confidence
High
Evidence
5 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch exposure paths that could affect data, operations or third-party trust.

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

MercadienData DisclosureSR BancorpInternal Audit ProviderMercadienP.C. CPAsSR Bancorp and Somerset RegalBankSomerset Regal Bank. TheImportantly

Quick context

Questions about this signal

What happened in this signal?

Mercadien, P.C. CPAs, an internal audit service provider for SR Bancorp and Somerset Regal Bank, reported a data security incident on July 10, 2026. An unauthorized actor accessed and acquired files from Mercadien's servers containing sensitive customer data belonging to Somerset Regal Bank. The compromised data included customer names, Social Security numbers, account numbers, identification documents, and dates of birth. Importantly, SR Bancorp confirmed that its own business systems, payment systems, customer access to accounts, and core information technology infrastructure were not affected by the incident. The bank is coordinating with Mercadien to provide notifications to affected customers as required by federal and state laws and regulatory guidance. While the incident exposes customers to potential identity theft and fraud, SR Bancorp currently assesses the financial impact as immaterial to its consolidated financial condition or results of operations. This incident highlights the significant risks associated with third-party vendors handling sensitive customer information.

When was this signal reported?

Shadow Tier lists Jul 10, 2026 as the signal date.

Which organization is connected to this signal?

Mercadien is the organization connected to this public signal.

Explore Mercadien