Heritage Bank, which operates in Washington, Oregon, and Idaho, detected unauthorized access to an internal employee file share server on March 1, 2026. The bank disclosed this incident, which may have exposed sensitive personal information of an unknown number of employees and customers. Customer accounts, systems, and operations were not impacted.
The confirmed data types exposed include names, social security numbers (SSNs), individual taxpayer identification numbers (ITINs), dates of birth, addresses, financial account numbers, and possibly government IDs or other confidential data. The exact number of affected individuals has not been disclosed, and specific details about any medical information involved remain unclear. The bank reported the incident to the SEC and banking regulators on March 20, 2026, and began sending notification letters to affected individuals around the same time.
Details can emerge later as investigations continue, and notices may be delayed.