---
schema_version: "secwatch.filing_event.v1"
accession: "0000927089-23-000102"
form_type: "8-K"
ticker: "SFBC"
cik: "0001541119"
company_name: "Sound Financial Bancorp, Inc."
filed_at: "2023-07-14T23:59:59+00:00"
generated_at: "2026-06-13T08:10:33.322213+00:00"
event_type: "cyber"
sentiment: "neutral"
materiality_score: 0.45
calibrated_materiality_score: 0.45
confidence: "high"
source: SEC EDGAR
---

# Sound Financial subsidiary vendor exposed ~16,000 customer records via MOVEit; no compromise found yet

## Summary
- Third-party vendor using MOVEit transferred data for Sound Community Bank's ~16,000 mobile/online banking customers.
- Vendor's forensic investigation shows customer data was downloaded only once via a valid bank file request; no indication of compromise to date.
- Bank notified law enforcement and regulators; vendor has patched the MOVEit vulnerability.
- Company expects the incident will not have a material adverse effect on business, operations, or financial results.

## SEC filing metadata
- accession: 0000927089-23-000102
- form_type: 8-K
- ticker: SFBC
- cik: 0001541119
- company_name: Sound Financial Bancorp, Inc.
- filed_at: 2023-07-14T23:59:59+00:00
- event_type: cyber
- sentiment: neutral
- materiality_score: 0.45
- calibrated_materiality_score: 0.45
- confidence: high
- sec_items: 8.01
- EDGAR index: https://www.sec.gov/Archives/edgar/data/1541119/000092708923000102/0000927089-23-000102-index.htm
- EDGAR primary document: https://www.sec.gov/Archives/edgar/data/1541119/000092708923000102/sfbc20230713_8k.htm

## Machine-readable alternates
- HTML: https://secwatch.observer/filing/0000927089-23-000102
- JSON: https://secwatch.observer/filing/0000927089-23-000102.json
- Plain text: https://secwatch.observer/filing/0000927089-23-000102.txt

This AI-assisted summary is a reading aid. Review the linked SEC EDGAR filing before relying on any specific claim.
