Filer
JEWETT CAMERON TRADING CO LTD (JCTC)
CIK
0000885307
Accession
0001079973-25-001631
Filed
2025-10-21
Records
not stated
Attacker
unstated
EDGAR
https://www.sec.gov/Archives/edgar/data/885307/000107997325001631/jctc_8k.htm

Narrative (as filed)

On October 15, 2025, Jewett-Cameron Trading Co. Ltd. (the “Company”) learned that a threat actor had gained unauthorized access to portions of the Company’s information technology (“IT”) environment and claimed to have unlawfully accessed certain Company information and data. The Company immediately activated its cyber incident response process to contain the intrusion, assess and investigate the incident and implement remedial measures. The Company also immediately notified law enforcement and retained external cybersecurity experts to assist. Based on its investigation to date, the Company believes that the cybersecurity incident consisted of unauthorized access and deployment of encryption and monitoring software by a third party to a portion of the Company’s internal corporate IT systems. The incident caused disruptions and limitation of access to portions of the Company’s business applications supporting aspects of the Company’s operations and corporate functions, which the Company voluntarily took offline as a precautionary measure. Based on the information reviewed to date, the Company believes the unauthorized activity has been contained and is working diligently to bring the impacted portions of its IT systems and individual computer devices back online.   Although the Company ascertained that certain information was exfiltrated, it is still investigating the extent of compromise of any sensitive information contained within the accessed IT systems. However, it is believed that the threat actors unlawfully accessed certain computer systems and exfiltrated images of video meetings and computer screens that may contain sensitive Company information. The threat actors have threatened to release this information publicly if the Company does not provide them with a monetary payment. The Company has taken additional cybersecurity measures in response to this incident including closing off the point of unlawful access and bolstering its cyber defensive capabilities. The Company believes that the costs associated with these activities will be largely covered by the Company’s cyber security insurance policy. However, due to the extended period that the Company has been and may continue to be offline, operations may be materially impacted, which may also impact the Company’s financial results for the first quarter of fiscal 2026.   Current analysis indicates that the data exfiltrated primarily relates to IT related information and financial information the Company has been gathering and analyzing over the past few weeks in preparation of filing with the Securities and Exchange Commission its Annual Report on Form 10-K for the fiscal year ended August 31, 2025, which the Company expects to release in mid-November.   As the investigation of the incident is ongoing, the full scope, nature and impact of the incident are not yet completely known. We have no current evidence that any personally identifiable information of any employees, customers, suppliers or vendors has been compromised, but our analysis and review of the potential compromised systems and data continues. The Company is bringing systems and devices online in a thoughtful and methodical manner in coordination with our cybersecurity experts and the ongoing investigation and expects to be at full operational capability shortly.   Cautionary Language Concerning Forward-Looking Statements   Information set forth herein contains financial estimates and other forward-looking statements that are subject to risks and uncertainties, and actual results might differ materially. A discussion of factors that may affect future results is contained in the Company’s filings with the Securities and Exchange Commission. The Company disclaims any obligation to update and revise statements contained herein based on new information or otherwise, except as required by law.

Reproduced verbatim from the filer's 8-K narrative. Source linked above; verify before relying on this for legal or incident-response work.