Page last updated on October 21, 2025
JEWETT CAMERON TRADING CO LTD initially disclosed a cybersecurity incident in an SEC 8-K filing on 2025-10-21 17:26:14 EDT.
Company Summary
Jewett-Cameron Trading Company Ltd. manufactures and distributes pet, fencing, and industrial wood products under various brands, serving retail and industrial customers across North America and globally from its headquarters in North Plains, Oregon.
Incident Details
Material: Yes
Is Breach: Yes
Records Compromised: Unknown
Data Types Impacted: Other, Unspecified
Compromised Date: Unknown
Detected Date: 2025-10-15
Disclosure Date: 2025-10-21
Contained Date: Unknown
Recovered Date: Unknown
Attack Goal: Unknown
Attack Tactics1: TA0010, TA0040
Attack Techniques1: T1486, T1041, OTHER
Costs: Not Tracked (yet)
- Incident response (Indirect): Not Tracked (yet)
- Third-party costs (Indirect): Not Tracked (yet)
Filings
8-K filed on 2025-10-21
JEWETT CAMERON TRADING CO LTD filed an 8-K at 2025-10-21 17:26:14 EDT
Accession Number: 0001079973-25-001631
Item 1.05 Material Cybersecurity Incidents.
On October 15, 2025, Jewett-Cameron Trading Co. Ltd. (the "Company") learned that a threat actor had gained unauthorized access to portions of the Company's information technology ("IT") environment and claimed to have unlawfully accessed certain Company information and data. The Company immediately activated its cyber incident response process to contain the intrusion, assess and investigate the incident and implement remedial measures. The Company also immediately notified law enforcement and retained external cybersecurity experts to assist. Based on its investigation to date, the Company believes that the cybersecurity incident consisted of unauthorized access and deployment of encryption and monitoring software by a third party to a portion of the Company's internal corporate IT systems. The incident caused disruptions and limitation of access to portions of the Company's business applications supporting aspects of the Company's operations and corporate functions, which the Company voluntarily took offline as a precautionary measure. Based on the information reviewed to date, the Company believes the unauthorized activity has been contained and is working diligently to bring the impacted portions of its IT systems and individual computer devices back online.
Although the Company ascertained that certain information was exfiltrated, it is still investigating the extent of compromise of any sensitive information contained within the accessed IT systems. However, it is believed that the threat actors unlawfully accessed certain computer systems and exfiltrated images of video meetings and computer screens that may contain sensitive Company information. The threat actors have threatened to release this information publicly if the Company does not provide them with a monetary payment. The Company has taken additional cybersecurity measures in response to this incident including closing off the point of unlawful access and bolstering its cyber defensive capabilities. The Company believes that the costs associated with these activities will be largely covered by the Company's cyber security insurance policy. However, due to the extended period that the Company has been and may continue to be offline, operations may be materially impacted, which may also impact the Company's financial results for the first quarter of fiscal 2026.
Current analysis indicates that the data exfiltrated primarily relates to IT related information and financial information the Company has been gathering and analyzing over the past few weeks in preparation of filing with the Securities and Exchange Commission its Annual Report on Form 10-K for the fiscal year ended August 31, 2025, which the Company expects to release in mid-November.
As the investigation of the incident is ongoing, the full scope, nature and impact of the incident are not yet completely known. We have no current evidence that any personally identifiable information of any employees, customers, suppliers or vendors has been compromised, but our analysis and review of the potential compromised systems and data continues. The Company is bringing systems and devices online in a thoughtful and methodical manner in coordination with our cybersecurity experts and the ongoing investigation and expects to be at full operational capability shortly.
Company Information
Name | JEWETT CAMERON TRADING CO LTD |
CIK | 0000885307 |
SIC Description | Retail-Lumber & Other Building Materials Dealers |
Ticker | JCTC - Nasdaq |
Website | |
Category | Non-accelerated filer Smaller reporting company |
Fiscal Year End | August 30 |