HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICPIILowContained
LAFAYETTE FEDERAL CREDIT UNION
bd_025c5df977a8fe6d · schema v1 · pii pii-v1
Full breach record for LAFAYETTE FEDERAL CREDIT UNION →Lafayette Federal Credit Union reported that an unauthorized third party accessed an employee email account on September 16, 2024. The breach potentially exposed personal information, including names and other data elements, of affected members. LFCU secured the account, engaged forensic investigators, and is offering one year of complimentary credit monitoring to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-605396
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 14, 2025
- Raw hash
- ce9f5ef525739ff6485b9dd26c0bf625c6d16760f9ff8ce7d28dceab990e7213
Reporting entity
- Name
- LAFAYETTE FEDERAL CREDIT UNIONnorm: lafayette federal credit union
Victim entity
- Name
- LAFAYETTE FEDERAL CREDIT UNIONnorm: lafayette federal credit union
Incident
- Discovered
- Sep 16, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 43 weeks(301 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.