Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICCREDENTIALSLowContained
South Bay Credit Union
bd_08a74b1806c29f8f · schema v1 · pii pii-v1
Full breach record for South Bay Credit Union →South Bay Credit Union notified consumers of a data breach involving unauthorized access to an employee email account. The incident, discovered on November 18, 2024, likely resulted from phishing. Affected data includes names and other personal information. The credit union secured the account, engaged third-party investigators, and offered credit monitoring services.
Vermont clock✗ VT AG >45 bday25 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_99daa838a9f34a3dIndiana State AGfiled 2025-05-13(1d gap)Verified
- bd_be8aa70e9935fd48California State AGfiled 2025-05-13(1d gap)Candidate
- bd_d3138b4a5b9dfc1eMaine State AGfiled 2025-05-13(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-05-14-south-bay-credit-union-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 14, 2025
- Raw hash
- c06f770120b7658f787a14ed7958803ba4a3f10d860204f926618118364ff9fd
Reporting entity
- Name
- South Bay Credit Unionnorm: south bay credit union
- Domain
- southbaycu.com
Victim entity
- Name
- South Bay Credit Unionnorm: south bay credit union
- Domain
- southbaycu.com
Incident
- Discovered
- Nov 18, 2024
- Materiality determined
- —
- Notification sent
- May 13, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 25 weeks(177 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.