HackingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
CONNEX CREDIT UNION
bd_11cb4d7ecd0a90f9 · schema v1 · pii pii-v1
Full breach record for CONNEX CREDIT UNION →Connex Credit Union notified South Carolina residents of a data security incident occurring June 2-3, 2025. Unauthorized access to files containing names, account numbers, SSNs, and government IDs was detected. The credit union engaged independent experts, enhanced network security, and notified federal law enforcement and the NCUA. Complimentary credit monitoring is offered.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_383732811c88e6d5Texas State AGfiled 2025-08-08Verified
- bd_975123fa51efd59cMaine State AGfiled 2025-08-08Verified
- bd_14a6428040752acaIndiana State AGfiled 2025-08-07(1d gap)Verified
- bd_2d7ba7fcb1ed3162California State AGfiled 2025-08-07(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- bd_b671a1b2a1a142f4Vermont State AGfiled 2025-08-07(1d gap)Verified
- bd_beda1a58d91c700cMontana State AGfiled 2025-08-07(1d gap)Candidate
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2025/Connex%20-%20Consumer%20Letter.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 8, 2025
- Raw hash
- 924563ab060dee12072b5fd94c8a3b6c960ccb5315e348899b44d38928944489
Reporting entity
- Name
- CONNEX CREDIT UNIONnorm: connex credit union
- Domain
- connexcu.org
- Industry
- financial_services
Victim entity
- Name
- CONNEX CREDIT UNIONnorm: connex credit union
- Domain
- connexcu.org
- Industry
- financial_services
Incident
- Discovered
- Jun 3, 2025
- Materiality determined
- —
- Notification sent
- Aug 6, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the National Credit Union AdministrationNotified federal law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(66 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.