Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Gain
bd_1e7fc70fc5473319 · schema v1 · pii pii-v1
Full breach record for Gain →Gain FCU notified the New Hampshire Attorney General of a data security incident affecting two New Hampshire residents. The breach involved unauthorized access to a single user's email account, potentially exposing names, addresses, account numbers, and loan/financial information. The incident was discovered on October 20, 2025, and confirmed via investigation on January 22, 2026. Gain FCU engaged forensic investigators and legal counsel, and is notifying affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/gain-fcu-20260204.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 4, 2026
- Raw hash
- 5f391db75779e2b4d7801e745fc9af2168397180c6cdf66e30e54be6fc71ba63
Reporting entity
- Name
- Gain FCUnorm: gain fcu
Victim entity
- Name
- Gainnorm: gain
- Domain
- manage.gainapp.com
Incident
- Discovered
- Oct 20, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 2
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 15 weeks(107 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.