HackingFinancial ServicesFinanceSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
1ST MIDAMERICA CREDIT UNION
bd_275f4715bec7cc1d · schema v1 · pii pii-v1
Full breach record for 1ST MIDAMERICA CREDIT UNION →On Aug 14, 2025, vendor Marquis Software Solutions suffered an unauthorized third-party intrusion affecting files containing MACU customer data. Names and Social Security Numbers of 131,070 individuals (7 Maine residents) were potentially accessed. MACU confirmed Maine resident exposure Nov 24, 2025. Letters mailed Jan 22, 2026. Epiq providing 24-month credit monitoring. Marquis enhanced security controls post-incident.
Maine clockDiscovered Aug 14, 2025 → Filed with AG Jan 30, 2026169d ✗ ME AG >90d24 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_d41974d707bdedf7Vermont State AGfiled 2026-01-30Verified
- bd_30a6ecedbb016c46Texas State AGfiled 2026-02-02(3d gap)Verified
- bd_4a0e035dbcce10e1New Hampshire State AGfiled 2026-02-02(3d gap)Verified
- bd_76d756860b4047a3Indiana State AGfiled 2026-01-22(8d gap)Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/a673f5bb-a5a8-4406-b516-a851f5b0b0e2.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 30, 2026
- Raw hash
- e6d6eb85c390459188688e56c933e161e52c546d75e6eff787d6ebc902895a8f
Reporting entity
- Name
- 1ST MIDAMERICA CREDIT UNIONnorm: 1st midamerica credit union
- Industry
- Financial Services
Victim entity
- Name
- 1ST MIDAMERICA CREDIT UNIONnorm: 1st midamerica credit union
- Industry
- Financial Services
- Industry
- Financial Servicesllm
Incident
- Discovered
- Aug 14, 2025
- Materiality determined
- Nov 24, 2025
- Notification sent
- Jan 22, 2026
- Affected individuals
- 7
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notice submitted to Maine Office of Attorney General on January 30, 2026Reported to Experian, Equifax, and TransUnion credit reporting agencies
- Third party
- via Marquis Software Solutions
- Initial access
- supply_chain
Compliance
- Time to disclose
- 24 weeks(169 days from discovery to filing)
- Compliance flags
- ME AG >90d · 169dME resident >60d · 161d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Aug 14, 2025→ Filed with AG: Jan 30, 2026169d 90 days ME AG >90d Maine Discovered: Aug 14, 2025→ Notified: Jan 22, 2026161d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.