HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Metrowest Community Federal Credit Union
bd_27bfc3acf10562e3 · schema v1 · pii pii-v1
Full breach record for Metrowest Community Federal Credit Union →MetroWest Community Federal Credit Union notified consumers of a cybersecurity incident where unauthorized access to certain systems occurred on September 3, 2025. The incident resulted in the copying of files containing names and government identifiers (e.g., SSN). MetroWest engaged forensic specialists, notified the FBI, and is offering 24 months of credit monitoring and identity protection services through Experian to affected individuals.
Vermont clock✗ VT AG >45 bday27 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by akira about this victim predates this filing by 132 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_116f45d168299bc0Leak Siteakirafiled 2025-10-25(132d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_0c962b2c99ddb824Indiana State AGfiled 2026-03-10(4d gap)Verified by operator
- bd_3778ce4cf42cd676Maine State AGfiled 2026-03-10(4d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-03-06-metrowest-community-federal-credit-union-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 6, 2026
- Raw hash
- e96c17a3e5fcde3f543e0813f367f766aa7d80ccb76c39127de4432c05e31782
Reporting entity
- Name
- Metrowest Community Federal Credit Unionnorm: metrowest community federal credit union
- Domain
- mwcfcu.com
Victim entity
- Name
- Metrowest Community Federal Credit Unionnorm: metrowest community federal credit union
- Domain
- mwcfcu.com
Incident
- Discovered
- Sep 1, 2025
- Materiality determined
- —
- Notification sent
- Mar 10, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- reported the event to the Federal Bureau of Investigation
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 27 weeks(186 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.