Manchester Credit Union
bd_2c8e6b603befa31a · schema v1 · pii pii-v1
Full breach record for Manchester Credit Union →Press / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage — verify against the source.
Attention. Manchester Credit Union: On April 17, a cyberattack against Manchester Credit Union was claimed on the showcase site of the ransomware brand Sarcoma. On April 3, the financial institution stated it was experiencing "current technical difficulties affecting incoming payments." Users simultaneously reported being unable to access their online banking accounts, and the institution was unreachable by phone or email. Linked ransomware group: sarcoma.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Apr 3, 2025
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitesarcomabd_8e002eb5e13d716b2025-04-17 · +14dCandidate
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
sarcoma
According to ransomware.live, Sarcoma is a ransomware group that debuted in October 2024, immediately ranking among the top three most active groups globally and surpassing 116 documented victims by mid-2025, targeting mid-market companies across manufacturing, retail, healthcare, legal, and business services with roughly 50% of victims in the United States.