HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
CONNEX CREDIT UNION
bd_2d7ba7fcb1ed3162 · schema v1 · pii pii-v1
Full breach record for CONNEX CREDIT UNION →Connex Credit Union experienced unauthorized access to files containing member personal information, including names, account numbers, and Social Security numbers, between June 2 and June 3, 2025. The incident was discovered on June 3, 2025. The credit union engaged independent experts, notified the NCUA and federal law enforcement, and is offering complimentary credit monitoring and fraud assistance to affected members.
California clockDiscovered Jun 3, 2025 → Notified Aug 6, 202564d ✗ CA 60-day late9 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_14a6428040752acaIndiana State AGfiled 2025-08-07Verified
- bd_b671a1b2a1a142f4Vermont State AGfiled 2025-08-07Verified
- bd_beda1a58d91c700cMontana State AGfiled 2025-08-07Candidate
- bd_11cb4d7ecd0a90f9South Carolina State AGfiled 2025-08-08(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- bd_383732811c88e6d5Texas State AGfiled 2025-08-08(1d gap)Verified
- bd_975123fa51efd59cMaine State AGfiled 2025-08-08(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-606757
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 7, 2025
- Raw hash
- ae52e88f0f60596d3d6de8c6d72b17761c68d3ef6ed8f5c13bdcf798d1e036c2
Reporting entity
- Name
- CONNEX CREDIT UNIONnorm: connex credit union
- Domain
- connexcu.org
Victim entity
- Name
- CONNEX CREDIT UNIONnorm: connex credit union
- Domain
- connexcu.org
Incident
- Discovered
- Jun 3, 2025
- Materiality determined
- —
- Notification sent
- Aug 6, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified the National Credit Union AdministrationNotified federal law enforcement
Compliance
- Time to disclose
- 9 weeks(65 days from discovery to filing)
- Compliance flags
- CA 60-day late · 64d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 3, 2025→ Notified: Aug 6, 202564d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.