HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedPIIIDENTITY_BASICFINANCIALLowContained
WESCOM CENTRAL CREDIT UNION
bd_37552ac98b0a31f0 · schema v1 · pii pii-v1
Full breach record for WESCOM CENTRAL CREDIT UNION →Wescom Central Credit Union notified members that a vulnerability in Barracuda Network's ESG appliances allowed unauthorized access to emails and attachments between October 30, 2022, and May 30, 2023. Wescom confirmed impact on May 30, 2023, and immediately removed the appliances from its network. Personal information in affected emails may have been accessed. Wescom is offering 12 months of identity protection services.
California clockDiscovered May 30, 2023 → Notified Oct 20, 2023143d ✗ CA 60-day late21 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_05fbc9fc7eca4727Maine State AGfiled 2023-10-21Candidate
- bd_0a8506e9bf5e4738Montana State AGfiled 2023-10-21Verified by operator
- bd_992ecaba454cb70dVermont State AGfiled 2023-10-20(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-575506
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 21, 2023
- Raw hash
- 984e722fb0a6abd7d067fd4dcbe39e358460793fa9ace0ce9a410687ce3bb958
Reporting entity
- Name
- WESCOM CENTRAL CREDIT UNIONnorm: wescom central credit union
- Domain
- wescom.org
Victim entity
- Name
- WESCOM CENTRAL CREDIT UNIONnorm: wescom central credit union
- Domain
- wescom.org
Incident
- Discovered
- May 30, 2023
- Materiality determined
- —
- Notification sent
- Oct 20, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1114 Email Collection
- Threat actor
- External
- Third party
- via Barracuda Network, Inc
- Initial access
- supply_chain
Compliance
- Time to disclose
- 21 weeks(144 days from discovery to filing)
- Compliance flags
- CA 60-day late · 143d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 30, 2023→ Notified: Oct 20, 2023143d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.