HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Alaska Air Group Federal Credit Union
bd_437e2f1386c30f9c · schema v1 · pii pii-v1
Full breach record for Alaska Air Group Federal Credit Union →Alaska Air Group Credit Union notified the New Hampshire Attorney General on April 16, 2026, of a cybersecurity incident involving its third-party IT service provider. The breach, occurring around March 5, 2026, exposed personal data of 4 New Hampshire residents, including SSNs, driver's license numbers, and financial account details. AAGCU resecured its systems, engaged forensic experts, and provided 24 months of credit monitoring to affected members.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_34559bdc6ddc4ce5Indiana State AGfiled 2026-04-16Candidate
- bd_280fdc00e92257feOregon State AGfiled 2026-04-17(1d gap)Verified
- bd_5e0a3bd92e535080California State AGfiled 2026-04-17(1d gap)Verified
- bd_869dab11152c8f64Vermont State AGfiled 2026-04-17(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- bd_b58902d825299539Maine State AGfiled 2026-04-17(1d gap)Verified
- bd_e65e6ed6cee14458Washington State AGfiled 2026-04-17(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/alaska-air-group-credit-union-20260416.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 16, 2026
- Raw hash
- 294b3a2b4434be323b620dcb045d163c7fe7cc3ff1322f716b10f4ecba9652f3
Reporting entity
- Name
- Alaska Air Group Federal Credit Unionnorm: alaska air group federal credit union
Victim entity
- Name
- Alaska Air Group Federal Credit Unionnorm: alaska air group federal credit union
Incident
- Discovered
- Mar 5, 2026
- Materiality determined
- —
- Notification sent
- Apr 16, 2026
- Affected individuals
- 4
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- supply_chain
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.