MalwareRansomwareData EncryptedRansom DemandedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHigh
Home › Bayer Heritage Federal Credit Union
bd_46a9d4d215794836 · schema v1 · pii pii-v1
Full breach record for Home › Bayer Heritage Federal Credit Union →Bayer Heritage Federal Credit Union experienced a ransomware incident, discovered on December 1, 2023, which occurred on October 31, 2023. The breach affected 61,159 individuals, compromising their names and Social Security numbers. The credit union notified affected individuals and offered 12 months of credit monitoring services through Experian.
Maine clockDiscovered Dec 1, 2023 → Filed with AG Feb 6, 202467d ⏱ ME AG >30d10 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by lorenz about this victim predates this filing by 67 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_5b5aa7ccc8c9028dLeak Sitelorenzfiled 2023-12-01(67d gap)Verified by operator
Regulatory filings (2) · sorted by filing gap
- bd_611ddf21b7468fd4Montana State AGfiled 2024-02-06Verified by operator
- bd_fd262f0a9dde3428New Hampshire State AGfiled 2024-02-08(2d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/dfbd4fa8-a7ba-482c-be99-5700946e008f.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 6, 2024
- Raw hash
- e75271e0bfe41ec0190a031a51acf6276a2769a2f52e2c473662ed89a92bc079
Reporting entity
- Name
- Home › Bayer Heritage Federal Credit Unionnorm: home bayer heritage federal credit union
- Domain
- bayerhfcu.com
Victim entity
- Name
- Home › Bayer Heritage Federal Credit Unionnorm: home bayer heritage federal credit union
- Domain
- bayerhfcu.com
Incident
- Discovered
- Dec 1, 2023
- Materiality determined
- —
- Notification sent
- Feb 6, 2024
- Affected individuals
- 61,159
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 10 weeks(67 days from discovery to filing)
- Compliance flags
- ME AG >30d · 67dME resident >60d · 67dLeak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Dec 1, 2023→ Filed with AG: Feb 6, 202467d 30 days (soft) ME AG >30d Maine Discovered: Dec 1, 2023→ Notified: Feb 6, 202467d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.