Chevron Federal Credit Union
bd_516ce6f1fa331ab4 · schema v1 · pii pii-v1
Full breach record for Chevron Federal Credit Union →Chevron Federal Credit Union experienced a data breach involving the MOVEit file transfer service provided by Progress Software. An unauthorized party exploited a previously unknown vulnerability (zero-day) in the MOVEit application to decrypt and download files between May 30 and May 31, 2023. The incident was discovered on August 1, 2023, after new detection methods were published. Personal information, including basic identity data, was compromised. The organization engaged third-party forensics, remediated the vulnerability, and offered one year of credit monitoring to affected members.
Linked disclosures
Why this link?Ransomware claims (2)
- bd_1e89fdb7a2e76660Leak Sitecl0pfiled 2023-07-26(29d gap)Verified
- bd_e4a22c92907248d2Leak Sitedispossessorfiled 2021-11-26(636d gap)Candidate
Regulatory filings (2) · sorted by filing gap
- bd_1b66e5dcd4aa08adOregon State AGfiled 2023-08-24Verified by operator
- bd_ac9885f89e17ab0aWashington State AGfiled 2023-08-24Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-572364
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 24, 2023
- Raw hash
- 41da855c1365e394f4fe062b1d78162a5892302ff97ae39ebbcd4184958c2826
Reporting entity
- Name
- Chevron Federal Credit Unionnorm: chevron federal credit union
- Domain
- chevronfcu.org
Victim entity
- Name
- Chevron Federal Credit Unionnorm: chevron federal credit union
- Domain
- chevronfcu.org
Incident
- Discovered
- Aug 1, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 23 days(23 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.