HackingBECCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
MERITUS Federal Credit Union
bd_5fe1be7948b73846 · schema v1 · pii pii-v1
Full breach record for MERITUS Federal Credit Union →Meritus Federal Credit Union reported a business email compromise (BEC) incident on July 28, 2021, discovered on October 18, 2021. The breach affected 20,388 individuals, including 5 Maine residents. Acquired data included names and Social Security Numbers. The credit union notified affected individuals in writing on November 17, 2021, and provided 12 months of credit monitoring and identity restoration services through Experian.
Maine clockDiscovered Oct 18, 2021 → Filed with AG Nov 17, 202130d ✓ ME AG ≤30d4 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed20,388 affectedView incident
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/c9cd6aa4-6c5b-4d6e-b6cb-d156a2e316cd.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 17, 2021
- Raw hash
- 7bb7b15e8f163623619f33b4fb10bd58f6ae37a29381e131c3d5e676f8e7382b
Reporting entity
- Name
- MERITUS Federal Credit Unionnorm: meritus federal credit union
- Domain
- merituscu.net
- Industry
- Financial Services
Victim entity
- Name
- MERITUS Federal Credit Unionnorm: meritus federal credit union
- Domain
- merituscu.net
- Industry
- Financial Services
Incident
- Discovered
- Oct 18, 2021
- Materiality determined
- —
- Notification sent
- Nov 17, 2021
- Affected individuals
- 20,388
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 30d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Oct 18, 2021→ Filed with AG: Nov 17, 202130d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.