HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICPIILowContained
LAFAYETTE FEDERAL CREDIT UNION
bd_6ff5139107b80bca · schema v1 · pii pii-v1
Full breach record for LAFAYETTE FEDERAL CREDIT UNION →Lafayette Federal Credit Union reported that an unauthorized third party accessed an employee email account on September 16, 2024. The breach may have exposed personal information, including names and other data elements, of affected members. The organization secured the account, engaged forensic investigators, and is offering one year of complimentary credit monitoring to affected individuals.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_d6cea7531eafa392Montana State AGfiled 2025-03-20Candidate
- bd_d80aaf6241c8160bMaine State AGfiled 2025-03-20Verified by operator
- bd_8bc2e38bdebff7f2Texas State AGfiled 2025-07-15(117d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-600147
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 20, 2025
- Raw hash
- 77354242a8747d431cc276c90861c7b8f6cb5f7ee9968897493b28d3b0875013
Reporting entity
- Name
- LAFAYETTE FEDERAL CREDIT UNIONnorm: lafayette federal credit union
Victim entity
- Name
- LAFAYETTE FEDERAL CREDIT UNIONnorm: lafayette federal credit union
Incident
- Discovered
- Sep 16, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 26 weeks(185 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.