MalwareRansomwareData ExfiltratedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTPIIMediumContained
PATELCO CREDIT UNION
bd_712c20c7d06c802e · schema v1 · pii pii-v1
Full breach record for PATELCO CREDIT UNION →Patelco Credit Union notified Vermont and Rhode Island residents of a ransomware attack detected on June 29, 2024. Unauthorized access occurred starting May 23, 2024. Data accessed included names, SSNs, driver's license numbers, dates of birth, and email addresses. 54 Rhode Island residents were explicitly identified as impacted. Patelco contained the threat, restored data, notified law enforcement, and engaged external cybersecurity professionals. Affected individuals were offered 24 months of Experian IdentityWorks.
Vermont clock✗ VT AG >45 bday12 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by ransomhub about this victim predates this filing by 86 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_d9d80d2a80042b16Vermont State AGfiled 2024-08-21(33d gap)Candidate
- bd_fc8a75d799d07306Indiana State AGfiled 2024-08-20(34d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-09-23-patelco-credit-union-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 23, 2024
- Raw hash
- 7384bb4ec7d028a3c5895d3ea4b218534d2ea4568142fbebf337cb22450ffe93
Reporting entity
- Name
- PATELCO CREDIT UNIONnorm: patelco credit union
- Domain
- patelco.org
Victim entity
- Name
- PATELCO CREDIT UNIONnorm: patelco credit union
- Domain
- patelco.org
Incident
- Discovered
- Jun 29, 2024
- Materiality determined
- —
- Notification sent
- Sep 23, 2024
- Affected individuals
- 54
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPII
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1119 Automated CollectionT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with Office of the Vermont Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 12 weeks(86 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.