One Community FCU
bd_75782fdc39c91951 · schema v1 · pii pii-v1
Full breach record for One Community FCU →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group DragonForce on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
One Community FCU offers a range of financial services including loans, savings accounts, and online banking solutions. Their products cater to individuals seeking personal, auto, mortgage, and credit card loans, as well as those interested in savings and checking accounts. In this release we provide a portion of the documentation we obtained from the company: databases, internal documentation, client data, client documents, client financial information (including statements that clients supplied to One Community FCU from other banks), documentation on delinquent payments. Additionally, the release contains reports and documentation produced by TraceSecurity LLC (6300 Corporate Blvd, Suite 200, Baton Rouge, LA 70809). TraceSecurity LLC handled security matters for One Community FCU. In our view, that work was performed very poorly. These shortcomings contributed to the data breach, though they were not the sole cause, so we believe it is necessary to publish them.
Source provenance
- Source URL
- https://www.ransomware.live/id/T25lIENvbW11bml0eSBGQ1VAZHJhZ29uZm9yY2U=
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 21, 2026
- Raw hash
- 03efe2f90ea026fd780fbc90e03df19fcddbc4aa9edab149761693af318ff6c5
Reporting entity
- Name
- dragonforce
Victim entity
- Name
- One Community FCUnorm: one community fcu
- Domain
- onecommunityfcu.org
- Industry
- Financial Servicesllm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· dragonforce
- Threat actor
- DragonforceExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.