DisclosureLens
HackingFinancial ServicesFinanceStolen CredentialsData ExfiltratedCustomer Data InvolvedIdentity (basic)Government IDFinancial accountFinancial credentialsMediumContained

Fairmont Federal Credit Union

bd_761a3297a827ae36 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jan 23, 2024

Filed

Sep 18, 2025

To disclose

20 months

Affected

36state residents only

Linked

8 filings

Confidence

66%
Full breach record for Fairmont Federal Credit Union

Fairmont Federal Credit Union (FFCU) notified New Hampshire AG John Formella of a cybersecurity incident affecting 36 NH residents. Unauthorized access occurred between September 30 and October 18, 2023. FFCU discovered the breach on January 23, 2024, and confirmed the scope on August 17, 2025. Impacted data includes names, SSNs, tax IDs, account numbers, and credit card details. FFCU engaged outside cybersecurity professionals for forensic investigation and is offering complimentary credit monitoring to affected residents.

Leak gap clock Leak >180d20 months discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

undetected · 115 days
discovery → filing · 20 months / 604 days

Sep 30, 2023

Begins

Jan 23, 2024

Discovered

Sep 18, 2025

Filed

vs. sector median

+78 wks slower

This filing is one of 8 about the same incident.View merged incident
A leak claim by black_basta about this victim predates this filing by 701 days.View originating leak claim

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (6) · sorted by filing gap

Show 2 more filingsup to 7d gap

Filing propagation · 7 filings · 7 states

View merged incident ↗
Maine State AGSep 11 · first
Montana State AGSep 11 · first
Nebraska State AGSep 11 · first
Massachusetts State AGSep 11 · first
California State AGSep 11 · first
New Hampshire State AG+7d · this page

Pattern: first filing Sep 11 (ME), last Sep 18 (NH) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.