HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMediumContained
Fairmont Federal Credit Union
bd_761a3297a827ae36 · schema v1 · pii pii-v1
Full breach record for Fairmont Federal Credit Union →Fairmont Federal Credit Union (FFCU) notified New Hampshire AG John Formella of a cybersecurity incident affecting 36 NH residents. Unauthorized access occurred between September 30 and October 18, 2023. FFCU discovered the breach on January 23, 2024, and confirmed the scope on August 17, 2025. Impacted data includes names, SSNs, tax IDs, account numbers, and credit card details. FFCU engaged outside cybersecurity professionals for forensic investigation and is offering complimentary credit monitoring to affected residents.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_296cd008c0de54c1Texas State AGfiled 2025-09-12(6d gap)Verified
- bd_0a31c3a936612f17Maine State AGfiled 2025-09-11(7d gap)Candidate
- bd_21b07e63bef16c8eMontana State AGfiled 2025-09-11(7d gap)Candidate
- bd_a6c06c435aa4a961California State AGfiled 2025-09-11(7d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/fairmont-federal-credit-union-20250918.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 18, 2025
- Raw hash
- fe42ea7f046264be676e5c0d630eabee532b0f8fa450e26579f67aabe5bb213c
Reporting entity
- Name
- McDonaldnorm: mcdonald
- Domain
- mcdonalds-menus.us
Victim entity
- Name
- Fairmont Federal Credit Unionnorm: fairmont federal credit union
Incident
- Discovered
- Jan 23, 2024
- Materiality determined
- —
- Notification sent
- Sep 11, 2025
- Affected individuals
- 36
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 20 months(604 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.