HackingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
VERIDIAN CREDIT UNION
bd_7dfc0628881503db · schema v1 · pii pii-v1
Full breach record for VERIDIAN CREDIT UNION →Veridian Credit Union notified the NH Attorney General of a data security incident detected on April 3, 2023. An unauthorized party used possessed personal information to initiate applications on VCU's online membership system, potentially accessing credit report data between April 1-2, 2023. VCU secured the network, investigated, contacted law enforcement, and offered credit monitoring to affected individuals.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_852539b85bef505dCalifornia State AGfiled 2023-05-03Candidate
- bd_df005db7b005d523Vermont State AGfiled 2023-05-03Verified
- bd_e261fb48faace56cMontana State AGfiled 2023-05-03Verified
- bd_6d3256afd8b9ce20Maine State AGfiled 2023-05-04(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/veridian-credit-union-20230503.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 3, 2023
- Raw hash
- be730b6e693e6f8f7927eb11319777ad1a8a601368f0f51c558091ae16932e75
Reporting entity
- Name
- VERIDIAN CREDIT UNIONnorm: veridian credit union
- Domain
- veridiancu.org
Victim entity
- Name
- VERIDIAN CREDIT UNIONnorm: veridian credit union
- Domain
- veridiancu.org
Incident
- Discovered
- Apr 3, 2023
- Materiality determined
- —
- Notification sent
- May 3, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- contacting law enforcement to address the incident
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.