HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedFINANCIAL_ACCOUNTPIILowContained
St. Mary's Credit Union
bd_7fdfa5a4a73c29b1 · schema v1 · pii pii-v1
Full breach record for St. Mary's Credit Union →St. Mary's Credit Union notified Massachusetts members of a security incident involving Mastercard where their debit/ATM cards may have been compromised, potentially allowing unauthorized access to funds. The Credit Union lowered daily transaction limits, issued new cards, and deactivated old cards. No specific count of affected individuals was provided in this notification.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_8b3f2ebc4f214c8aMassachusetts State AGfiled 2026-06-01Candidate
- bd_97514116f376b7ecMassachusetts State AGfiled 2026-06-01Candidate
- bd_4ed87e64ac3bd1f8Massachusetts State AGfiled 2026-07-01(30d gap)Candidate
- bd_8077307e22ef9eacMassachusetts State AGfiled 2026-07-01(30d gap)Candidate
Show 3 more filings ↓Show fewer ↑up to 31d gap
- bd_9f76c8801e9b61ffMassachusetts State AGfiled 2026-07-01(30d gap)Candidate
- bd_e6fe8f857139afc6Massachusetts State AGfiled 2026-07-01(30d gap)Candidate
- bd_790b1bf932b33b9cMassachusetts State AGfiled 2026-05-01(31d gap)Candidate
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-954-st-marys-credit-union/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2026
- Raw hash
- 94da79b2fe2a4aa998e67bec8e557f65275fb18e37f2bccf0bc0658ede11209a
Reporting entity
- Name
- St. Mary's Credit Unionnorm: st mary s credit union
Victim entity
- Name
- St. Mary's Credit Unionnorm: st mary s credit union
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Third party
- via Mastercard
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.