Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICCREDENTIALSLowContained
Service Federal Credit Union
bd_81056413d1d25055 · schema v1 · pii pii-v1
Full breach record for Service Federal Credit Union →Service Federal Credit Union reported a potential data security incident to the New Hampshire Attorney General. An unauthorized third party gained access to an employee email account between Jan 18-23, 2023, likely via phishing. The incident involved the personal information (name) of one NH resident. Service FCU secured the account, engaged forensic investigators, and notified the affected individual.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/service-federal-credit-union-20230405.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 5, 2023
- Raw hash
- 37a5736a068c1386cf0e2221135ce8c42541a221cdfcb4474d66e278e1c35f1e
Reporting entity
- Name
- Service Federal Credit Unionnorm: service federal credit union
- Domain
- servicecu.org
Victim entity
- Name
- Service Federal Credit Unionnorm: service federal credit union
- Domain
- servicecu.org
Incident
- Discovered
- Jan 23, 2023
- Materiality determined
- Mar 24, 2023
- Notification sent
- Mar 31, 2023
- Affected individuals
- 1
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection Bureau
- Initial access
- phishing_link
Compliance
- Time to disclose
- 10 weeks(72 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.