HackingFinancial ServicesFinanceStolen CredentialsCapture App DataCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
KEYPOINT Credit Union
bd_82ec30846eb09bfe · schema v1 · pii pii-v1
Full breach record for KEYPOINT Credit Union →KeyPoint Credit Union notified affected individuals of a data breach in which an unauthorized third party gained access to an employee email account in August 2020. The incident was contained to a single email account. On October 28, 2020, a forensic review determined that the email account contained personal information including names and at least one additional variable data element (e.g., SSN per the notice template). One year of Experian IdentityWorks Credit 3B was offered.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-196989
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 9, 2020
- Raw hash
- a64671fa140931dc2522a6dfcae12eec1451f63b1fae58c72b21d68e28220d1a
Reporting entity
- Name
- KEYPOINT Credit Unionnorm: keypoint credit union
Victim entity
- Name
- KEYPOINT Credit Unionnorm: keypoint credit union
- Industry
- Financial Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.