HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
CARTER FEDERAL CREDIT UNION
bd_88c07223dc6e1c14 · schema v1 · pii pii-v1
Full breach record for CARTER FEDERAL CREDIT UNION →Carter Federal Credit Union filed a supplemental data breach notification with the New Hampshire Attorney General regarding unauthorized access to its network between June 25 and July 2, 2025. The incident affected 127 New Hampshire residents, exposing names, SSNs, driver's license numbers, and financial account data. Carter engaged forensic investigators, reported to law enforcement, and provided one year of complimentary credit monitoring to affected individuals. Notifications were completed on February 4, 2026.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_f76cb3be7e811332Oregon State AGfiled 2026-02-05Candidate
- bd_c744aa77557cb50dTexas State AGfiled 2026-02-06(1d gap)Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/carter-federal-credit-union-20260205.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 5, 2026
- Raw hash
- 2acddaeb0c4d3d226671f0be0c393a3476b0e098db7463af77256759c4ce80ff
Reporting entity
- Name
- Polsinelli (on behalf of Western Alliance Bank)norm: polsinelli on behalf of western alliance bank
Victim entity
- Name
- CARTER FEDERAL CREDIT UNIONnorm: carter federal credit union
- Industry
- financial_services
Incident
- Discovered
- Jul 2, 2025
- Materiality determined
- —
- Notification sent
- Feb 4, 2026
- Affected individuals
- 127
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General's Office
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 31 weeks(218 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.