HackingIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
KEYPOINT Credit Union
bd_8c741ed027f93dbe · schema v1 · pii pii-v1
Full breach record for KEYPOINT Credit Union →Kettering Health notified KH Credit Union members of unauthorized access to Kettering's network (not KHCU's) between April 9 and May 20, 2025. The incident exposed member names, SSNs, driver's licenses, bank/financial account numbers, and medical billing information. Kettering engaged third-party investigators and federal law enforcement, and is offering 12 months of credit monitoring and fraud assistance via Cyberscout/TransUnion.
Massachusetts clock✗ MA AG >90d13 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_394a306c1d9f3f32Indiana State AGfiled 2026-06-16(15d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-985-kh-credit-union/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2026
- Raw hash
- 1aa496d3b57647396664d89ca2a8f311955655293ab0e882c41c34e189ea1ba8
Reporting entity
- Name
- Kettering Healthnorm: kettering health
- Domain
- ketteringhealth.org
- Industry
- healthcare
Victim entity
- Name
- KEYPOINT Credit Unionnorm: keypoint credit union
- Industry
- financial_services
Incident
- Discovered
- May 20, 2025
- Materiality determined
- —
- Notification sent
- Jun 16, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- working with federal law enforcement agencies
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 months(377 days from discovery to filing)
- Compliance flags
- MA AG >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.