HackingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumActive
First Commonwealth Federal Credit Union
bd_8d32f8044fdebc31 · schema v1 · pii pii-v1
Full breach record for First Commonwealth Federal Credit Union →First Commonwealth Federal Credit Union notified consumers on August 2, 2024, of a data breach discovered June 27, 2024. An unauthorized actor accessed files containing names, SSNs, DOBs, and account numbers around June 26, 2024. The investigation is ongoing. The credit union engaged independent cybersecurity experts and is offering 12-24 months of identity theft protection services.
Vermont clock⏱ VT AG >14 bday5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_8dd610fc000eee78Leak Sitemeowfiled 2024-07-16(17d gap)Verified by operator
Regulatory filings (2) · sorted by filing gap
- bd_2dbb64663be5cea6Montana State AGfiled 2024-08-02Verified by operator
- bd_dcab9d258550b385Maine State AGfiled 2024-08-02Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-08-02-first-commonwealth-federal-credit-union-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 2, 2024
- Raw hash
- 74bb708fde878429de98929607c947a2f57a3da597f9e74cec7b7acd6c35b11c
Reporting entity
- Name
- First Commonwealth Federal Credit Unionnorm: first commonwealth federal credit union
- Domain
- firstcomcu.org
Victim entity
- Name
- First Commonwealth Federal Credit Unionnorm: first commonwealth federal credit union
- Domain
- firstcomcu.org
Incident
- Discovered
- Jun 27, 2024
- Materiality determined
- —
- Notification sent
- Aug 2, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.