DisclosureLens
Social EngineeringFinancial ServicesFinancePhishingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedData ExfiltratedIdentity (basic)Government IDMediumContained

Provident Credit Union

bd_937b5f162cf437c2 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Apr 25, 2017

Filed

Jun 13, 2017

To disclose

7 weeks

Affected

11state residents only

Linked

2 filings

Confidence

66%
Full breach record for Provident Credit Union2 incidents on file

Provident Credit Union notified the NH Attorney General of a data breach involving a third-party vendor, Creditors Specialty Services, Inc. (CSS). A CSS sales representative sent an email containing sensitive member data to a former CSS president on March 3, 2017. Provident confirmed the incident on April 25, 2017, and notified 11 NH residents on May 24, 2017. Affected data included names, addresses, and SSNs. Provident terminated its relationship with CSS and offered credit monitoring.

Incident timeline

undetected · 53 days
discovery → filing · 7 weeks / 49 days

Mar 3, 2017

Begins

Apr 25, 2017

Discovered

Jun 13, 2017

Filed

vs. sector median

1 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
New Hampshire State AGJun 13 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.