HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedPIICREDENTIALSFINANCIAL_ACCOUNTLowContained
WESCOM CENTRAL CREDIT UNION
bd_992ecaba454cb70d · schema v1 · pii pii-v1
Full breach record for WESCOM CENTRAL CREDIT UNION →Wescom Central Credit Union notified consumers of a data breach involving its Barracuda ESG appliance. A vulnerability allowed unauthorized access to emails and attachments stored on the appliance between October 2022 and May 2023. Wescom removed and decommissioned the appliance, engaged cybersecurity experts, and offered 12 months of identity protection services. Personal information, including financial account data, was potentially accessed.
Vermont clock✗ VT AG >45 bday20 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_05fbc9fc7eca4727Maine State AGfiled 2023-10-21(1d gap)Candidate
- bd_0a8506e9bf5e4738Montana State AGfiled 2023-10-21(1d gap)Verified by operator
- bd_37552ac98b0a31f0California State AGfiled 2023-10-21(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-10-20-wescom-central-credit-union-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 20, 2023
- Raw hash
- 5e992fb0481f0faa585e4cd03ec8a8a66eba5798fd87024631a0c71ddfa6f4e6
Reporting entity
- Name
- WESCOM CENTRAL CREDIT UNIONnorm: wescom central credit union
- Domain
- wescom.org
Victim entity
- Name
- WESCOM CENTRAL CREDIT UNIONnorm: wescom central credit union
- Domain
- wescom.org
Incident
- Discovered
- May 30, 2023
- Materiality determined
- Oct 20, 2023
- Notification sent
- Oct 20, 2023
- Affected individuals
- Not disclosed
- Data types
- PIICREDENTIALSFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1119 Automated Collection
- Threat actor
- External
- Third party
- via Barracuda Network, Inc.
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 20 weeks(143 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.