HackingFinancial ServicesFinanceCustomer Data InvolvedPIILowContained
FIRST HARVEST Federal Credit Union
bd_9b5f4fdfe0bffc64 · schema v1 · pii pii-v1
Full breach record for FIRST HARVEST Federal Credit Union →First Harvest Federal Credit Union, a New Jersey-based federal credit union, experienced an external system breach (hacking) that occurred on January 14, 2026 and was discovered on April 17, 2026. Eight Maine residents were affected. Written notifications were sent on May 6, 2026. Affected individuals were offered 12 months of credit monitoring through Experian.
Maine clockDiscovered Apr 17, 2026 → Filed with AG May 6, 202619d ✓ ME AG ≤30d19 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_09b41c7ea1244482Vermont State AGfiled 2026-05-06Verified
- bd_e5b9567f26b08d41New Hampshire State AGfiled 2026-05-06Verified
- bd_cd6c0df3fb879c20Massachusetts State AGfiled 2026-05-01(5d gap)Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/88ffb4af-2214-4720-a781-2020b913265f.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 6, 2026
- Raw hash
- 32297d0f169c3a0a606f3358c0fea8e2838ddc0d623e2c8991abe44900824249
Reporting entity
- Name
- FIRST HARVEST Federal Credit Unionnorm: first harvest federal credit union
- Domain
- firstharvestcu.com
- Industry
- Financial Services
Victim entity
- Name
- FIRST HARVEST Federal Credit Unionnorm: first harvest federal credit union
- Domain
- firstharvestcu.com
- Industry
- Financial Services
- Industry
- Financial Servicesllm
Incident
- Discovered
- Apr 17, 2026
- Materiality determined
- —
- Notification sent
- May 6, 2026
- Affected individuals
- 8
- Data types
- PII
- Attack vector
- Unauthorized Access
- Threat actor
- External
Compliance
- Time to disclose
- 19 days(19 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 19d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Apr 17, 2026→ Filed with AG: May 6, 202619d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.