HackingCustomer Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
OE Federal Credit Union
bd_a89563f40ff80881 · schema v1 · pii pii-v1
Full breach record for OE Federal Credit Union →OE Federal Credit Union notified consumers of a cybersecurity incident detected on October 28, 2023. Unauthorized access occurred between August 19 and October 29, 2023, potentially exposing personal information. The credit union engaged external forensic investigators and is offering complimentary Experian IdentityWorks membership to affected individuals.
Vermont clock✗ VT AG >45 bday26 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
A leak claim by noescape about this victim predates this filing by 184 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_13ffb6f7f84418cfCalifornia State AGfiled 2024-04-30Verified
- bd_195ac9680f382b80Montana State AGfiled 2024-04-30Candidate
- bd_5e779dd08ad7d768Washington State AGfiled 2024-04-30Verified
- bd_6c93b213b362f468Oregon State AGfiled 2024-05-02(2d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-04-30-oe-federal-credit-union-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 30, 2024
- Raw hash
- 7d8a69ce8e1c66e95314a652031edef6b3bac4c403f247a0e897321e8c140f55
Reporting entity
- Name
- OE Federal Credit Unionnorm: oe federal credit union
- Domain
- oefederal.org
Victim entity
- Name
- OE Federal Credit Unionnorm: oe federal credit union
- Domain
- oefederal.org
Incident
- Discovered
- Oct 28, 2023
- Materiality determined
- Apr 1, 2024
- Notification sent
- Apr 30, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 26 weeks(185 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.