HackingCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICLowContained
SRP Federal Credit Union ("SRP FCU")
bd_ad44b54b9631ed6b · schema v1 · pii pii-v1
Full breach record for SRP Federal Credit Union ("SRP FCU") →SRP Federal Credit Union notified South Carolina and other state regulators of a data breach occurring between September 5, 2024, and November 4, 2024. An unauthorized third party accessed systems and potentially acquired personal information. The credit union engaged law enforcement and a forensic firm, secured systems, and offered one year of Experian IdentityWorks credit monitoring to affected individuals.
Leak gap clock⏱ Leak >90d26 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
A leak claim by nitrogen about this victim predates this filing by 90 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_44451beb33e5b56aLeak Sitenitrogenfiled 2024-12-05(90d gap)Verified
Regulatory filings (3) · sorted by filing gap
- bd_3c6d257b57db9e6aMaine State AGfiled 2025-02-03(31d gap)Verified
- bd_052d1ec56ee86a31Maine State AGfiled 2024-12-12(84d gap)Verified
- bd_680347720545e521Montana State AGfiled 2024-12-12(84d gap)Verified by operator
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2025/SRPFederalCreditUnion.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 6, 2025
- Raw hash
- d4798c0d28a129922d9ccd090a629f0713a82562ef80d465f521979eba94eb8a
Reporting entity
- Name
- SRP Federal Credit Union ("SRP FCU")norm: srp federal credit union srp fcu
- Domain
- srpfcu.org
Victim entity
- Name
- SRP Federal Credit Union ("SRP FCU")norm: srp federal credit union srp fcu
- Domain
- srpfcu.org
Incident
- Discovered
- Sep 5, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 26 weeks(182 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.