MalwareRansomwareCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
PATELCO CREDIT UNION
bd_b0617d89cdc9b416 · schema v1 · pii pii-v1
Full breach record for PATELCO CREDIT UNION →Patelco Credit Union detected a ransomware attack on June 29, 2024, involving unauthorized access to databases starting May 23, 2024. The incident affected current and former members and employees, exposing names, SSNs, driver's license numbers, dates of birth, and email addresses. The threat was contained, and 24 months of credit monitoring were offered.
Leak gap clock⏱ Leak >30d7 weeks discovery → filing
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (2)
- bd_c9b83b21890cb423Leak Siteransomhubfiled 2024-08-16(3d gap)Verified by operator
- bd_d86fc539771c8086Leak Siteransomhubfiled 2024-06-29(52d gap)Verified by operator
Regulatory filings (6) · sorted by filing gap
- bd_272abed51034ca0cOregon State AGfiled 2024-08-20Verified
- bd_3490e911272cfc69Montana State AGfiled 2024-08-20Verified by operator
- bd_5c6d990f0a189873Maine State AGfiled 2024-08-20Verified
- bd_99719e822b1c011bWashington State AGfiled 2024-08-20Candidate
Show 2 more filings ↓Show fewer ↑up to 34d gap
- bd_c88dac2c250735a6Washington State AGfiled 2024-09-23(34d gap)Verified
- bd_f1d3d40e3783e96cMaine State AGfiled 2024-09-23(34d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-590495
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 20, 2024
- Raw hash
- 5b58caa9bfccd592b5b6215a1f75257ca9dfdaab17803803dd6b71a1c6cacc8e
Reporting entity
- Name
- PATELCO CREDIT UNIONnorm: patelco credit union
- Domain
- patelco.org
Victim entity
- Name
- PATELCO CREDIT UNIONnorm: patelco credit union
- Domain
- patelco.org
Incident
- Discovered
- Jun 29, 2024
- Materiality determined
- —
- Notification sent
- Aug 14, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 7 weeks(52 days from discovery to filing)
- Compliance flags
- Leak >30dCA 60-day OK · 46d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 29, 2024→ Notified: Aug 14, 202446d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.