HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Quorum Federal Credit Union
bd_b0840f575c1c318b · schema v1 · pii pii-v1
Full breach record for Quorum Federal Credit Union →Quorum Federal Credit Union notified California residents of unauthorized access to personal information via a vulnerability in the MOVEit data transfer tool (owned by Progress Software). The incident occurred between May 28, 2023, and May 31, 2023. The credit union engaged a cybersecurity firm, implemented vendor-recommended fixes, and offered one year of identity monitoring through Kroll to affected individuals.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_e8c795bcc5dc102cLeak Sitedispossessorfiled 2023-10-18(93d gap)Verified by operator
Regulatory filings (3) · sorted by filing gap
- bd_82052e2f5c4e9a44Montana State AGfiled 2023-07-17Candidate
- bd_d656dc22c94733b0Maine State AGfiled 2023-07-17Verified
- bd_fc30fcc8f9d3ce42Washington State AGfiled 2023-07-17Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570418
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 17, 2023
- Raw hash
- 60ab6646e0b1fb8e999de0b327b4bb58400b3ecfb9e0c84c3cde4b890aef2e75
Reporting entity
- Name
- Quorum Federal Credit Unionnorm: quorum federal credit union
- Domain
- quorumfcu.org
Victim entity
- Name
- Quorum Federal Credit Unionnorm: quorum federal credit union
- Domain
- quorumfcu.org
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jun 20, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.