HackingSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
TEXAS DOW EMPLOYEES CREDIT UNION
bd_b2e7dac90834b113 · schema v1 · pii pii-v1
Full breach record for TEXAS DOW EMPLOYEES CREDIT UNION →Texas Dow Employees Credit Union (TDECU) notified the NH Attorney General of a third-party data breach involving the MOVEit transfer tool. The bad actor accessed TDECU member files between May 29-31, 2023. TDECU discovered the compromise on July 30, 2024. Approximately 47 New Hampshire residents were affected. TDECU engaged external cybersecurity professionals, confirmed no broader network compromise, and is offering 12 months of credit monitoring.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_1caca9cfdc469dffCalifornia State AGfiled 2024-08-23Verified
- bd_634c94500f5b1258Indiana State AGfiled 2024-08-23Verified
- bd_88e3b57d2d281e64Vermont State AGfiled 2024-08-23Verified
- bd_e658683972919e3cMontana State AGfiled 2024-08-23Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/texas-dow-employees-credit-union-20240823.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 23, 2024
- Raw hash
- 61384907a74403cdbbca6b3c7cad3de0676e0046501a150174bc408fedbf24ec
Reporting entity
- Name
- TEXAS DOW EMPLOYEES CREDIT UNIONnorm: texas dow employees credit union
Victim entity
- Name
- TEXAS DOW EMPLOYEES CREDIT UNIONnorm: texas dow employees credit union
Incident
- Discovered
- Jul 30, 2024
- Materiality determined
- —
- Notification sent
- Aug 23, 2024
- Affected individuals
- 47
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella, Office of the Attorney General, Consumer Protection Bureau
- Initial access
- supply_chain
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.