HackingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
CONNEX CREDIT UNION
bd_b671a1b2a1a142f4 · schema v1 · pii pii-v1
Full breach record for CONNEX CREDIT UNION →Connex Credit Union notified consumers of a data security incident occurring June 2-3, 2025. Unauthorized access to files containing names, account numbers, SSNs, and government IDs was detected. The credit union engaged independent experts, enhanced network security, and notified the NCUA and federal law enforcement. Affected individuals are offered complimentary credit monitoring and identity protection services via Cyberscout.
Vermont clock⏱ VT AG >14 bday9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_14a6428040752acaIndiana State AGfiled 2025-08-07Verified
- bd_2d7ba7fcb1ed3162California State AGfiled 2025-08-07Verified
- bd_beda1a58d91c700cMontana State AGfiled 2025-08-07Candidate
- bd_11cb4d7ecd0a90f9South Carolina State AGfiled 2025-08-08(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- bd_383732811c88e6d5Texas State AGfiled 2025-08-08(1d gap)Verified
- bd_975123fa51efd59cMaine State AGfiled 2025-08-08(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-08-07-connex-credit-union-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 7, 2025
- Raw hash
- d7db369d7ab3e1cf04200ee9a24a6d2be41aec88cdd667cd031c16c8830dcc57
Reporting entity
- Name
- CONNEX CREDIT UNIONnorm: connex credit union
- Domain
- connexcu.org
Victim entity
- Name
- CONNEX CREDIT UNIONnorm: connex credit union
- Domain
- connexcu.org
Incident
- Discovered
- Jun 3, 2025
- Materiality determined
- —
- Notification sent
- Aug 6, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated CollectionT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the National Credit Union AdministrationNotified federal law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(65 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.