HackingFinancial ServicesFinanceStolen CredentialsCapture App DataCustomer Data InvolvedDelayed DiscoveryPIILowResolved
Lafayette Federal Credit Union ("LFCU") - SUPPLEMENTAL NOTICE
bd_b692cb281903e8c5 · schema v1 · pii pii-v1
Full breach record for Lafayette Federal Credit Union ("LFCU") - SUPPLEMENTAL NOTICE →Lafayette Federal Credit Union (LFCU) reported that an unknown unauthorized third party gained access to one employee email account on September 16, 2024. The breach was discovered on February 5, 2025 after completing a review of the account contents. The incident potentially exposed personal information of 77,337 individuals total, including 124 Maine residents. LFCU secured the account, engaged a forensic firm, and offered 12-month Experian IdentityWorks Credit 3B monitoring.
Maine clockDiscovered Feb 5, 2025 → Filed with AG Jul 30, 2025175d ✗ ME AG >90d25 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed124 affectedView incident
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/730f334a-0a37-4695-8abf-c7a761b880d7.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 30, 2025
- Raw hash
- ecc142f027d23a2b4afec6157eccc79b517eec34eca76f0c8c2c10da6f1f8861
Reporting entity
- Name
- Lafayette Federal Credit Union ("LFCU") - SUPPLEMENTAL NOTICEnorm: lafayette federal credit union lfcu supplemental notice
- Domain
- lfcu.org
- Industry
- Financial Services
Victim entity
- Name
- Lafayette Federal Credit Union ("LFCU") - SUPPLEMENTAL NOTICEnorm: lafayette federal credit union lfcu supplemental notice
- Domain
- lfcu.org
- Industry
- Financial Services
- Industry
- Financial Servicesllm
Incident
- Discovered
- Feb 5, 2025
- Materiality determined
- —
- Notification sent
- Mar 20, 2025
- Affected individuals
- 124
- Data types
- PII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Notified Maine Attorney General
Compliance
- Time to disclose
- 25 weeks(175 days from discovery to filing)
- Compliance flags
- ME AG >90d · 175d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Feb 5, 2025→ Filed with AG: Jul 30, 2025175d 90 days ME AG >90d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.