Social EngineeringPhishingCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
VENTURA COUNTY CREDIT UNION
bd_bfa82828285b3bc4 · schema v1 · pii pii-v1
Full breach record for VENTURA COUNTY CREDIT UNION →Ventura County Credit Union (VCCU) notified New Hampshire residents on June 20, 2024, of a phishing incident involving unauthorized access to an employee email account between January 29-30, 2024. VCCU discovered the activity on January 30, 2024, and engaged outside specialists. The incident exposed customer PII, including names and government IDs. VCCU notified the NCUA and federal law enforcement, and is offering credit monitoring via Experian.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_004d28accb577cd9Maine State AGfiled 2024-06-20Candidate
- bd_16adfea87a25c634Montana State AGfiled 2024-06-20Verified
- bd_54934c9153dfbca0Indiana State AGfiled 2024-06-20Verified
- bd_9893e2549b7bb411California State AGfiled 2024-06-20Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/ventura-county-credit-union-20240620.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 20, 2024
- Raw hash
- 75ffc657ddad465fca790adfb7f0de32dbe5feb7b3fbd200c8f021d969bb29b5
Reporting entity
- Name
- VENTURA COUNTY CREDIT UNIONnorm: ventura county credit union
- Domain
- vccuonline.net
Victim entity
- Name
- VENTURA COUNTY CREDIT UNIONnorm: ventura county credit union
- Domain
- vccuonline.net
Incident
- Discovered
- Jan 30, 2024
- Materiality determined
- —
- Notification sent
- Jun 20, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- notified its primary federal regulator, the National Credit Union Association (“NCUA”)
- Initial access
- phishing_link
Compliance
- Time to disclose
- 20 weeks(142 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.