MalwareRansomwareSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedMulti-Stage ChainIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumActive
INTOUCH CREDIT UNION
bd_c0b50cd5d6fb7320 · schema v1 · pii pii-v1
Full breach record for INTOUCH CREDIT UNION →InTouch Credit Union notified the New Hampshire Attorney General of a ransomware attack on a third-party data analytics vendor. The incident potentially affected 8 New Hampshire residents, exposing names, SSNs, and financial/loan account information. The unauthorized access window was July 2, 2017, to October 10, 2017. The credit union offered 12 months of credit monitoring and is reviewing vendor contracts. Investigation was ongoing as of November 8, 2017.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_3ce565c9cdcbfc62Montana State AGfiled 2017-11-08Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/intouch-credit-union-20171108.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 8, 2017
- Raw hash
- a33d04c66dc5d4656f890080d70189c5f28e5e8145c6272c58daabc960575170
Reporting entity
- Name
- INTOUCH CREDIT UNIONnorm: intouch credit union
Victim entity
- Name
- INTOUCH CREDIT UNIONnorm: intouch credit union
Incident
- Discovered
- Oct 10, 2017
- Materiality determined
- —
- Notification sent
- Nov 8, 2017
- Affected individuals
- 8
- Data types
- IDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Providing notice of this incident to your office (Attorney General)Providing notice of this incident to certain other state regulators, federal regulators, and consumer reporting agencies
- Initial access
- supply_chain
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.