DisclosureLens
MalwareFinancial ServicesFinanceRansomwareSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedMulti-Stage ChainGovernment IDFinancial accountMediumActive

INTOUCH CREDIT UNION

bd_c0b50cd5d6fb7320 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Oct 10, 2017

Filed

Nov 8, 2017

To disclose

29 days

Affected

8state residents only

Linked

3 filings

Confidence

66%
Full breach record for INTOUCH CREDIT UNION2 incidents on file

InTouch Credit Union notified the New Hampshire Attorney General of a ransomware attack on a third-party data analytics vendor. The incident potentially affected 8 New Hampshire residents, exposing names, SSNs, and financial/loan account information. The unauthorized access window was July 2, 2017, to October 10, 2017. The credit union offered 12 months of credit monitoring and is reviewing vendor contracts. Investigation was ongoing as of November 8, 2017.

Incident timeline

undetected · 100 days
discovery → filing · 29 days

Jul 2, 2017

Begins

Oct 10, 2017

Discovered

Nov 8, 2017

Filed

vs. sector median

4 wks faster

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Montana State AGNov 8 · first
New Hampshire State AGNov 8 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.