HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Gain Federal Credit Union
bd_ca9f5fe590c9106d · schema v1 · pii pii-v1
Full breach record for Gain Federal Credit Union →Gain Federal Credit Union experienced a data breach on October 20, 2025, when an unauthorized party gained access to a user's email account. The incident potentially exposed names, addresses, account numbers, financial/loan information, tax information, dates of birth, Social Security numbers, and potential driver's license numbers. Access was immediately interrupted upon discovery. The organization engaged third-party forensics, notified affected members, and offered identity theft protection services.
California clockDiscovered Oct 20, 2025 → Notified Feb 4, 2026107d ✗ CA 60-day late15 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_fde3c66c99ad683eIndiana State AGfiled 2026-02-04Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-618188
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 4, 2026
- Raw hash
- 1c1cfb751b358550a62185030bc4fc914867695c3318624589a249155318e9c5
Reporting entity
- Name
- Gain Federal Credit Unionnorm: gain federal credit union
Victim entity
- Name
- Gain Federal Credit Unionnorm: gain federal credit union
Incident
- Discovered
- Oct 20, 2025
- Materiality determined
- —
- Notification sent
- Feb 4, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Reported the matter to appropriate authorities
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 15 weeks(107 days from discovery to filing)
- Compliance flags
- CA 60-day late · 107dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 20, 2025→ Notified: Feb 4, 2026107d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Feb 4, 2026→ AG copy submitted: Feb 4, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.