HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHighContained
ALOHA PACIFIC FEDERAL CREDIT UNION
bd_ccb3f82da7b671b6 · schema v1 · pii pii-v1
Full breach record for ALOHA PACIFIC FEDERAL CREDIT UNION →Aloha Pacific Federal Credit Union (APFCU) notified Hawaii regulators of a data security incident involving its vendor, Darling Consulting Group (DCG). On May 31, 2023, a vulnerability in DCG's MOVEit file transfer tool was exploited. APFCU was notified on August 1, 2023, that files containing personal information of 5,409 Hawaii residents were accessed. Data included names, SSNs, DOBs, and credit card/account numbers. APFCU sent notification letters and offered 12 months of credit monitoring. APFCU's own systems were not directly accessed.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_2ce3165ff117dec8Montana State AGfiled 2023-08-30Candidate
- bd_54201b9c2d71a38bMaine State AGfiled 2023-08-30Candidate
- bd_e78d2bcf9eaba2b2Vermont State AGfiled 2023-08-30Verified
Source provenance
- Source URL
- https://cca.hawaii.gov/wp-content/uploads/2026/05/Letter.2023-0950.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 30, 2023
- Raw hash
- 7e43b15e2366ac9ea922e0725ff494cbd7bcfe606dc9e5e2a64ef4c305f93e19
Reporting entity
- Name
- ALOHA PACIFIC FEDERAL CREDIT UNIONnorm: aloha pacific federal credit union
Victim entity
- Name
- ALOHA PACIFIC FEDERAL CREDIT UNIONnorm: aloha pacific federal credit union
Incident
- Discovered
- Aug 1, 2023
- Materiality determined
- —
- Notification sent
- Aug 30, 2023
- Affected individuals
- 5,409
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Hawaii Department of Commerce and Consumer Affairs
- Third party
- via Darling Consulting Group
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.