FIRST HARVEST Federal Credit Union
bd_cd6c0df3fb879c20 · schema v1 · pii pii-v1
Full breach record for FIRST HARVEST Federal Credit Union →First Harvest Federal Credit Union notified Massachusetts and Rhode Island residents of a security incident involving unauthorized access to an employee email account. The breach, discovered on February 3, 2026, resulted from suspicious activity likely stemming from a phishing attack on January 14, 2026. The incident exposed name data elements and potentially government identifiers (SSN, DOB, driver's license) of affected individuals. First Harvest engaged third-party forensic reviewers, enhanced security policies, and offered 12-24 months of credit monitoring via Experian. No actual misuse of information was indicated at the time of notification.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 14, 2026
Begins
Feb 3, 2026
Discovered
May 6, 2026
Filed
vs. sector median
+5 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Vermont State AGbd_09b41c7ea12444822026-05-06Verified
- Maine State AGbd_9b5f4fdfe0bffc642026-05-06Verified
- New Hampshire State AGbd_e5b9567f26b08d412026-05-06Verified
- Nebraska State AGbd_ffb640149c5431722026-05-06Verified
Filing propagation · 5 filings · 5 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.