Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedMulti-Stage ChainPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
VENTURA COUNTY CREDIT UNION
bd_d1ae26cf7d7cdffc · schema v1 · pii pii-v1
Full breach record for VENTURA COUNTY CREDIT UNION →Ventura County Credit Union (VCCU) reported a phishing incident where unauthorized access to employee email accounts occurred between October 20 and December 15, 2022. VCCU discovered the suspicious activity on December 14, 2022. The breach affected personal and financial information of 13 individuals (11 in NH, 2 supplemental NH, plus RI residents). VCCU engaged forensic specialists, notified regulators and credit bureaus, and offered credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_94d975cc0c03776aMaine State AGfiled 2024-01-24Candidate
- bd_f0d2f8cfe155efefCalifornia State AGfiled 2024-01-24Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/ventura-county-credit-union-20240124.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 24, 2024
- Raw hash
- 435c1519fe04b5d9b1fe83a9db9138775e5dd6cc02bc7c99290bf58138f74d47
Reporting entity
- Name
- VENTURA COUNTY CREDIT UNIONnorm: ventura county credit union
- Domain
- vccuonline.net
Victim entity
- Name
- VENTURA COUNTY CREDIT UNIONnorm: ventura county credit union
- Domain
- vccuonline.net
Incident
- Discovered
- Dec 14, 2022
- Materiality determined
- Jun 7, 2023
- Notification sent
- Jul 6, 2023
- Affected individuals
- 13
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- providing written notice of this incident to relevant state and federal regulatorsprovided notice to the three major credit reporting agencies, Equifax, Experian, and TransUnion
- Initial access
- phishing_link
Compliance
- Time to disclose
- 14 months(406 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.