HackingFinancial ServicesFinanceStolen CredentialsCapture App DataCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryPIILowResolved
South Bay Credit Union
bd_d3138b4a5b9dfc1e · schema v1 · pii pii-v1
Full breach record for South Bay Credit Union →South Bay Credit Union (SBCU), a financial services organization based in Redondo Beach, CA, experienced an unauthorized access to one employee's email account on or about November 18, 2024. Discovery occurred on January 7, 2025, following investigation by third-party specialists. Personal information including names and other data elements may have been accessed. 2 Maine residents were among 7,479 total affected individuals. Notifications sent May 13, 2025; IDX credit monitoring offered.
Maine clockDiscovered Jan 7, 2025 → Filed with AG May 13, 2025126d ✗ ME AG >90d18 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_99daa838a9f34a3dIndiana State AGfiled 2025-05-13Verified
- bd_be8aa70e9935fd48California State AGfiled 2025-05-13Candidate
- bd_08a74b1806c29f8fVermont State AGfiled 2025-05-14(1d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/111f53f5-70c0-4862-b931-3bb6a86b5718.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 13, 2025
- Raw hash
- 0424fb9fd34e5e61f51b4818e7073a60194d88d44ad0d11284519f1a4b5dc570
Reporting entity
- Name
- South Bay Credit Unionnorm: south bay credit union
- Domain
- southbaycu.com
- Industry
- Financial Services
Victim entity
- Name
- South Bay Credit Unionnorm: south bay credit union
- Domain
- southbaycu.com
- Industry
- Financial Services
- Industry
- Financial Servicesllm
Incident
- Discovered
- Jan 7, 2025
- Materiality determined
- —
- Notification sent
- May 13, 2025
- Affected individuals
- 2
- Data types
- PII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
Compliance
- Time to disclose
- 18 weeks(126 days from discovery to filing)
- Compliance flags
- ME AG >90d · 126dME resident >60d · 126d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jan 7, 2025→ Filed with AG: May 13, 2025126d 90 days ME AG >90d Maine Discovered: Jan 7, 2025→ Notified: May 13, 2025126d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.