Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
MAINSTREET FEDERAL CREDIT UNION
bd_dc1bebca2267480f · schema v1 · pii pii-v1
Full breach record for MAINSTREET FEDERAL CREDIT UNION →Mainstreet Credit Union notified the NH Attorney General of a cybersecurity event affecting one NH resident. An unauthorized actor accessed an employee's email account between Jan 12-20, 2026, likely via phishing. The actor accessed one resident's name and financial account number. MCU secured the account, engaged forensic investigators, and mailed notification on June 18, 2026.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_95a5aa203651f160Indiana State AGfiled 2026-05-04(45d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/mainstreet-credit-union-20260618.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 18, 2026
- Raw hash
- cb214370f428906e4a0a646c288a2ee65a45a5c464a755c4587b0e64e7defac6
Reporting entity
- Name
- MAINSTREET FEDERAL CREDIT UNIONnorm: mainstreet federal credit union
Victim entity
- Name
- MAINSTREET FEDERAL CREDIT UNIONnorm: mainstreet federal credit union
Incident
- Discovered
- Jan 12, 2026
- Materiality determined
- —
- Notification sent
- Jun 18, 2026
- Affected individuals
- 1
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General's Office
- Initial access
- phishing_link
Compliance
- Time to disclose
- 22 weeks(157 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.