HackingFinancial ServicesFinanceCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMediumContained
First Financial Credit Union
bd_dc948e8357a87906 · schema v1 · pii pii-v1
Full breach record for First Financial Credit Union →First Financial Credit Union (FFCU) notified members of unauthorized third-party access to computer files between January 17 and February 6, 2022. Potentially exposed data includes names, addresses, Social Security numbers, driver's license/government IDs, financial account information, and credit/debit card information. FFCU secured affected servers, engaged a forensic firm, notified law enforcement, and offered one year of Experian IdentityWorks Credit 3B monitoring.
Leak gap clock⏱ Leak >30d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 2 about the same incident.View merged incident
A leak claim by lockbit2 about this victim predates this filing by 80 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_1a71afc14cbd8765Maine State AGfiled 2022-05-18Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-553514
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 18, 2022
- Raw hash
- f60066acecb19980df789b762988a2ac9f43b8aaf552c03a15fc1a5c591a8881
Reporting entity
- Name
- First Financial Credit Unionnorm: first financial credit union
- Domain
- ffnm.org
Victim entity
- Name
- First Financial Credit Unionnorm: first financial credit union
- Domain
- ffnm.org
- Industry
- Financial Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- May 13, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated CollectionT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Compliance flags
- Leak >30d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.