HackingStolen CredentialsTargetedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
VERIDIAN CREDIT UNION
bd_df005db7b005d523 · schema v1 · pii pii-v1
Full breach record for VERIDIAN CREDIT UNION →Veridian Credit Union notified consumers of a data security incident occurring April 1-2, 2023. Attackers used stolen personal information to initiate fraudulent membership applications, potentially accessing credit reports containing names, SSNs, DOBs, and financial account numbers. Veridian engaged law enforcement and offered 12-24 months of identity protection services via IDX.
Vermont clock⏱ VT AG >14 bday4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_7dfc0628881503dbNew Hampshire State AGfiled 2023-05-03Verified
- bd_852539b85bef505dCalifornia State AGfiled 2023-05-03Candidate
- bd_e261fb48faace56cMontana State AGfiled 2023-05-03Verified
- bd_6d3256afd8b9ce20Maine State AGfiled 2023-05-04(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-05-03-veridian-credit-union-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 3, 2023
- Raw hash
- 14232c0c847619c447e929c6e7caf556880637570698e87505c59b442d2d0bcf
Reporting entity
- Name
- VERIDIAN CREDIT UNIONnorm: veridian credit union
- Domain
- veridiancu.org
Victim entity
- Name
- VERIDIAN CREDIT UNIONnorm: veridian credit union
- Domain
- veridiancu.org
Incident
- Discovered
- Apr 2, 2023
- Materiality determined
- —
- Notification sent
- May 3, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Vermont Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.