HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
ALOHA PACIFIC FEDERAL CREDIT UNION
bd_e78d2bcf9eaba2b2 · schema v1 · pii pii-v1
Full breach record for ALOHA PACIFIC FEDERAL CREDIT UNION →Aloha Pacific Federal Credit Union notified consumers of a data breach involving its vendor, Darling Consulting Group, which used Progress Software's MOVEit file transfer tool. A vulnerability in MOVEit allowed unauthorized access to files containing member PII, including names, SSNs, DOBs, and credit card numbers. Aloha FCU's own systems were not accessed. The credit union is offering 12 months of Experian IdentityWorks credit monitoring.
Vermont clock✗ VT AG >45 bday13 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_2ce3165ff117dec8Montana State AGfiled 2023-08-30Candidate
- bd_54201b9c2d71a38bMaine State AGfiled 2023-08-30Candidate
- bd_ccb3f82da7b671b6Hawaii State AGfiled 2023-08-30Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-08-30-aloha-pacific-federal-credit-union-progress-software-moveit-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 30, 2023
- Raw hash
- 42b0af274b5254eb733cc0d043f4c4ba26161afa4f0862eb3ceec392a8ed0af1
Reporting entity
- Name
- ALOHA PACIFIC FEDERAL CREDIT UNIONnorm: aloha pacific federal credit union
Victim entity
- Name
- ALOHA PACIFIC FEDERAL CREDIT UNIONnorm: aloha pacific federal credit union
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Aug 30, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 weeks(91 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.