HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
UNIVERSITY FEDERAL CREDIT UNION
bd_f0cf02b02814adcc · schema v1 · pii pii-v1
Full breach record for UNIVERSITY FEDERAL CREDIT UNION →University Federal Credit Union (UFCU) notified consumers on October 10, 2023, of a data breach involving its vendor, Progress Software's MOVEit transfer platform. The incident, discovered on September 15, 2023, involved unauthorized access to files containing member personal information (including SSNs) copied from the MOVEit platform. No evidence of financial fraud was found. UFCU engaged third-party investigators and offered 12 months of credit monitoring. The breach affects members across multiple US states.
Vermont clock⏱ VT AG >14 bday25 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_5b896898ca06cc29Maine State AGfiled 2023-10-09(1d gap)Candidate
- bd_9d100ecc7e0e5184California State AGfiled 2023-10-09(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-10-10-university-federal-credit-union-progress-software-moveit-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 10, 2023
- Raw hash
- fc9679dcdc5c09f4dc98b95411928fdbe8758bf7810d27762b80b4ddf27bb381
Reporting entity
- Name
- UNIVERSITY FEDERAL CREDIT UNIONnorm: university federal credit union
Victim entity
- Name
- UNIVERSITY FEDERAL CREDIT UNIONnorm: university federal credit union
Incident
- Discovered
- Sep 15, 2023
- Materiality determined
- —
- Notification sent
- Oct 10, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Third party
- via Progress Software (MOVEit)
- Initial access
- supply_chain
Compliance
- Time to disclose
- 25 days(25 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.