DisclosureLens
HackingFinancial ServicesFinanceVulnerability ExploitData ExfiltratedCustomer Data InvolvedIdentity (basic)Government IDFinancial accountPIIMediumContained

Quorum Federal Credit Union

bd_fc30fcc8f9d3ce42 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 20, 2023

Filed

Jul 17, 2023

To disclose

27 days

Affected

802state residents only

Linked

7 filings

Confidence

69%
Full breach record for Quorum Federal Credit Union2 incidents on file

Quorum Federal Credit Union experienced unauthorized access to files containing personal information of 802 Washington residents due to a vulnerability in the MOVEit file transfer tool. The incident occurred between May 28 and May 31, 2023, and was discovered on June 20, 2023. Affected data included names, SSNs, driver's license numbers, financial account numbers, and payment card information. Notifications were sent on July 17, 2023, with credit monitoring services offered.

Washington clock WA AG ≤30d27 days discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 23 days
discovery → filing · 27 days

May 28, 2023

Begins

Jun 20, 2023

Discovered

Jul 17, 2023

Filed

vs. sector median

5 wks faster

This filing is one of 7 about the same incident.View merged incident
Part of Progress Software Corporation supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Ransomware claims (2)

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 5 states

View merged incident ↗
Montana State AGJul 17 · first
California State AGJul 17 · first
Massachusetts State AGJul 17 · first
Maine State AGJul 17 · first
Washington State AGJul 17 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.