FIRST HARVEST Federal Credit Union
ent_019e10f427e1419640dcca583fed467b
Disclosures
4
State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
16
as filed · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- FIRST HARVEST Federal Credit Union
- Normalized
- first harvest federal credit union— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493002P6EVQ94HFYF14
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- firstharvestcu.com
Disclosure history (4)newest first
- 🍁Vermont State AGas victim2026-05-06
First Harvest Federal Credit Union reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-05-06. The reporting organization type is Financial Services. 7 Vermont residents were affected. Categories of data breached: Social Security Numbers, Financial Account Codes, Credit or Debit Account Info.
- 🦞Maine State AGas victim2026-05-06
First Harvest Federal Credit Union, a New Jersey-based federal credit union, experienced an external system breach (hacking) that occurred on January 14, 2026 and was discovered on April 17, 2026. Eight Maine residents were affected. Written notifications were sent on May 6, 2026. Affected individuals were offered 12 months of credit monitoring through Experian.
- ⛰️New Hampshire State AGas victim2026-05-06
First Harvest Federal Credit Union notified the NH AG of a data event affecting 16 NH residents. An unknown actor accessed an employee email account on Jan 14, 2026, after suspicious activity was detected on Feb 3, 2026. Data potentially exposed included names, SSNs, and financial/payment card info. The credit union provided 12 months of credit monitoring via Kroll/Experian and notified regulators.
- 🏛️Massachusetts State AGas victim2026-05-01
First Harvest Federal Credit Union notified Massachusetts and Rhode Island residents of a security incident involving unauthorized access to an employee email account. The breach, discovered on February 3, 2026, resulted from suspicious activity likely stemming from a phishing attack on January 14, 2026. The incident exposed name data elements and potentially government identifiers (SSN, DOB, driver's license) of affected individuals. First Harvest engaged third-party forensic reviewers, enhanced security policies, and offered 12-24 months of credit monitoring via Experian. No actual misuse of information was indicated at the time of notification.