Chevron Federal Credit Union
ent_8f6c6e58afa7f952
Disclosures
8
State AG · Leak Site · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
90,536
nationwide · State AG ME
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- Chevron Federal Credit Union
- Normalized
- chevron federal credit union— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- chevronfcu.org
Disclosure history (8)newest first
- Maine State AGas victim2023-08-29
Chevron Federal Credit Union reported a data breach impacting 90,536 individuals due to a third-party vendor's compromise involving the MOVEit vulnerability. The incident occurred between May 30 and May 31, 2023, and was discovered on August 1, 2023. The compromised information includes names and Social Security numbers. The credit union offered 12 months of credit monitoring services through Experian.
- Oregon State AGas victim2023-08-24
Chevron Federal Credit Union ("CFCU") reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-24. The breach occurred during 5/30/2023 - 5/31/2023. The breach was discovered on 8/1/2023. 90,536 individuals were affected. Notice was sent on 8/24/2023.
- Montana State AGas victim2023-08-24
Chevron Federal Credit Union notified members of a data breach involving the MOVEit file transfer application. An unauthorized party exploited a previously unknown vulnerability between May 30-31, 2023, to decrypt and download personal information. The breach was discovered on August 1, 2023, following a re-investigation prompted by new detection methodologies published by a cybersecurity firm. The Credit Union engaged forensic investigators, remediated the vulnerability, and offered one year of complimentary credit monitoring to affected individuals.
- California State AGas victim2023-08-24
Chevron Federal Credit Union experienced a data breach involving the MOVEit file transfer service provided by Progress Software. An unauthorized party exploited a previously unknown vulnerability (zero-day) in the MOVEit application to decrypt and download files between May 30 and May 31, 2023. The incident was discovered on August 1, 2023, after new detection methods were published. Personal information, including basic identity data, was compromised. The organization engaged third-party forensics, remediated the vulnerability, and offered one year of credit monitoring to affected members.
- Massachusetts State AGas victim2023-08-24
Chevron Federal Credit Union reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-08-24. 195 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGas victim2023-08-24
Chevron Federal Credit Union (CFCU) notified Washington AG of a data breach involving unauthorized access to its MOVEit file transfer application. The incident occurred May 30-31, 2023, and was discovered in late July 2023 after a third-party firm published new detection methods. 947 Washington residents were affected. CFCU engaged forensic investigators and offered one year of credit monitoring.
- GLOBALLeak Siteas victim2023-07-26
Chevron Federal Credit Union
- GLOBALLeak Siteas victim2021-11-26
chevronfcu.org