NIH Federal Credit Union notified 14,706 members after an email account breach
- Organization
- National Institutes of Health Federal Credit Union (NIHFCU)
- Exploit
- Credential Compromise
- Industry
- Financial Services
The National Institutes of Health Federal Credit Union filed a data breach notice with the Maine attorney general's office on July 5, 2023, reporting that an outside party had gained access to an employee's email account. The credit union said the account was accessible to the intruder for a few hours on April 11, 2023.
After securing the account, NIHFCU brought in outside cybersecurity specialists and reviewed the messages and attachments the mailbox contained. That review found consumer information in some of them. The credit union then worked through the affected files to identify the individuals involved and locate current contact details for them.
NIHFCU reported that names and Social Security numbers were among the data exposed, with the specific information varying from person to person. The filing put the number of people notified at 14,706. Credit union trade coverage described the total as roughly 15,000 members.
Notification letters went to all affected individuals once the review was complete. The incident later produced a class action, resolved through a settlement that made up to $295,000 available for member claims and provided a year of credit monitoring, with a claims deadline of March 20, 2024 and a final approval hearing scheduled for April 2024.