Suffolk Credit Union
Incident posture
Linked entities
- Victim
- Suffolk Credit Union
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Suffolk Credit Union experienced a data breach that originated at a former vendor, Mercadien, P.C., CPAs, where an unauthorized third party accessed part of the vendor’s computer environment over a period of several weeks. The intrusion was detected several months after it began, and the vendor finished its review and shared the results with the credit union months later. Following the review, the credit union began notifying affected individuals that their names, Social Security numbers, financial account numbers, government‑issued identification numbers and other identity verification information may have been exposed. Regulators in Delaware, California, Vermont and Hawaii were informed of the incident. The credit union stated it has no evidence of misuse and offered affected members a complimentary two‑year identity‑protection service.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On November 7, 2025, Mercadien, P.C., CPAs, a former service provider to Suffolk Credit Union, detected unauthorized access to part of its computer environment. Its investigation determined that an unauthorized third party may have accessed certain data between September 17, 2025, and October 9, 2025. The intrusion was confined to Mercadien's systems and did not involve Suffolk Credit Union's own network. Mercadien completed its review and provided the results to Suffolk Credit Union on August 13, 2026.
Suffolk Credit Union began notifying affected individuals on September 11, 2026, after receiving the vendor's findings. The exposed information included names, Social Security numbers, financial account numbers, government‑issued identification numbers, and other identity verification data. Because the breach originated at a third‑party vendor, Suffolk Credit Union stated that its own systems were not accessed and that it has no evidence of misuse of the compromised data. To assist those impacted, the credit union offered a complimentary two‑year membership in Experian IdentityWorks Credit 3B, which provides credit monitoring, identity restoration, and up to one million dollars in identity theft insurance, with an enrollment deadline of December 31, 2026.
Regulators in Delaware, California, and Vermont, along with the Hawaii Office of Consumer Protection, were notified of the incident. Edelson Lechtzin LLP launched an investigation into potential data privacy claims and is offering free case evaluations to individuals whose personal information may have been compromised. Suffolk Credit Union remains a member‑owned, not‑for‑profit financial institution that continues to serve its members while addressing the aftermath of the vendor‑related breach.
Sources
Sources available to members: 1 source.