CSIDB logo
Incident

Suffolk Credit Union

Incident posture

Attack window
Sep 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-18 17:18

Linked entities

Victim
Suffolk Credit Union
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2025
Discovered
Nov 2025
Disclosed
Sep 2026
Resolved
Pending

Summary

Suffolk Credit Union experienced a data breach that originated at a former vendor, Mercadien, P.C., CPAs, where an unauthorized third party accessed part of the vendor’s computer environment over a period of several weeks. The intrusion was detected several months after it began, and the vendor finished its review and shared the results with the credit union months later. Following the review, the credit union began notifying affected individuals that their names, Social Security numbers, financial account numbers, government‑issued identification numbers and other identity verification information may have been exposed. Regulators in Delaware, California, Vermont and Hawaii were informed of the incident. The credit union stated it has no evidence of misuse and offered affected members a complimentary two‑year identity‑protection service.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On November 7, 2025, Mercadien, P.C., CPAs, a former service provider to Suffolk Credit Union, detected unauthorized access to part of its computer environment. Its investigation determined that an unauthorized third party may have accessed certain data between September 17, 2025, and October 9, 2025. The intrusion was confined to Mercadien's systems and did not involve Suffolk Credit Union's own network. Mercadien completed its review and provided the results to Suffolk Credit Union on August 13, 2026.

Suffolk Credit Union began notifying affected individuals on September 11, 2026, after receiving the vendor's findings. The exposed information included names, Social Security numbers, financial account numbers, government‑issued identification numbers, and other identity verification data. Because the breach originated at a third‑party vendor, Suffolk Credit Union stated that its own systems were not accessed and that it has no evidence of misuse of the compromised data. To assist those impacted, the credit union offered a complimentary two‑year membership in Experian IdentityWorks Credit 3B, which provides credit monitoring, identity restoration, and up to one million dollars in identity theft insurance, with an enrollment deadline of December 31, 2026.

Regulators in Delaware, California, and Vermont, along with the Hawaii Office of Consumer Protection, were notified of the incident. Edelson Lechtzin LLP launched an investigation into potential data privacy claims and is offering free case evaluations to individuals whose personal information may have been compromised. Suffolk Credit Union remains a member‑owned, not‑for‑profit financial institution that continues to serve its members while addressing the aftermath of the vendor‑related breach.

Sources

Sources available to members: 1 source.

CSIDB