POLAM Federal Credit Union
Incident posture
Linked entities
- Victim
- POLAM Federal Credit Union
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
POLAM Federal Credit Union learned that a former employee illegally accessed and obtained documents from its system, exposing personal information such as full names, addresses, Social Security numbers, credit and debit card numbers, driver’s license numbers, financial account numbers, IRS e‑file PINs, loan numbers, passport numbers, medical details, taxpayer identification numbers, and alien registration numbers. The breach prompted a third‑party cybersecurity investigation and led Edelson Lechtzin LLP to launch a look into potential class action claims on behalf of affected individuals who may have had their personal information exposed.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On or about May 20, 2025, POLAM Federal Credit Union learned that it had experienced a data breach. The credit union was notified on or around that date that a former employee had illegally accessed and obtained specific documents from its internal systems. Upon receiving the alert, the organization engaged third‑party cybersecurity professionals to conduct an investigation into the incident. The investigators determined that the former employee’s unauthorized access had resulted in the acquisition of certain files containing personal data.
The investigation indicated that the breach may have exposed a broad range of personal information belonging to individuals associated with the credit union. This information includes full names, residential addresses, Social Security numbers, credit and/or debit card numbers (without associated passwords or security codes), driver’s license numbers, financial account numbers both with and without passwords or routing numbers, Internal Revenue Service e‑file personal identification numbers, loan numbers, passport numbers, medical history, condition, treatment, or diagnosis details, individual taxpayer identification numbers, and alien registration numbers. Individuals who received a data breach notification from POLAM Federal Credit Union were identified as potentially facing an increased risk of identity theft and fraud as a consequence of the exposure.
In response to the breach, POLAM Federal Credit Union issued notifications to affected individuals informing them of the incident and the types of information that may have been compromised. The credit union’s engagement of third‑party cybersecurity experts formed part of its containment and assessment efforts. Simultaneously, the national class action law firm Edelson Lechtzin LLP announced that it was investigating potential data privacy claims arising from the breach and was evaluating the possibility of pursuing a class action on behalf of those whose sensitive personal data may have been compromised. POLAM Federal Credit Union is described as a financial institution created to serve members of the Polish American community, while Edelson Lechtzin LLP is noted as a national class action law firm with offices in Pennsylvania and California that handles a variety of litigation matters including data breach cases.
Sources
Sources available to members: 1 source.