CSIDB logo
Incident

Hawaii First Federal Credit Union

Incident posture

Attack window
Jun 2015
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-15 11:14

Linked entities

Victim
Hawaii First Federal Credit Union
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2015
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Hawaii First Federal Credit Union experienced a breach where an unauthorized individual potentially accessed an employee's email account containing members' personal information, including names, addresses, Social Security numbers, and bank account details. The organization terminated the compromised account access immediately, reset passwords, initiated a security review, and notified all potentially affected individuals while offering complimentary identity theft protection services. Though no misuse of information was reported, the credit union proactively communicated the incident as a precautionary measure to ensure transparency and reinforce its commitment to safeguarding member data.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On June 1, 2015, Hawaii First Federal Credit Union discovered that an unauthorized individual may have gained access to an employee’s email account, potentially compromising customer personal information. The breach exposed sensitive data including names, addresses, Social Security numbers, and bank account numbers, though the exact number of affected individuals remained undisclosed. The credit union acted swiftly to terminate access to the compromised email account and reset all passwords to prevent further unauthorized activity. While no reports indicated misuse of the exposed information at the time of discovery, the organization initiated a comprehensive review of its information security practices and procedures to address vulnerabilities. The incident stemmed from unauthorized access to a single employee account, highlighting risks associated with email-based data storage.

In response to the breach, Hawaii First Federal Credit Union notified all potentially affected customers by August 31, 2015, advising them of the incident through direct communication. The notification letter emphasized the absence of confirmed identity theft or credit misuse but acknowledged the seriousness of the exposure. As a remedial measure, the credit union offered impacted individuals a free year of identity theft protection services to mitigate potential financial or reputational harm. The organization’s public statement underscored its cautionary approach, prioritizing transparency despite the lack of evidence regarding malicious exploitation of the data. These actions reflected immediate containment efforts alongside longer-term commitments to strengthen security protocols following the internal review.

Sources

Sources available to members: 1 source.

CSIDB