1st MidAmerica Credit Union
Incident posture
Linked entities
- Victim
- 1st MidAmerica Credit Union
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
1st MidAmerica Credit Union learned of a data breach after its vendor Marquis Software Solutions reported suspicious network activity and confirmed that an unauthorized third party had accessed the vendor’s environment and may have obtained files containing customers’ names and Social Security numbers. The credit union notified affected individuals and the law firm Edelson Lechtzin LLP has begun investigating potential claims on behalf of those whose personal information may have been compromised.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On or about August 14, 2025, 1st MidAmerica Credit Union learned of a data breach after its vendor Marquis Software Solutions notified it of suspicious activity on its network. Marquis determined that a cybersecurity incident had occurred and launched an investigation. The investigation revealed that an unauthorized third party gained access to Marquis's network environment and may have accessed and acquired certain files. These files may have contained personal information related to certain MACU customers, including names and Social Security numbers.
The potential exposure of names and Social Security numbers raises concerns about identity theft and fraud for affected customers. In response, Marquis conducted an investigation to determine the scope of the unauthorized access. Additionally, the law firm Edelson Lechtzin LLP announced on February 1, 2026 that it is investigating data privacy claims on behalf of MACU customers whose data may have been compromised. The firm is pursuing a class action lawsuit to seek legal remedies for individuals whose sensitive personal data may have been compromised. MACU is a nonprofit, member-owned financial institution that offers a range of banking and lending services to support its members' financial goals. The breach was disclosed publicly through a press release issued by Edelson Lechtzin LLP on February 1, 2026.
Sources
Sources available to members: 2 sources.