CSIDB logo
Incident

Fairwinds Credit Union

Incident posture

Attack window
Nov 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-25 16:29

Linked entities

Victim
Fairwinds Credit Union
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2025
Discovered
Nov 2025
Disclosed
Sep 2026
Resolved
Pending

Summary

A data breach at a vendor exposed personal and financial information of members of Fairwinds Credit Union. The credit union learned of the incident after being notified by the vendor, which had detected unauthorized access to its systems. An investigation determined that the intruder had obtained data including names, Social Security numbers, financial account details and driver’s license numbers. Affected individuals received breach notifications and were offered free identity and credit protection services. The credit union terminated its relationship with the vendor and reported the incident to state regulators.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Fairwinds Credit Union discovered suspicious activity on its vendor Mercadien's systems on November 7, 2025, prompting an investigation that determined an unauthorized actor had accessed and acquired information from Mercadien's systems between September 7, 2025, and November 7, 2025. Fairwinds had engaged Mercadien to perform an independent review for quality control and regulatory compliance. The breach was not detected within Fairwinds' own environment but rather in the systems of its third‑party service provider. After completing its internal review, Fairwinds notified affected individuals and reported the incident to state regulators on or about September 23, 2026.

The information potentially exposed included names, Social Security numbers, financial account details, and driver's license numbers, although the exact number of affected individuals remains unknown; breach notices were sent to New Hampshire residents. Fairwinds stated that it became aware of the breach in August 2026 and completed its review in September 2026 before issuing notices. In response, Fairwinds ended its contractual relationship with Mercadien and began offering affected members free identity and credit protection services. The incident raised concerns about increased risk of identity theft and fraud for those whose data may have been compromised.

Following the disclosure, the national class action law firm Edelson Lechtzin LLP announced an investigation into potential data privacy claims arising from the breach, indicating it would evaluate whether a class action could be pursued on behalf of individuals whose personal information may have been exposed. No further details about the outcome of the investigation or any legal proceedings were provided in the source material.

Sources

Sources available to members: 1 source.

CSIDB