The breach originated not within the credit union’s internal infrastructure, but at Mercadien, P.C., CPAs, a former service provider. Unauthorized actors gained access to the firm’s environment between September 17 and October 9, 2025, though the intrusion was not identified until November 7. It took nearly ten months for the review process to conclude, with Suffolk Credit Union finally initiating member notifications on September 11, 2026.
The scope of the stolen data is extensive, encompassing names, government-issued identification, and financial account details. While Suffolk Credit Union maintains there is no current evidence of data misuse, it has provided affected members with two years of Experian IdentityWorks credit monitoring. Legal experts warn that the sensitivity of the exposed information necessitates immediate action, including the potential placement of credit freezes and rigorous monitoring of financial statements for suspicious activity. Individuals must enroll in the provided identity protection services by December 31, 2026.

Comments (0)
No comments yet. Be the first!