Fairmont Federal Credit Union (FFCU)

Fairmont Federal Credit Union (FFCU)

Fairmont Federal Credit Union (FFCU) experienced a severe cybersecurity incident exposing the personal and sensitive data of over 180,000 individuals. The breach compromised a wide range of highly confidential information, including full names, Social Security numbers, financial account details (routing numbers, credit/debit card data, PINs), government-issued IDs (driver’s licenses, passports, military IDs), tax identification numbers, and extensive health records (treatment/diagnosis, Medicare/Medicaid numbers, health insurance details, and medical IDs). The exposed data also included full access credentials, security questions/answers, and digital signatures, posing a critical risk of identity theft, financial fraud, and unauthorized access to sensitive accounts. The incident prompted a legal investigation by Lynch Carpenter LLP, with affected individuals potentially eligible for compensation. The scale and sensitivity of the leaked data suggest a large-scale, high-impact breach with long-term repercussions for victims, including financial loss, reputational harm, and heightened vulnerability to cybercrime.

Source: https://www.globenewswire.com/news-release/2025/09/12/3149342/0/en/Lynch-Carpenter-Investigates-Claims-in-Fairmont-Federal-Credit-Union-Data-Breach.html

TPRM report: https://www.rankiteo.com/company/fairmont-federal-credit-union

"id": "fai3992439091225",
"linkid": "fairmont-federal-credit-union",
"type": "Breach",
"date": "9/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '180,000+ individuals',
                        'industry': 'Financial Services',
                        'location': 'Pittsburgh, Pennsylvania, USA (inferred '
                                    'from press release location)',
                        'name': 'Fairmont Federal Credit Union (FFCU)',
                        'type': 'Credit Union'}],
 'customer_advisories': 'Individuals who received breach notifications may '
                        'contact Lynch Carpenter, LLP for legal review via '
                        'form, phone ((412) 322-9243), or email '
                        '(jerry@lcllp.com)',
 'data_breach': {'data_exfiltration': 'Likely (given the nature of the breach '
                                      'and data types exposed)',
                 'number_of_records_exposed': '180,000+',
                 'personally_identifiable_information': 'Yes (comprehensive '
                                                        'PII including '
                                                        'government-issued '
                                                        'IDs, financial data, '
                                                        'and health records)',
                 'sensitivity_of_data': 'Extremely High (includes SSNs, '
                                        'financial account details, health '
                                        'records, and authentication '
                                        'credentials)',
                 'type_of_data_compromised': ['Personally Identifiable '
                                              'Information (PII)',
                                              'Financial Information',
                                              'Health Information (PHI)',
                                              'Authentication Credentials']},
 'date_publicly_disclosed': '2025-04-28',
 'description': 'Fairmont Federal Credit Union (FFCU) announced a '
                'cybersecurity incident impacting the personal information of '
                'over 180,000 individuals. The breach exposed a wide range of '
                'sensitive data, including financial, identification, and '
                'health-related information. Not all data elements were '
                'impacted for every individual.',
 'impact': {'brand_reputation_impact': 'Potential significant reputational '
                                       'damage due to exposure of highly '
                                       'sensitive personal and financial data',
            'data_compromised': ['Full name',
                                 'Date of birth',
                                 'Address',
                                 'Social Security number',
                                 'U.S. Alien registration number',
                                 'Passport number',
                                 'Driver’s license or state ID number',
                                 'Military ID number',
                                 'Tax ID number',
                                 'Non-U.S. national identification number',
                                 'Financial account number',
                                 'Routing number',
                                 'Financial institution name',
                                 'Credit card/debit card number',
                                 'Security code/PIN number',
                                 'Credit card/debit card expiration date',
                                 'IRS PIN number',
                                 'Treatment information/diagnosis',
                                 'Prescription information',
                                 'Provider name',
                                 'MRN/patient ID',
                                 'Medicare/Medicaid number',
                                 'Health insurance policy/subscriber number',
                                 'Other health insurance information',
                                 'Treatment cost information',
                                 'Full access credentials',
                                 'Security questions and answers',
                                 'Digital signatures'],
            'identity_theft_risk': 'High (due to exposure of SSNs, financial '
                                   'account details, and other PII)',
            'legal_liabilities': 'Under investigation by Lynch Carpenter, LLP '
                                 'for potential class action claims; '
                                 'individuals may be entitled to compensation',
            'payment_information_risk': 'High (credit/debit card numbers, '
                                        'security codes, expiration dates, and '
                                        'financial account details exposed)'},
 'investigation_status': 'Ongoing (legal investigation by Lynch Carpenter, '
                         'LLP; no technical investigation details provided)',
 'references': [{'date_accessed': '2025-09-12',
                 'source': 'Maine Attorney General - Data Breach Notification',
                 'url': 'https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/75c92a2c-3791-47c6-84f7-87b34fab952d.html'},
                {'date_accessed': '2025-09-12',
                 'source': 'Fairmont Federal Credit Union - Substitute Notice '
                           '(PDF)'},
                {'date_accessed': '2025-09-12',
                 'source': 'Globe Newswire Press Release'}],
 'regulatory_compliance': {'legal_actions': 'Potential class action lawsuit '
                                            'being investigated by Lynch '
                                            'Carpenter, LLP',
                           'regulatory_notifications': 'Notification filed '
                                                       'with the Maine '
                                                       'Attorney General (as '
                                                       'per provided '
                                                       'reference)'},
 'response': {'communication_strategy': 'Public disclosure via substitute '
                                        'notice (PDF) and press release; '
                                        'potential individual notifications '
                                        'sent to affected parties'},
 'title': 'Fairmont Federal Credit Union Data Breach',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.