[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1zgp3scyffmdi":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":29,"seoTitle":30,"seoTitleEn":31,"seoDescription":30,"seoDescriptionEn":32,"logoUrl":33,"isVerified":4,"isSensitive":4,"isSpamList":34,"isMalware":34,"company":35},"6a7161c25bb8ab75be8a7659","ConnexCreditUnion2025","Connex Credit Union 2025 Data Breach","connex-credit-union-2025","connexcu.org","2025-06-02T00:00:00.000Z","2026-08-04T03:51:29.999Z","Connex notice, Maine and Texas Attorneys General, and BleepingComputer","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20250809174104id_\u002Fhttps:\u002F\u002Fwww.maine.gov\u002Fagviewer\u002Fcontent\u002Fag\u002F985235c7-cb95-4be2-8792-a1252b4f8318\u002Fba496af0-2688-4929-ad01-f07a4d8972cf.html",[14,16,17],"https:\u002F\u002Foag.my.site.com\u002Fdatasecuritybreachreport\u002Fapex\u002FDataSecurityReportsPage","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fconnex-credit-union-discloses-data-breach-impacting-172-000-people\u002F",172000,"known",null,"people","High",[24,25,26,27,28],"Names","Social security numbers","Government issued IDs","Financial account information","Bank account numbers","\u003Cp>\u003Cstrong>The 2025 Connex Credit Union data breach\u003C\u002Fstrong> involved unauthorized access to or downloading of certain files on the credit union's network. State filings report 172,000 affected people nationwide.\u003C\u002Fp>\u003Cp>Connex is a Connecticut-based, member-owned credit union. The affected information varied by person, and not every listed field was present for every member.\u003C\u002Fp>\u003Ch2>When did the Connex Credit Union data breach occur?\u003C\u002Fh2>\u003Cp>Connex detected unusual activity in its cyber environment on June 3, 2025. Its investigation found that certain files may have been accessed or downloaded without authorization between June 2 and June 3.\u003C\u002Fp>\u003Cp>The organization completed its work to identify affected people on July 27, 2025. Notification letters were sent on August 7, and the Texas filing was published on August 8.\u003C\u002Fp>\u003Ch2>How did the incident happen?\u003C\u002Fh2>\u003Cp>The official filing classifies the incident as an external-system breach involving unauthorized file access. Connex began an investigation with independent specialists after detecting unusual network activity.\u003C\u002Fp>\u003Cp>The method used to enter the system, the technical access path, and the attacker's identity were not disclosed. The reviewed sources do not confirm ransomware or attribution to a particular threat group.\u003C\u002Fp>\u003Ch2>What information was affected?\u003C\u002Fh2>\u003Cp>Depending on the person, the affected files could contain a name, account number, Social Security number, and other government identification used to open an account.\u003C\u002Fp>\u003Cp>The regulatory letter filed in Maine says debit card information could also have been involved for some people. Connex said it had no reason to believe the incident involved unauthorized access to member accounts or funds.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>Maine and Texas regulatory filings report 172,000 affected people nationwide. The 965 Texas residents and 467 Maine residents are included in that national total and are not additional counts.\u003C\u002Fp>\u003Ch2>What risks can this incident create?\u003C\u002Fh2>\u003Cp>Social Security numbers and government identification can support identity theft or fraudulent account applications. Account and debit card information can also make bank-impersonation scams more convincing or create a risk of unauthorized transaction attempts.\u003C\u002Fp>\u003Cp>The notice says there was no indication that member accounts or funds were accessed. Even so, a caller or message claiming to represent Connex and asking for a PIN, passcode, or account number is an important fraud warning sign.\u003C\u002Fp>\u003Ch2>How did Connex respond?\u003C\u002Fh2>\u003Cp>The credit union said it secured its network, investigated with independent specialists, and strengthened security measures. It also notified the National Credit Union Administration and federal law enforcement and offered affected people credit monitoring and identity protection through Cyberscout.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients should review account and debit card activity, credit reports, and unfamiliar accounts opened in their name. If a suspicious transaction appears, contact Connex or the relevant institution only through an official communication channel.\u003C\u002Fp>\u003Cp>People whose Social Security number or government identification was affected can consider a free fraud alert or security freeze. Do not provide a PIN, password, verification code, or account number in response to an unexpected call or message.\u003C\u002Fp>","","Connex Credit Union Data Breach (172 Thousand People Affected)","The Connex Credit Union data breach affected 172,000 people. Learn when it happened, what information was involved, and how to respond.","\u002Fuploads\u002Flogo\u002Fconnex-credit-union.png",false,{"name":36,"sector":37,"country":38,"website":39,"websiteArchiveUrl":30,"websiteStatus":30,"websiteCheckedAt":20},"Connex Credit Union","Financial Services","United States","https:\u002F\u002Fwww.connexcu.org\u002Fhome\u002Fhome"]