[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1qq25s35tqpys":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":4,"isSpamList":37,"isMalware":37,"company":38},"6a6f8d7b59eead31f50905d7","EducationalEmployeesCreditUnion2025","EECU Data Breach","educational-employees-credit-union-2025","myeecu.org","2025-12-15T00:00:00.000Z","2026-08-02T18:33:31.635Z","Unauthorized access to one employee email account with certain messages potentially accessed or removed","https:\u002F\u002Foag.ca.gov\u002Fecrime\u002Fdatabreach\u002Freports\u002Fsb24-624147",[14,16],"https:\u002F\u002Foag.my.site.com\u002Fdatasecuritybreachreport\u002Fapex\u002FDataSecurityReportsPage",201185,"known",null,"people","High",[23,24,25,26,27,28,29,30,31],"Names","Physical addresses","Dates of birth","Social security numbers","Government IDs","Driver's license numbers","Passport numbers","Financial account information","Credit card numbers","\u003Cp>Educational Employees Credit Union (EECU) is a credit union serving California's Central San Joaquin Valley. According to the Texas Attorney General record, the December 15, 2025 incident affected 201,185 people nationwide.\u003C\u002Fp>\u003Cp>EECU said it discovered the same day that an unauthorized individual had accessed one employee email account for a limited period. The credit union secured its email environment, engaged outside cybersecurity specialists, and offered notice recipients two years of identity-monitoring services.\u003C\u002Fp>\u003Ch2>Confirmed timeline\u003C\u002Fh2>\u003Cp>The investigation found that the unauthorized individual may have accessed or removed certain emails in the account on December 15, 2025. The sources do not identify how the account was initially accessed or name a specific threat actor.\u003C\u002Fp>\u003Cp>A detailed content review confirmed on May 8, 2026 that personal information may have been affected. The California filing and consumer letters were dated May 29, and the Texas record was published June 1; the May date marks completion of the scope review, not the initial access date.\u003C\u002Fp>\u003Ch2>What information may have been affected?\u003C\u002Fh2>\u003Cp>Depending on the person, affected information may include names, addresses, dates of birth, Social Security or tax identification numbers, driver's-license or state-ID numbers, passport numbers, financial-account information, and credit or debit card numbers, expiration dates, and security codes.\u003C\u002Fp>\u003Cp>The 949 people listed in Texas are a state subset within the nationwide total of 201,185 and are not added separately. Not every listed field should be assumed for every person; an individual's notice letter identifies the categories relevant to that recipient.\u003C\u002Fp>\u003Ch2>Identity and tax-fraud risks\u003C\u002Fh2>\u003Cp>A combination of Social Security, tax, passport, and driver's-license information can support fraudulent credit applications, tax filings, or account-recovery attempts. Real names and addresses can make those requests appear more convincing.\u003C\u002Fp>\u003Cp>Notice recipients should enroll in monitoring only through the channel in the official letter, review their credit reports, and consider a credit freeze or fraud alert. Anyone whose tax identifier or government document information was involved should also watch for unusual tax and identity activity.\u003C\u002Fp>\u003Ch2>Financial-account and card security\u003C\u002Fh2>\u003Cp>People whose individual notice includes financial-account or card information should contact the relevant bank or card issuer directly. Review recent activity and request a new card, account number, or security information when appropriate.\u003C\u002Fp>\u003Cp>The sources do not say that EECU online-banking passwords or one-time authentication codes were affected. Those fields should not be added to the incident scope, although unexpected login or transfer alerts should still be verified independently.\u003C\u002Fp>\u003Ch2>Watch for EECU-themed fraud\u003C\u002Fh2>\u003Cp>Someone who knows a real name, address, or financial context may impersonate EECU in a fake security alert, card-replacement request, account-verification message, or refund offer. Personal details in a message do not authenticate its sender.\u003C\u002Fp>\u003Cp>Do not use a link or phone number supplied in the message. Verify the request through EECU's official website, the number on the back of a card, or another previously known channel, and never disclose a password, one-time code, or card security detail during an unexpected call.\u003C\u002Fp>\u003Ch2>How should a result be interpreted?\u003C\u002Fh2>\u003Cp>\u003Cstrong>A positive match connected to this incident is sufficient reason to check the fields in the person's own notice and apply appropriate identity and financial protections.\u003C\u002Fstrong> It does not prove that every category above belonged to that person or that the information was misused.\u003C\u002Fp>\u003Cp>A negative result does not guarantee that no record exists in another incident. Anyone who received a direct EECU notice should follow its deadlines and protective steps regardless of a search result.\u003C\u002Fp>","","EECU Data Breach (201.2 Thousand People Affected)","EECU's 2025 data breach affected 201,185 people and may have exposed names, addresses, identity documents, Social Security and financial data.","https:\u002F\u002Fwww.myeecu.org\u002Fimages\u002Fdefault-source\u002Ftemplate-images\u002Flogo.svg?sfvrsn=9f01fe1d_3",false,{"name":39,"sector":40,"country":41,"website":10,"websiteArchiveUrl":33,"websiteStatus":42,"websiteCheckedAt":12},"Educational Employees Credit Union","Finance","United States","active"]