Data Breaches

Patelco Credit Union Says Breach Impacts 726k After Ransomware Gang Auctions Data

Patelco Credit Union has confirmed a data breach impacting many individuals after the RansomHub ransomware group stole some databases. 

Patelco Credit Union has confirmed a data breach impacting many individuals after the RansomHub ransomware group stole some databases. 

California-based Patelco Credit Union is informing customers and employees about a data breach after a ransomware group managed to steal databases containing personal information from its systems. 

Patelco is a member-owned, not-for-profit credit union that serves Northern California, particularly the San Francisco Bay Area. 

The organization revealed in a data breach notice on its website that it detected a ransomware attack involving unauthorized access to its databases on June 29. An investigation revealed that the hackers had access to its systems between May 23 and June 29.

Patelco has determined that the compromised information includes names, Social Security numbers, driver’s license numbers, dates of birth, and email addresses, but noted that not every data element was compromised for each individual.

Patelco’s website says it has over 450,000 members and it was initially presumed that they were all impacted by the breach. Attempts to initiate a class action against the company shortly after the incident came to light said roughly 500,000 people were impacted, likely based on the data from the credit union’s site. 

However, the organization has informed the Maine Attorney General’s Office that the incident actually impacted 726,000 customers and employees. Affected individuals are being offered two years of free identity protection services. 

Advertisement. Scroll to continue reading.

California’s Department of Financial Protection and Innovation has also issued a consumer alert in response to the incident. 

Patelco was added to the RansomHub ransomware group’s website on August 16. The cybercriminals claimed to have conducted negotiations for two weeks, but could not reach an agreement with the financial organization so they are now auctioning the sensitive data they have stolen. 

A sample made public by the hackers shows that the databases contained information such as name, postal address, phone number, email address, date of birth, gender, Social Security number, driver’s license number, password, and credit rating.

Related: Evolve Bank Data Breach Impacts 7.6 Million People

Related: European Banks Put to Test

Related: Cost of Data Breach in 2024: $4.88 Million, Says Latest IBM Study

Related: 750k Impacted by Frontier Communications Data Breach

Related Content

Data Breaches

The cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision.

Data Breaches

The data breach was initially believed to affect roughly 350,000 people, but the HHS breach tracker shows a far bigger impact.

Data Breaches

Hackers stole names, addresses, phone numbers, Social Security numbers, and financial information from a third-party platform.

Data Breaches

Hackers used compromised credentials to access enterprise and personal tax-related data.

Data Breaches

Hackers exploited a vulnerability in the order-tracking function of a plugin to access SafePal customer information.

Data Breaches

The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers.

Data Breaches

The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts.

Data Breaches

Hackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version