Fairwinds Credit Union
Sep 2025 · Graded Verified · Financial Services · Government record
Fairwinds Credit UnionSep 2025
breach at Mercadien
Not yet quantified
VVerifiedFairwinds sent member data to Mercadien, the outside firm hired to satisfy a regulatory quality-control check, and that data sat exposed on Mercadien's systems from September 7 to November 7, 2025. The credit union's own network was never touched; the compliance requirement simply relocated the sensitive information to a vendor with its own, unaudited security posture. Mercadien did not tell Fairwinds which members were affected until August 13, 2026, nine months after it coughed up its own customers' data. The filing shows how little visibility Fairwinds had into a trusted vendor system holding its members' information
Financial Services
California AG breach notification
About this record
This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.