West Virginia-based Bayer Heritage Federal Credit Union said that the cyber security incident it suffered last year compromised the sensitive personal information of more than 60,000 individuals.
Founded in 1957, Bayer Heritage Federal Credit Union is the largest credit union in the state of West Virginia. As of September 2023, the credit union had 149 employees and catered to 41,608 members across twelve locations.
In a filing with the Office of the Maine Attorney General, Bayer Heritage Federal Credit Union said that it recently learned that an unauthorised party gained access to portions of its internal network.
The credit union said it launched an internal investigation, with assistance from third party cyber security experts, to understand the nature and scope of the incident, took steps to contain the incident, and notified relevant law enforcement authorities.
“Based on the results of the investigation, we believe that the unauthorised party acquired copies of certain Bayer Heritage files between October 31, 2023 and November 1, 2023,” the credit union said.
The investigation, which concluded on December 1, revealed that sensitive personal information including names and other personal identifiers along with Social Security Numbers were compromised during the incident. The company’s filing with the regulator also revealed that at least 61,159 individuals were affected by the data security incident.
Bayer Heritage said it did not find any evidence of the compromised data being misused, but the possibility of the same cannot be ruled out. The company has urged all affected individuals to remain vigilant, review their credit reports and financial statements on a regular basis, and report suspicious transactions to relevant law enforcement authorities.
It is also offering a year of complimentary credit monitoring and identity protection services through Experian Identity Works to all the individuals affected by the data breach.
On December 1, a group of threat actors going by the name Lorenz ransomware gang claimed responsibility for the cyber attack on Bayer Heritage and listed the company as a victim on its data leak site.
The Lorenz ransomware group is relatively new, having first surfaced in February 2021. According to Cybereason, the gang targets victims mostly in English-speaking countries and demands hundreds of thousands of dollars, and even millions in ransom fees. It is believed to be a rebranded version of the “.sZ40” ransomware that was discovered in October 2020.
Last year, it targeted American pharmaceutical sourcing and distribution services company AmerisourceBergen and listed the company on its dark web site. AmerisourceBergen acknowledged the security incident and said it launched an internal investigation to understand the nature and scope of the cyber attack.
The security firm says the ransomware gang quickly disappeared from the scene after No More Ransom, a joint project by law enforcement agencies, including Europol’s European Cybercrime Centre, shared a decrypter for free with all affected victims.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543