ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

MetroWest Community Credit Union says data breach affected over 20,000 members

U.S. banking institution MetroWest Community Federal Credit Union said a significant data breach discovered in September compromised the personal and financial information of more than 20,000 customers.

 

The Framingham, Massachusetts-based credit union, which provides affordable savings and loan products to more than 60,000 members in the state, said it discovered unauthorised access to certain systems last year that enabled hackers to steal personal and banking information of a subset of customers.

 

The cyber attack took place not long after the credit union merged with Marlborough, Massachusetts-based St. Mary’s Credit Union to form a new entity with more than $1.1 billion in assets and a base of more than 60,000 members. 

 

In a data breach incident notice filed with the office of the Attorney General of Maine on Tuesday, MetroWest Community FCU said it discovered suspicious activity on certain systems in its network on September 1 and following an investigation and review which completed in January, determined that an unauthorised third party copied certain files from its systems without permission.

 

The credit union informed the Attorney General’s office that the security incident impacted 20,722 members, including 132 members residing in the state of Texas. "The information that could have been subject to unauthorised access includes name, Social Security number, financial account number, routing number, and payment card number," the credit union said.

 

In a previous data breach notice filed with the office of the Attorney General of Vermont on December 29, MetroWest Community FCU said the compromised data included affected members’ names, addresses, phone numbers, Social Security numbers, full financial account numbers, debit card numbers, and driver’s licence numbers.

 

The bank said that when it discovered the breach, it quickly assessed the security of its systems, notified the FBI, and initiated the process of identifying the affected individuals. It is also offered two years of free credit monitoring and identity protection services through Experian to individuals whose personal information was potentially affected by the incident.

 

According to data breach monitoring and intelligence firm BreachSense, the Akira ransomware group was behind the cyber attack on MetroWest Community FCU that compromised members’ personal and financial information. 

 

In late 2025, the ransomware group also claimed a cyber attack on American state-chartered community bank, Valley Banks, stating that it stole 294 GB of corporate documents, including employees’ personal, financial and employment information, client files and non-disclosure agreements.

 

ABA Insurance Services said in mid-2025 that it noticed an uptick in the number of banks reporting Akira ransomware attacks. It said the ransomware group typically uses stolen credentials to gain network access, escalates privileges to perform lateral movement, exfiltrates sensitive data and launches encryption code to halt operations and demand a ransom.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543