FAIRWINDS CU Notifies Members PII May Have Been Accessed in Cyberattack

ORLANDO, Fla. — FAIRWINDS Credit Union is notifying members that their personal information may have been accessed during a cyberattack on an outside accounting firm it used for a regulatory and quality-control review.

The credit union said in a sample notification filed with the California attorney general that Mercadien, P.C. CPAs discovered suspicious activity in its systems Nov. 7, 2025. An investigation found that an unauthorized person may have accessed or acquired information in Mercadien’s systems between Sept. 7 and Nov. 7, 2025. FAIRWINDS said its own systems were not compromised. 

Mercadien told FAIRWINDS on Aug. 13, 2026, that information relating to credit union members was involved, according to the notice. FAIRWINDS said it completed a review to identify affected members Sept. 4 and began preparing notifications. The sample notice is dated Sept. 23. FAIRWINDS said it has no indication that the information has been fraudulently used. 

Uncertainty Around What Information May be Exposed 

The publicly filed sample letter does not specify which information was involved for every recipient; that section contains a placeholder to be filled in on individual notices. A Sept. 24 release from law firm Edelson Lechtzin LLP said information potentially involved could include names, Social Security numbers, financial account information and driver’s license numbers. The firm said it is investigating possible data privacy claims. It has not announced that it filed a lawsuit over this incident. CA.docx

FAIRWINDS said it ended its relationship with Mercadien and is offering affected members complimentary credit monitoring, identity restoration and identity theft insurance through Experian. The sample notice directs recipients who want the monitoring service to enroll by Dec. 31. Its duration appears as a placeholder in the public sample, so affected members should check their individual letters for the terms of their offer. CA.docx

The California filing does not give a nationwide count of affected people. The sample notice says approximately 39 Rhode Island residents may have been affected. FAIRWINDS advised recipients to review account statements and credit reports and said it will not call, text or email asking for online banking passwords or multifactor authentication codes.

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.