Gale CU Reports Data Breach Involving Members’ Account, Personal Information

GALESBURG, Ill. — Gale Credit Union has reported a data breach involving member information, including Social Security numbers, financial account numbers and Visa credit card information, according to a filing with the Massachusetts Office of Consumer Affairs and Business Regulation.

The $74-million credit union reported the breach to Massachusetts regulators Sept. 3. The filing indicates that two Massachusetts residents were affected, but does not disclose how many Gale CU members or other individuals were affected nationwide. GCU has approximately 4,800 members. 

In a notification letter filed with the state, Gale CU said information involved in the incident included members’ names, Social Security numbers, financial account numbers, Visa credit card numbers and card expiration dates.

The credit union said it worked with its payment card processor to reissue affected cards and told members they should receive replacement cards in the mail.

Member Account Database Was Protected

Gale CU’s notification provides few details about how the security incident occurred, when it was discovered or how attackers obtained the personal information.

However, the credit union said its investigation determined that its security systems successfully prevented access to its primary member account system.

“The investigation determined that our security systems blocked all access to our Member Account Database,” Gale CU said in the notice.

Gale CU also did not identify the attacker in its Massachusetts filing or characterize the incident as ransomware.

Separate cybersecurity and legal-industry reports have linked the incident to the Akira ransomware group, which reportedly listed Gale CU as a victim Aug. 31 and claimed to have obtained approximately 50 gigabytes of data. A CU Daily review shows those claims have not been independently verified or confirmed by the credit union.

According to those reports, Akira claimed the information it obtained included employee and client data, Social Security and driver’s license information, payment card data, financial records, contracts and other corporate information.

No Misuse Reported So Far

Gale CU said it was not aware of any misuse of the compromised information as of the date of its notification.

The credit union is offering affected individuals two years of complimentary Kroll Identity Monitoring, including credit monitoring, fraud consultation and identity theft restoration services.

It also advised affected individuals to closely review account statements for the next 12 to 24 months and immediately report suspicious activity.

“We regret any inconvenience or concern this incident may cause,” President and CEO Randy D. McElwee said in the notification. “We have taken steps to enhance our existing security measures.”

Massachusetts law requires organizations holding personal information about state residents to notify regulators and affected consumers following certain security breaches.

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.