AUSTIN, Texas — Travis County Credit Union is notifying members that a March cybersecurity incident involving its email system may have exposed personal information, although the credit union said it has found no evidence the data has been used for identity theft or fraud.
The credit union disclosed the breach in a letter to affected members that was filed with the Massachusetts Attorney General’s Office.
According to the notice, the $5.68-billion credit union discovered suspicious activity in its email environment on March 3 after identifying what it described as a limited number of unauthorized emails. The credit union said it immediately launched an investigation, changed passwords, revoked session tokens and reset multifactor authentication while engaging outside cybersecurity and privacy specialists to conduct a forensic review.

What Investigation Discovered
The investigation determined that an unauthorized actor had accessed a limited number of employee email accounts. Travis County Credit Union said the incident was quickly contained and no additional unauthorized activity was detected. However, investigators determined that emails containing members’ personal information may have been accessed or acquired during the intrusion.
The credit union said the potentially affected information includes members’ names and other personal data, although the specific data elements varied by individual. The institution said there is currently no evidence that any of the compromised information has been misused.
How CU Has Responded
In response, Travis County Credit Union said it has strengthened its existing security safeguards, completed an analysis to identify affected individuals and begun notifying members. The credit union is offering 24 months of complimentary Experian credit monitoring and identity theft protection services to those impacted. Members have until Oct. 31 to enroll in the service.
The notification also urges members to remain vigilant by regularly reviewing account statements and credit reports, changing passwords and promptly reporting suspicious activity to financial institutions. The letter includes information on placing fraud alerts or security freezes with the major credit reporting agencies and obtaining an IRS Identity Protection PIN.




