NORTH LIBERTY, Iowa–University of Iowa Community Credit Union is reporting that it has been breached through a phishing scam that targeted an employee.
As a result, some personal consumer information involving members and non-members utilizing its mortgage services has been exposed, according to a statement the $3.9-billion credit union published on its website.
UICCU said it has engaged an independent third-party to conduct a forensic investigation and has reported the incident to federal law enforcement. Anyone who has been affected has been sent a letter via U.S. mail.
According to the statement, “In late March, UICCU discovered that a credit union employee was the victim of an email phishing scam. This was a highly-sophisticated attack to gain unauthorized access to the e-mail inbox of one of our employees on March 17, 2017. This act exposed the employee’s e-mail and any e-mail attachments to possible review by an unauthorized third party. While we don’t know whether specific information was accessed, we do know that e-mails in the account contained the personal information of some buyers and sellers involved in mortgage transactions. The unauthorized access was shut down March 21, 2017.”
UICCU said information that could have been compromised may have included names, credit union account numbers (for members only), and Social Security numbers. Those affected include non-members. The credit union said it is offering credit monitoring services at no cost.
“UICCU is in the process of reviewing all security measures and processes in order to prevent this from happening again,” the statement reads. “We will implement additional security measures and training as appropriate to fulfill our commitment to the protection of personal consumer information.”
