cancel
Showing results for 
Search instead for 
Did you mean: 

AODFCU publicly discloses a data breach

tag
coldfusion
Community Leader
Mega Contributor

AODFCU publicly discloses a data breach

 

AOD sent out individual letters to be delivered today to those individuals they believe may be impacted, but I included a link to an online article discussing the breach instead of trying to type a detailed synopsis.

 

In brief,  there apparently was a compromise last August which was confirmed and validated last month where a least some account holders had at a minmum may have had their name+SSN+AODFCU account number(s) accessible.  FBI was engaged and I'm sure both the FFIEC and at least one of the 3rd party cybersecurity companies vetted and authorized by the NCUA to provide related services to their member institutions are also involved.  

 

If you got a letter you are also entitled to a free 24 months of Experian IdenityWorks Credit 3B.  Details of how to enroll are included in the letter.

 

https://markets.businessinsider.com/news/stocks/aod-federal-credit-union-data-breach---levi-korsinsk...

(2/2025)
FICO 8 (EX) 850 (TU) 850 (EQ) 850
FICO 9 (EX) 850 (TU) 850 (EQ) 850

$1M+ club

Artist formerly known as the_old_curmudgeon who was formerly known as coldfusion
Message 1 of 19
18 REPLIES 18
Wandering
Regular Contributor

Re: AODFCU publicly discloses a data breach

Woo, good thing AOD was "johnny on the spot".

 

Only took them 7.75 months from learning of the breech to identify people and inform them of said identity data breech. Way better than 8 months or even a year. Am I right or what(?)

Message 2 of 19
crystal626
Regular Contributor

Re: AODFCU publicly discloses a data breach

Got the letter. It's only 12 months of monitoring, not 24. As these breaches almost always happen as a result of gross negligence (not staying on top of updates, stupid employees), I would dump them, but their 3% card is still worth it to me and my credit reports are frozen anyway.

Message 3 of 19
tiniwings
Valued Member

AOD Data breach

Just received from AOD 🙁20250408_130958.jpg

 


Message 4 of 19
Varsity_Lu
Established Contributor

Re: AOD Data breach

Nothing better than to wait 8 months before informing your customers that their sensitive financial and personal data may have been stolen. Yikes!

Blue Cash PreferredBlue Cash Everyday (AU)Hilton HonorsSavorQuicksilverVentureOneVoice Rewards + Perks Checking
Mechanics Savings BankHuntington National BankCapital One, N.A.American Express National BankFidelity Investments
FICO® 8: 806 (Eq) · 794 (Ex) · 812 (TU)

Message 5 of 19
crystal626
Regular Contributor

Re: AOD Data breach

We got the letter too. I'm pretty much numb to them at this point because I get at least one every few months. Lots of medical providers have been breached recently...

Message 6 of 19
CreditPoor
Frequent Contributor

Re: AOD Data breach

This is why i refuse to send sensitive financial data to banks for "verification" purposes. These banks are incapable if protecting sensitive data and lie about the severity ofthe breaches. Amex last breach was massive, yet they lied to there clients and continue to request bank statements with  account numbers and tax records without bring able to protect the data.

 

Don't even get me started on what they actually do with that data.

Message 7 of 19
unsungivy
Valued Contributor

Re: AOD Data breach


@Varsity_Lu wrote:

Nothing better than to wait 8 months before informing your customers that their sensitive financial and personal data may have been stolen. Yikes!


Sure there is! Waiting 11 months, which is what my work did 🙄

Biz - Authorized User -
Sock - Debit Cards -
Chopping Block -
Message 8 of 19
AndySoCal
Senior Contributor

Re: AODFCU publicly discloses a data breach

The time that the data breach is discovered til the notifications are sent out is slow. There are reasons for for this. There are several questions that must be answered this not a complete list by any means. The job is not easy because the hacker is going to be stealth as possible to avoid detection.

Where and how did the hacker breach the system?

How many times and when was the system breached?

What did the hacker have access to? 
Was and data pulled from the system and exported somewhere?

How to fix the known breach ?

Are there other potential breach points waiting to be exploited?

Whose information was compromised or was potentially compromised?

 

The  fixes that prevent furthur hacks have to be in place ahead of any notifications.

All that said, there are companies that specialize in doing this type work after a company has had data breach. I have read where teams that are working on a data breach are working  24 7 due to the difficulty of the job they have to.

 

FIC Scores XPN v8 808 V2 831 (SDFCU) TUC V 8 803 03/25 EFX Bankcard v8 822 EFX FIC0 v8 800 Vantage score 4.0 817 via JC Penney )
Discover IT 09/90, 19000, JC Penney 10/2008 4700, US Bank Cash 08/2010 12,000 Citibank Custom Cash 5/2015 11,100 State Dept. FCU 20,000 06/2023 , 02/2024 Redstone FCU Signature VISA 10,000 08/23/2024 Langley FCU Signature Cash Back Visa 10000
Banking: Langley FCU Credit Unions: Lafayette FCU Fortera FCU State Department FCU Pelican State CU Red-stone FCU Hughes FCU
My personal blacklist Axos Bank, Bank of America, Synchrony Bank Capital One TD Bank Comerica Bank BMO
Message 9 of 19
coldfusion
Community Leader
Mega Contributor

Re: AODFCU publicly discloses a data breach


@AndySoCal wrote:

The time that the data breach is discovered til the notifications are sent out is slow. There are reasons for for this. There are several questions that must be answered this not a complete list by any means. The job is not easy because the hacker is going to be stealth as possible to avoid detection.

Where and how did the hacker breach the system?

How many times and when was the system breached?

What did the hacker have access to? 
Was and data pulled from the system and exported somewhere?

How to fix the known breach ?

Are there other potential breach points waiting to be exploited?

Whose information was compromised or was potentially compromised?

 

The  fixes that prevent furthur hacks have to be in place ahead of any notifications.

All that said, there are companies that specialize in doing this type work after a company has had data breach. I have read where teams that are working on a data breach are working  24 7 due to the difficulty of the job they have to.

 


There are other things to be addressed but this largely sums it up.    A key point is that multiple government agencies are involved in the entire process and they help determine when it's the appropriate time for public disclosure.   

 

A relevant point is that as an NCUA member institution AOD has regulatory requirements to adhere to a wide swath of best security-centric business practices and must regularly positively demonstrate via external audit their compliance with these best practices.  3rd party cybersecurity-related companies that AOD would have been eligible to engage are also validated (with the FFIEC) as having complied with the same requirements.

 

(2/2025)
FICO 8 (EX) 850 (TU) 850 (EQ) 850
FICO 9 (EX) 850 (TU) 850 (EQ) 850

$1M+ club

Artist formerly known as the_old_curmudgeon who was formerly known as coldfusion
Message 10 of 19
Advertiser Disclosure: The offers that appear on this site are from third party advertisers from whom FICO receives compensation.