A former vendor of Suffolk Federal Credit Union, accounting firm Mercadien, P.C., CPAs, detected unauthorized computer access in November 2025 that may have exposed members’ personal and financial information between September and October 2025. The exact number affected has not been disclosed. Affected individuals should enroll in the free Experian IdentityWorks Credit 3B monitoring offered by the credit union and watch their credit reports closely.
| Company | Suffolk Federal Credit Union |
|---|---|
| Industry | Finance |
| Data Types Exposed | Full Name, Personal Identifying Information, Financial Account Details, Identity Verification Information |
| People Affected | Not Publicly Disclosed |
| Attack Method | Third-Party Vendor Breach |
| Regulators Notified | Delaware Attorney General, California Attorney General, Vermont Attorney General, Hawaii Office of Consumer Protection |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Suffolk Federal Credit Union Data Breach?
Suffolk Federal Credit Union has notified members about a data security incident tied to a former vendor. The vendor, an accounting firm called Mercadien, P.C., CPAs, discovered unauthorized access to part of its computer environment. This means the breach did not start inside Suffolk Federal Credit Union’s own network. Instead, it occurred at a third-party service provider that once handled data on the credit union’s behalf.
According to the notification, unauthorized access to Mercadien’s systems occurred in November 2025. The investigation later determined that an unknown outside party may have accessed certain files between September 17, 2025, and October 9, 2025. As a result, the intrusion window predates the actual detection date by several weeks. This gap is common in vendor breaches, where forensic teams must reconstruct exactly when access occurred after the fact.
Once Mercadien identified the intrusion, it worked with digital forensics and cybersecurity specialists to contain the threat and secure its systems. The firm then conducted a detailed review of the affected data to determine whose personal information was involved. Mercadien reportedly finished this review and shared results with Suffolk Federal Credit Union afterward. Because the credit union relied on the vendor’s findings, notification to affected members did not happen immediately after the intrusion was first detected. The credit union has stated clearly that its own computer systems were never compromised in this incident.
Who was affected?
The individuals affected by this breach are people whose personal information Mercadien held while providing services connected to Suffolk Federal Credit Union. This likely includes current and former credit union members whose financial and identifying records passed through the vendor’s systems. Because Mercadien is an accounting and financial services firm, the exposed population may include people who had no direct interaction with the breach itself, only an indirect relationship through the credit union’s use of this vendor.
The exact number of affected individuals has not been publicly disclosed. However, the credit union chose to notify members individually and file notice with multiple state attorneys general, indicating a broad enough population to warrant formal, coordinated disclosure. In addition, because Suffolk Federal Credit Union serves members across different states, the impact of this breach likely extends beyond a single region.
What Information Was Potentially Exposed?
The notification letter references personal information without listing every exact data category in the portion available to the public. Nonetheless, breaches involving financial institutions and their accounting vendors typically involve highly sensitive identifying and financial details. Based on the nature of Mercadien’s work and the type of notice issued, the following categories are relevant to this incident.
- Full name
- Personal identifying information tied to credit union membership
- Financial account details
- Information used to verify identity for financial services
When this type of data is exposed, the most immediate risk is identity theft. Criminals can use stolen identifying details to open new credit accounts, file fraudulent tax returns, or apply for loans in a victim’s name. Because financial institutions hold especially sensitive records, exposed data from a credit union vendor can be more damaging than a typical retail breach.
Beyond identity theft, exposed financial information also raises the risk of direct account fraud. For example, attackers could attempt to access existing accounts or trick victims through targeted phishing messages that reference real account details. This makes the stolen data more convincing and dangerous than a random phishing attempt. As a result, affected members should treat any unexpected financial communication with heightened suspicion.
What is the company doing?
After learning of the incident, Suffolk Federal Credit Union says it moved quickly to gather details from Mercadien so it could understand the scope of the breach. The credit union then began notifying affected individuals once it received the vendor’s completed findings. Although the credit union states it has no evidence that any personal information has actually been misused, it chose to notify members out of caution.
To help protect affected individuals, Suffolk Federal Credit Union is offering a complimentary one-year membership in Experian’s IdentityWorks Credit 3B service. This tool helps detect potential misuse of personal information and offers support for resolving identity theft issues. Enrollment must be completed by December 31, 2026, using an activation code provided directly to each affected member. In addition to notifying individuals, Suffolk Federal Credit Union also filed formal notice of this breach with the California Attorney General, consistent with state data breach reporting requirements.
What Should Affected Individuals Do?
Monitor Your Credit Reports Closely
Affected individuals should regularly check their credit reports for unfamiliar accounts or inquiries. Because this breach involves a financial institution’s vendor, credit monitoring is especially important. You can request free credit reports from each of the three major bureaus through AnnualCreditReport.com.
Reviewing these reports every few months, rather than just once, increases the chance of catching fraud early. If you notice any account you did not open, dispute it immediately with the credit bureau and the lender involved. Early detection often limits the financial damage from identity theft.
Place a Fraud Alert or Credit Freeze
Given that financial information may have been exposed, placing a fraud alert or credit freeze offers strong protection. A fraud alert requires lenders to verify your identity before approving new credit in your name. A credit freeze goes further by blocking most access to your credit file entirely.
You can request either option directly through Equifax, Experian, or TransUnion. Because a freeze is free and can be lifted temporarily when needed, it is one of the most effective tools available to consumers after a breach like this one.
Enroll in the Offered Identity Protection Service
Suffolk Federal Credit Union is offering a free one-year membership in Experian’s IdentityWorks Credit 3B service. This benefit is already paid for, so affected individuals should take advantage of it before the enrollment deadline. The service can help detect misuse of your data and assist with resolving identity theft if it occurs.
To enroll, visit the Experian IdentityWorks website and use the activation code included in your personal notification letter. Because enrollment closes on December 31, 2026, it is best to sign up as soon as possible rather than risk missing the deadline.
Stay Alert for Phishing Attempts
After a breach involving personal and financial details, scammers often send phishing emails or texts pretending to be from the credit union or a related service. These messages may reference real details to appear convincing. Therefore, always verify unexpected messages by contacting the credit union directly using a known phone number.
Avoid clicking links or providing information in response to unsolicited messages. Instead, log into your accounts directly through official websites or apps. This simple habit significantly reduces the risk of falling victim to a follow-up scam tied to this breach.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
More Information
Official data breach notification report (PDF) from Delaware Attorney General
Official data breach notification from California Attorney General
View the public data breach notification listing from Vermont Attorney General
Official data breach notification report (PDF) from Hawaii Office of Consumer Protection
