Skip to main content
Back to overview
High

MemberSource Credit Union Suffers Ransomware Attack and Data Breach

MemberSource Credit Union experienced a data security incident on June 3, 2025, when a disruption was detected in its branch computer networks.

Key points

  • Disruption in branch computer networks detected on June 3, 2025.
  • SafePay ransomware group claimed responsibility on June 17, 2025, and stated they exfiltrated 50 GB of data.
  • Affected data included names, Social Security numbers, driver's license/state identification numbers, and financial account information from unencrypted files.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Jun 3, 2025
Updated
Jul 15, 2026
Confidence
High
Evidence
16 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch ransomware, endpoint compromise and business interruption exposure.

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

MembersourcecuData DisclosureMemberSource Credit Union Suffers RansomwareCredit UnionThe SafePayAttorneys GeneralDisruptionSafePayAffected

Quick context

Questions about this signal

What happened in this signal?

MemberSource Credit Union experienced a data security incident on June 3, 2025, when a disruption was detected in its branch computer networks. An investigation confirmed that an unauthorized party exfiltrated data from the affected network. The SafePay ransomware group claimed responsibility for the attack on June 17, 2025, stating they had obtained approximately 50 GB of data. The credit union began notifying affected individuals on May 7, 2026, and reported the incident to state Attorneys General starting May 8, 2026.

When was this signal reported?

Shadow Tier lists Jun 3, 2025 as the signal date.

Which organization is connected to this signal?

Membersourcecu is the organization connected to this public signal.

Explore Membersourcecu
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence