More than 500,000 credit union members’ information exposed in breach

Published:

Texas Dow Employees Credit Union (TDECU) Data Breach: Impact on Over 500,000 Members and 20 Million Individuals

The Texas Dow Employees Credit Union (TDECU) recently fell victim to a data breach that exposed the personal information of over 500,000 members, affecting more than 20 million individuals in total. The breach, which occurred on May 31, 2023, was linked to a compromise of the third-party vendor MOVEit, which is used for transferring data.

Initially, TDECU conducted an investigation but found no evidence of a compromise. However, on July 30, 2024, the organization discovered that files containing sensitive information such as birth dates, driver’s licenses, credit card numbers, and Social Security numbers had been lost.

Security experts have expressed concerns over the widespread impact of the breach. Ken Dunham, Cyber Threat Director at Qualys Threat Research Unit, highlighted the exploitation of the MOVEit vulnerability by ransomware groups like Cl0p. Darren Guccione, CEO and Co-Founder at Keeper Security, emphasized the importance of continuous monitoring and prompt patch management to prevent such breaches.

Adam Gavish, CEO at DoControl, warned of the potential long-term consequences of the breach, including ongoing vulnerability and delayed data leaks. He stressed the need for comprehensive visibility and control over data transfers, as well as a proactive, data-centric approach to cybersecurity.

The TDECU data breach serves as a stark reminder of the importance of robust cybersecurity practices and the need for organizations to prioritize the protection of sensitive information in an increasingly interconnected digital landscape.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Cisco Catalyst SD-WAN Manager API authentication bypass vulnerability CVE-2026-76504 actively exploited

On September 30, 2026, Cisco disclosed a critical API authentication bypass vulnerability, CVE-2026-76504, affecting its Catalyst SD-WAN Manager. This flaw, which has a CVSSv3.1...

Apple updates macOS privacy settings to prevent misuse of full-disk access by AI agents

Apple has announced changes to its macOS privacy settings aimed at preventing third-party applications from misusing full-disk access to read sensitive user data, including...

Palo Alto Networks Unit 42 reports exploitation of NetScaler zero-day vulnerabilities CVE-2026-88771 and CVE-2026-88772 in the wild

Palo Alto Networks' Unit 42 has reported active exploitation of two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting Citrix NetScaler devices. These vulnerabilities, which...

Governments face rising cyber threats as phishing incidents surge to 23% of intrusions in 2026

In a significant shift, government agencies have emerged as the most targeted sector for cyber threats, accounting for 27% of observed activity in 2026,...