Full Report
The credit union filed breach notification documents with regulators in Maine and Texas on Friday acknowledging that it recently detected suspicious activity on its network.
Analysis Summary
# Incident Report: SRP Federal Credit Union Data Breach
## Executive Summary
SRP Federal Credit Union suffered a data breach between September 5 and November 4, 2024, resulting in the compromise of personal and financial information belonging to over 240,000 individuals. The threat actor, identified as the ransomware group Nitrogen, claimed responsibility for exfiltrating 650 GB of customer data, though the credit union did not confirm ransomware usage. The investigation concluded on November 22, and SRP began notifying regulators and affected parties afterward.
## Incident Details
- Discovery Date: Recently detected suspicious activity (Prior to notification filings on Friday, date unspecified)
- Incident Date: September 5, 2024, through November 4, 2024
- Affected Organization: SRP Federal Credit Union
- Sector: Financial Services (Credit Union)
- Geography: South Carolina, USA (Confirmed by regulatory filings in Maine and Texas)
## Timeline of Events
### Initial Access
- Date/Time: On or shortly before September 5, 2024
- Vector: Not explicitly disclosed, but attributed to an attack by the Nitrogen ransomware group.
- Details: Attackers accessed SRP Federal Credit Union systems.
### Lateral Movement
- Details: Attackers accessed and potentially acquired "certain files from our network" during the two-month window. Specific lateral movement techniques are not detailed in the source material.
### Data Exfiltration/Impact
- Date/Time: Between September 5 and November 4, 2024
- Details: The Nitrogen group claimed to have stolen 650 GB of customer data. Affected data included names, Social Security numbers, driver’s license numbers, dates of birth, financial information, and credit/debit card numbers.
### Detection & Response
- Date/Time: Suspicious activity detected shortly before regulatory filings (Post-November 4, 2024). Investigation concluded November 22, 2024.
- Details: Law enforcement was notified, and an internal investigation was conducted. Breach notification filings occurred on the Friday preceding the report date. Impact appears restricted to file systems, as core banking and processing systems were reportedly unaffected.
## Attack Methodology
- Initial Access: Unknown (Likely exploitation or compromised credential, given the ransomware group attribution).
- Persistence: Not disclosed.
- Privilege Escalation: Not disclosed.
- Defense Evasion: Not disclosed.
- Credential Access: Not disclosed.
- Discovery: Not disclosed.
- Lateral Movement: Access to "certain files from our network."
- Collection: Gathering of customer Personally Identifiable Information (PII) and financial data.
- Exfiltration: Theft of 650 GB of data, claimed by Nitrogen.
- Impact: Unauthorized disclosure and potential misuse of PII and financial data affecting 240,000+ individuals.
## Impact Assessment
- Financial: Not disclosed (Beyond investigation costs and potential regulatory fines/remediation).
- Data Breach: Names, Social Security numbers, driver’s license numbers, dates of birth, account numbers, and credit/debit card numbers for over 240,000 individuals.
- Operational: The attack did not impact the online banking system or core processing system.
- Reputational: A significant public breach impacting a major South Carolina credit union.
## Indicators of Compromise
- Network indicators: None provided (No defanged IPs/URLs available).
- File indicators: None provided.
- Behavioral indicators: Access and exfiltration of files over a two-month period (Sept 5 - Nov 4).
## Response Actions
- Containment: Not explicitly detailed, but investigation commenced after detection.
- Eradication: Not explicitly detailed.
- Recovery Actions: Law enforcement notified and investigation conducted. Breach notifications issued to regulators and affected customers.
## Lessons Learned
- **Visibility Gap:** A sustained data compromise occurred over a two-month period (Sept 5 – Nov 4) without timely detection, indicating potential gaps in continuous monitoring or anomaly detection.
- **Incident Scope Clarity:** The organization was unable to immediately confirm the exact type of attack (e.g., ransomware) or the precise data stolen, highlighting the need for faster forensic attribution.
## Recommendations
- **Enhanced Network Segmentation:** Re-evaluate network segmentation to limit potential lateral movement, ensuring that exfiltration pathways are tightly monitored.
- **MFA/Strong Authentication:** Review all authentication protocols, especially for access that may lead to data exfiltration pathways.
- **Continuous Monitoring:** Implement or enhance tools capable of detecting prolonged unauthorized data access and large-scale data staging/exfiltration attempts.
- **Tabletop Exercises:** Conduct more frequent tabletop exercises simulating sophisticated intrusion scenarios similar to those employed by modern ransomware groups.