Suffolk Credit Union Data Breach Investigation
Suffolk Federal Credit Union reported a hacking/IT incident connected with third-party provider Mercadien, P.C. that may have involved sensitive personal and financial information. The available notice materials identify names, Social Security numbers, dates of birth, driver’s license numbers, addresses, and financial account numbers as potentially affected. Strauss Borrelli PLLC is investigating the incident and the rights of impacted individuals. If you received a notice, you may fill out the secure contact form on this page to help verify potential claim eligibility.
Key Facts at a Glance
- Entity Involved: Suffolk Federal Credit Union (Financial Services)
- Incident Type: Reported Hacking/IT Incident involving third-party provider Mercadien, P.C.
- Date of Incident: September 17, 2025 to October 9, 2025
- Discovery Date: November 7, 2025
- Official Notice Date: September 11, 2026
- Exposed Information: Names, addresses, Social Security numbers, dates of birth, driver’s license numbers, and financial account numbers
- Affected Population: Not publicly stated
What Happened?
According to information reported in connection with the consumer notice, the event was characterized as a hacking/IT incident involving network data. The reported incident period ran from September 17, 2025 through October 9, 2025. The materials identify Mercadien, P.C. as a third party connected to the event, although the available information does not fully explain how access occurred or which systems were affected.
Suffolk Federal Credit Union provided official notice on September 11, 2026, which was also the date associated with the incident’s public listing through the California Attorney General process. The available materials do not state a reliable number of affected individuals. They also do not establish that every listed data category was exposed for every notice recipient. Individuals should therefore review their own notification letters for details specific to their information.
What Information Was Exposed?
The reported data categories include names, mailing addresses, Social Security numbers, dates of birth, driver’s license numbers, and financial account numbers. These elements may enable several forms of fraud when combined, including identity theft, new-account or loan fraud, unauthorized account changes, and attempts to reset online banking credentials.
Because this incident concerns a financial institution and a third-party provider, affected individuals should also watch for fraudulent wire instructions, account-verification texts, and calls claiming that funds must be transferred to a “safe” account. A legitimate financial institution generally will not request passwords, one-time security codes, or full Social Security numbers through an unsolicited message.
What Should You Do Next?
- Review the notice carefully: Determine which data categories may apply to you, preserve the notice and envelope, and follow any enrollment instructions or deadlines it provides.
- Monitor financial accounts: Examine credit union, bank, credit card, and loan statements for unfamiliar transactions, new payees, changed contact details, or unauthorized password-reset activity. Report suspicious activity through a verified telephone number or website.
- Check your credit reports: Obtain reports from Equifax, Experian, and TransUnion through AnnualCreditReport.com. Look for unfamiliar accounts, loans, addresses, or credit inquiries and dispute inaccurate information promptly.
- Consider a fraud alert or credit freeze: A fraud alert asks creditors to verify your identity, while a security freeze generally restricts access to your credit file. Freezes must be placed separately with each nationwide credit bureau.
- Be alert for financial phishing: Do not click unexpected links or share login credentials, one-time codes, or account numbers in response to messages referencing the incident. Independently contact the credit union before approving transfers or account changes.
Your Legal Rights
People whose information may have been involved could have rights under federal and state privacy, consumer-protection, and data-security laws. Depending on the facts and applicable law, those rights may include receiving notice, obtaining information about the incident, disputing fraudulent activity, and seeking relief for certain documented losses. The availability of a claim depends on factors such as residency, the information involved, actual harm, contractual terms, and filing deadlines.
Preserve notices, credit-monitoring alerts, correspondence, receipts, and records of time spent responding to suspected misuse. Speaking with a privacy attorney can help you understand possible options, but reviewing an incident does not guarantee that a legal claim or recovery is available.
Why Hire Strauss Borrelli PLLC?
Our privacy attorneys investigate cybersecurity incidents involving financial institutions and third-party service providers. The legal team can review notice materials, evaluate whether applicable privacy or consumer-protection laws may provide a remedy, and explain the claims process in plain language. Consultations are confidential, and contacting the firm does not obligate you to pursue a case or guarantee any particular outcome.
If you received a breach notification letter from Suffolk Federal Credit Union:
We would like to speak with you about your rights and potential legal remedies in response to this data breach. Please fill out the form, below, or contact us at 872.263.1100 or sam@straussborrelli.com.










