Brazos Valley Credit Union disclosed a business email compromise event in May 2025 affecting 34,000 members. An employee email account compromise allowed access to member PII and triggered an attempted wire fraud.
Phishing targeting finance department employee. Credential harvest via fake credit union SSO page. Threat actor accessed member data and attempted to redirect ACH payroll disbursements.
Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →
| Regime | Standard / Citation | Gap Identified |
|---|---|---|
| NCUA | NCUA Letter 23-CU-08 | Cyber incident reporting — NCUA notification required within 72 hours of reportable event |
| GLBA | Safeguards Rule §314.4(h) | Incident response program — no documented plan for BEC scenario |
| TDPA | Tex. B&C Code §521.053 | 34,000 TX credit union member notifications required |
CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.
Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.