Were you recently affected by a data breach?

Fairwinds Credit Union Data Breach

Fairwinds Credit Union notified New Hampshire regulators of a data breach traced to its vendor Mercadien, exposing members’ Social Security numbers, financial account information, and driver’s license numbers. Affected individuals may be entitled to compensation.

Fairwinds Credit Union
Date of Breach: September 7-November 7, 2025 (incident at vendor Mercadien, P.C.)
CAU logo

Who was affected:

Clients of Fairwinds Credit Union

Impacted Data:

Names, Social Security numbers, financial account information, and in limited circumstances, driver’s license numbers

Fairwinds Credit Union has notified the New Hampshire Attorney General of a data security incident affecting the personal information of its members after a third-party vendor, Mercadien, P.C. CPAs, experienced a cybersecurity incident. Financial institutions and the vendors they rely on are expected to safeguard the sensitive account and identity information entrusted to them, and when that trust is broken, members can be left facing real risk of fraud and identity theft.

Fairwinds Credit Union’s Data Breach Investigation

According to a notice filed with the New Hampshire Attorney General’s Office, Fairwinds engaged Mercadien, an external professional services firm, to perform an independent assessment as part of routine quality control and regulatory requirements for credit unions. Fairwinds provided certain information necessary for Mercadien to complete that assessment.

On November 7, 2025, Mercadien identified a cybersecurity incident within its own systems and began an investigation. That investigation determined that an unauthorized actor may have accessed or acquired information within Mercadien’s systems between September 7, 2025, and November 7, 2025. On August 13, 2026, Mercadien notified Fairwinds that information relating to its members had been identified as affected by the incident. Fairwinds then undertook an additional review to validate the impacted population and ensure notifications were issued appropriately, completing that review on September 4, 2026, before promptly beginning the process of notifying affected members. Importantly, the incident occurred within Mercadien’s systems and did not involve a compromise of Fairwinds’ own systems.

Breaches that originate with an outside vendor rather than the financial institution itself are an increasingly common pattern in the industry. Credit unions and banks routinely share member data with accounting firms, IT vendors, and other third parties to meet quality-control and regulatory obligations, which means a single vulnerability at one vendor can expose the financial data of members across multiple institutions at once. This kind of arrangement can also lengthen the time between when a breach first occurs and when affected individuals are ultimately notified, since forensic investigators must first determine exactly whose data was involved before each affected client can issue its own notice.

The combination of data reportedly involved here — names, Social Security numbers, financial account information, and in some cases driver’s license numbers — is especially valuable to identity thieves because it can be used to open new financial accounts, file fraudulent tax returns, or take out loans in a victim’s name. Unlike a compromised credit card number, which can simply be canceled and reissued, a stolen Social Security number cannot be replaced, meaning the exposure can pose a risk to victims well beyond the immediate aftermath of the breach.

Fairwinds began mailing written notice of the incident to affected New Hampshire residents on or about September 23, 2026. In response to the breach, Fairwinds has stated that it terminated its relationship with Mercadien and is offering complimentary credit monitoring, identity restoration, and identity theft insurance services through Experian for affected individuals. Fairwinds also reported that Mercadien notified federal law enforcement regarding the incident.

When Did This Breach Occur?

The underlying incident at Mercadien occurred between approximately September 7, 2025, and November 7, 2025, when Mercadien says an unauthorized actor may have accessed or acquired information within its systems. Mercadien identified the incident on November 7, 2025, and did not notify Fairwinds that member information was involved until August 13, 2026. Fairwinds completed its own review on September 4, 2026, and began mailing notification letters to affected New Hampshire residents on or about September 23, 2026.

What Information Was Breached?

Fairwinds has disclosed that the information potentially subject to unauthorized access includes members’ names, Social Security numbers, financial account information, and, in limited circumstances, driver’s license numbers. Fairwinds states it has no indication that the information has been fraudulently used, but out of caution is notifying affected members and offering twelve months of complimentary credit monitoring and identity protection services through Experian.

What You Can Do

If you received a breach notification letter from Fairwinds Credit Union or believe you may have been affected, consider taking the following steps:

  • Enroll in the complimentary Experian credit monitoring and identity restoration services offered in your notification letter.
  • Regularly review your bank and credit card statements for unauthorized transactions.
  • Place a fraud alert or security freeze on your credit reports with the three major credit bureaus.
  • Monitor your credit reports for new accounts or inquiries you do not recognize.
  • Be cautious of unsolicited calls, emails, or texts referencing this breach, and never share your online banking credentials with anyone claiming to represent Fairwinds.

File a Data Breach Lawsuit Against Fairwinds Credit Union

If your personal or financial information was exposed as a result of this breach, you may have legal options available to you. Financial institutions and the vendors they rely on are expected to maintain reasonable safeguards to protect the sensitive data entrusted to them.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: September 7-November 7, 2025 (incident at vendor Mercadien, P.C.)
Date of Breach: December 2-18, 2025 (incident at business associate Aesto, LLC)
Date of Breach: Reported to the Vermont Attorney General's Office on September 23, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.