Fairwinds Credit Union has notified the New Hampshire Attorney General of a data security incident affecting the personal information of its members after a third-party vendor, Mercadien, P.C. CPAs, experienced a cybersecurity incident. Financial institutions and the vendors they rely on are expected to safeguard the sensitive account and identity information entrusted to them, and when that trust is broken, members can be left facing real risk of fraud and identity theft.
Fairwinds Credit Union’s Data Breach Investigation
According to a notice filed with the New Hampshire Attorney General’s Office, Fairwinds engaged Mercadien, an external professional services firm, to perform an independent assessment as part of routine quality control and regulatory requirements for credit unions. Fairwinds provided certain information necessary for Mercadien to complete that assessment.
On November 7, 2025, Mercadien identified a cybersecurity incident within its own systems and began an investigation. That investigation determined that an unauthorized actor may have accessed or acquired information within Mercadien’s systems between September 7, 2025, and November 7, 2025. On August 13, 2026, Mercadien notified Fairwinds that information relating to its members had been identified as affected by the incident. Fairwinds then undertook an additional review to validate the impacted population and ensure notifications were issued appropriately, completing that review on September 4, 2026, before promptly beginning the process of notifying affected members. Importantly, the incident occurred within Mercadien’s systems and did not involve a compromise of Fairwinds’ own systems.
Breaches that originate with an outside vendor rather than the financial institution itself are an increasingly common pattern in the industry. Credit unions and banks routinely share member data with accounting firms, IT vendors, and other third parties to meet quality-control and regulatory obligations, which means a single vulnerability at one vendor can expose the financial data of members across multiple institutions at once. This kind of arrangement can also lengthen the time between when a breach first occurs and when affected individuals are ultimately notified, since forensic investigators must first determine exactly whose data was involved before each affected client can issue its own notice.
The combination of data reportedly involved here — names, Social Security numbers, financial account information, and in some cases driver’s license numbers — is especially valuable to identity thieves because it can be used to open new financial accounts, file fraudulent tax returns, or take out loans in a victim’s name. Unlike a compromised credit card number, which can simply be canceled and reissued, a stolen Social Security number cannot be replaced, meaning the exposure can pose a risk to victims well beyond the immediate aftermath of the breach.
Fairwinds began mailing written notice of the incident to affected New Hampshire residents on or about September 23, 2026. In response to the breach, Fairwinds has stated that it terminated its relationship with Mercadien and is offering complimentary credit monitoring, identity restoration, and identity theft insurance services through Experian for affected individuals. Fairwinds also reported that Mercadien notified federal law enforcement regarding the incident.
When Did This Breach Occur?
The underlying incident at Mercadien occurred between approximately September 7, 2025, and November 7, 2025, when Mercadien says an unauthorized actor may have accessed or acquired information within its systems. Mercadien identified the incident on November 7, 2025, and did not notify Fairwinds that member information was involved until August 13, 2026. Fairwinds completed its own review on September 4, 2026, and began mailing notification letters to affected New Hampshire residents on or about September 23, 2026.
What Information Was Breached?
Fairwinds has disclosed that the information potentially subject to unauthorized access includes members’ names, Social Security numbers, financial account information, and, in limited circumstances, driver’s license numbers. Fairwinds states it has no indication that the information has been fraudulently used, but out of caution is notifying affected members and offering twelve months of complimentary credit monitoring and identity protection services through Experian.
What You Can Do
If you received a breach notification letter from Fairwinds Credit Union or believe you may have been affected, consider taking the following steps:
- Enroll in the complimentary Experian credit monitoring and identity restoration services offered in your notification letter.
- Regularly review your bank and credit card statements for unauthorized transactions.
- Place a fraud alert or security freeze on your credit reports with the three major credit bureaus.
- Monitor your credit reports for new accounts or inquiries you do not recognize.
- Be cautious of unsolicited calls, emails, or texts referencing this breach, and never share your online banking credentials with anyone claiming to represent Fairwinds.
File a Data Breach Lawsuit Against Fairwinds Credit Union
If your personal or financial information was exposed as a result of this breach, you may have legal options available to you. Financial institutions and the vendors they rely on are expected to maintain reasonable safeguards to protect the sensitive data entrusted to them.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.