Law Firm Investigates FAIRWINDS CU Data Breach Tied To Vendor
By CU Today Staff —
ORLANDO, Fla.—A law firm has opened an investigation into a data breach involving FAIRWINDS Credit Union after information held by a third-party vendor was accessed during a 2025 cyberattack, according to a report by Morningstar.
Edelson Lechtzin LLP said the incident involved Mercadien, which FAIRWINDS had retained to conduct an independent review for quality control and regulatory compliance. According to the report, Mercadien discovered suspicious activity Nov. 7, 2025, and an investigation determined an unauthorized actor had accessed and acquired information from its systems between Sept. 7 and Nov. 7, 2025.
FAIRWINDS was notified of the incident in August 2026 and completed its review in September, according to the report. The breach involved Mercadien's systems rather than FAIRWINDS' systems, and the credit union has since ended its relationship with the vendor.
FAIRWINDS notified affected individuals and reported the incident to state regulators on or about Sept. 23, according to Morningstar. The total number of people affected was not disclosed. Edelson Lechtzin said it is investigating potential data-privacy claims arising from the incident.
Originally reported by CU Today.