21st MidAmerica Credit Union Reports 2025 Data Breach in Indiana
21st MidAmerica Credit Union, based in Indiana, officially reported a data security incident on January 22, 2026, stemming from an event on August 14, 2025. This breach exposed highly sensitive personal and financial data, potentially impacting its members through identity theft risks and financial fraud.
- State
- Indiana
- Breach date
- August 14, 2025
- Reported
- January 22, 2026
What may have been exposed
- Full Name
- Social Security Number
- Date of Birth
- Financial Account Number
- Routing Number
- Credit Score Information
- Transaction History
- Mailing Address
21st MidAmerica Credit Union in Indiana officially reported a data security incident to regulators on January 22, 2026. The breach event itself occurred on August 14, 2025, and the specific mechanics of how the intrusion happened remain unspecified. The investigation into the incident is currently under monitoring.
As a financial institution, 21st MidAmerica Credit Union handles an extensive volume of sensitive personal and financial data from its members, which is essential for providing banking, lending, and wealth management services. Institutions holding such valuable information are frequent targets for malicious actors seeking to compromise data through various cyberattacks.
The compromised data types in this incident include Full Name, Social Security Number, Date of Birth, Financial Account Number, Routing Number, Credit Score Information, Transaction History, and Mailing Address. The exposure of this combination of details creates substantial risks for affected individuals.
When information such as Social Security numbers and financial account details are leaked, individuals face an elevated threat of identity theft, unauthorized credit applications, fraudulent wire transfers, and account takeovers. Unlike a simple credit card compromise, the exposure of core identity and financial credentials can lead to long-term issues, requiring extensive recovery efforts.
Individuals who believe they may be affected by this breach should remain vigilant. It is recommended to regularly monitor financial account statements and credit reports for any suspicious activity. Placing a fraud alert or security freeze on credit files can also provide an additional layer of protection against unauthorized use of personal information.
What to do if you were affected
Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Watch your financial accounts
Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Source: Indiana Attorney General filing
Related data breach cases
- Teamsters Local 17
- Bank
- American Motorcyclist Association
- Deer Management Co. LLC dba Bessemer Venture Partners
- MEBS Global Reach
- McKenzie Creative Brands
- Midvale Indemnity and American Family Connect Insurance Company
- Nishiyamato Academy
- 9World Acceptance Corporation
- Chicago Psychoanalytic Institute
- Poppins Payroll Company
- Baltimore Medical System Inc
- Pavillon International Inc
- 7The Association of the Bar of the City of New York