In 2025-2026, 1st MidAmerica Credit Union experienced a data breach stemming from unauthorized access to the network of its third-party vendor, Marquis Software Solutions, on or around August 14, 2025. The credit union became aware of the incident on August 14, 2025. The breach did not involve the credit union's internal systems.
The breach affected 131,070 individuals. Exposed data types include name, Social Security number, date of birth, address, government IDs, and financial account information such as account and credit/debit card numbers. While one report mentioned medical information, this is not widely confirmed across sources. States confirmed to be affected include Maine, Indiana, New Hampshire, Texas, and Vermont. Notifications to consumers began on January 22, 2026, and regulators in affected states were subsequently notified.
Details about data breaches can emerge over time, and notification processes may experience delays.