Skip to main content

Ransomware: 'It's A Growing Issue'

MADISON, Wis.—Ransomware attacks, already a quiet concern that has been growing among credit unions, are expected to dramatically increase this year—with one analyst saying there is “no silver bullet” to prevent the threat.
Ransomware is a type of malicious software designed to block access to a computer system or PC until a sum of money is paid. In the case of a financial institution, crooks first use the malware to encrypt the contents of the FI’s data and then extract a ransom in exchange for decrypting the information and allowing the victim to regain access.

It’s an issue, according to one regulator source who asked for anonymity that has been growing within credit unions, many of which have paid ransoms to regain access to their data and have chosen not to speaking publicly about the crime.
“This has become a huge problem,” said Ken Otsuka, senior consultant in CUNA Mutual Group’s risk management department, adding that CUNA Mutual Group’s cyber liability coverage data does not break down the type of cyber-attack that leads to a claim. “The FBI statistics are unnerving.”
According to the FBI, between April 2014 and June 2015 the agency received 992 ransomware complaints, with victims reporting losses of more than $18 million. Overall, reports indicate that losses from ransomware to date range from tens of millions to hundreds of millions of dollars.
Experts are predicting the threat will spread in 2016 due to inexpensive, do-it-yourself ransomware kits that are beginning to become available in underground markets.
“Analysts are concerned that cyber criminals are on the verge of widening the scope of their attacks,” reported ThirdCertainty’s Jaikumar Vijayan. “Researchers at security vendor Emsisoft analyzed a malware tool dubbed Ransom32 that many believe is a harbinger of things to come on the ransomware front.”
Portabile Platform
Ransom32 is the first ransomware tool written entirely in Javascript. That makes it easily portable to other platforms such as Linux and Mac OS X, Vijayan reported.
While reports indicate that ransomware costs can reach as high as $5,000 per user on an infected system, the bigger costs, sources say, come from staff downtime and from the credit union’s damaged reputation among its members.
According to a survey conducted by cloud IT services company Intermedia, many firms do not have a business continuity plan that would help them continue working while under a ransomware attack. Instead, they suffer costly downtime, with 72% not being able to access their files for two days, and 32% for five days or more.
Otsuka confirmed that a business continuity plan to address a ransomware attack is necessary today. He also outlined several steps credit unions should take to defend against ransomware, none more important that backing up data regularly.
“The big item is making sure the credit union has an effective data backup strategy in place so that if the credit union is hit with a ransomware attack and files are unreadable, it can go back to the most recent backup media tape and restore the data and not have to pay the ransom,” said Otsuka.
Otsuka said credit unions should periodically conduct “restore tests,” where they test to see if the data they would use to restore compromised files is usable.
“The time to find out your backup data is not usable is not during the middle of a ransomware attack,” he said.
Steps to Take
Noting there is no “silver bullet,” Otsuka outlined other important steps to guard against ransomware:
·         Securely configure systems and services.
·         Protect against unauthorized access.
·         Perform security monitoring, prevention and risk mitigation.
·         Update information security awareness and training programs to include cyber-attacks involving extortion.
·         Implement and regularly test controls around critical systems.
·         Review, update and test incident response and business continuity plans periodically.
·         Ensure antivirus programs are kept up-to-date.
·         Confirm operating systems and software are kept up-to-date with the latest patches.
·         Block access to personal email accounts.
·         Deploy spam and web filters.
·         Enable pop-up blockers.
As if often the case, in many successful cyber-attacks, staff are often the weak link, said Otsuka. He emphasized that credit unions should regularly test employees to make sure they understand how to prevent against phishing attacks and other email scams that can infect the system.
“I would test employees by sending them phishing-like emails to see how susceptible they are,” said Otsuka, explaining that cyber security companies can provide these “test” emails.
Otsuka said another key guiding principle is to network on risks, such as in industry information-sharing forums, and share information regarding threat intelligence.
“Credit unions with a CUNA Mutual Group cyber liability insurance policy may be eligible for a discounted membership fee for the Financial Services Information Sharing and Analysis Center (FS-ISAC),” said Otsuka.

To learn more, visit www.cunamutual.com/fs-isac

Comments

Popular posts from this blog

NCUA Board Approves 11 Final Rules for Deregulation Project

Alexandria, VA (August 5, 2026) ― The National Credit Union Administration (NCUA) today finalized eleven rules that were proposed for changes through the Deregulation Project. This is the first round of final rules from the ongoing Deregulation Project which is an initiative to review NCUA’s regulations and ensure they are focused on credit unions’ safety, soundness, and resilience. The final rules include: This is an external link to a website belonging to another federal agency, private organization, or commercial entity. Surety and Guarantor Requirements – 12 CFR 701.20(c)(3) and 701.20(d) (Opens new window) This is an external link to a website belonging to another federal agency, private organization, or commercial entity. Limits on Loan to Other Credit Unions – 12 CFR 701.25(b) (Opens new window) This is an external link to a website belonging to another federal agency, private organization, or commercial entity. Service to Underserved Areas – IRPS 08-2 (Opens new window) This is...

Making the Most of the Final Five Years Before Retirement

  NATIONAL COUNCIL OF FIRST RESPONDER CREDIT UNIONS RETIREMENT READINESS Making the Most of the Final Five Years Before Retirement A practical planning guide for first responders, credit union volunteers, employees, and their families Five years before retirement is an important checkpoint. It is the time to confirm what you have saved, understand the income you can expect, and decide whether your retirement plans match the life you want to lead.   1. Review Your Retirement Savings Start by taking a fresh look at your retirement accounts, personal savings, investments, and other assets. A retirement calculator can help estimate whether you are on track and show how additional saving during the next five years may strengthen your plan.   2. Identify Every Source of Retirement Income List the income you may receive in retirement, including pensions, Social Security, retirement-plan withdrawals, invest...

Senate, 51-47, has confirmed John Crews to the NCUA board

WASHINGTON—The U.S. Senate, 51-47, has confirmed John Crews to the NCUA board, clearing the way for him to succeed Kyle Hauptman and return the agency to a single-member board following the Trump Administration's removal of Democratic board members Todd Harper and Tanya Otsuka earlier this year. Maintaining the foundational stability of the credit union system Supporting efficient, risk-based regulation that accounts for institutional size and operational differences Preparing for technological advancement while safeguarding member assets Encouraging the growth of new credit unions to serve underbanked and military communities Preserving an open, accessible, and collaborative dialogue between the NCUA and the credit union movement Crews, who most recently served in the Treasury Department, has said his priorities include reducing regulatory burden for smaller credit unions, encouraging innovation and supporting the chartering of new credit unions, while maintaining the safety and s...

Liquidity Resources

Liquidity Resources Liquidity is a credit union’s capacity to meet its cash and collateral obligations at a reasonable cost. Adequate liquidity is necessary to efficiently meet both expected and unexpected cash flows and collateral needs without compromising the credit union’s daily operations or financial condition. Effective credit union management identifies, measures, monitors, and controls exposure to liquidity risk. Primary Risks In managing expected cash flows, a credit union may experience situations that increase its liquidity risk. These situations include mismatches between sources and uses of funds, market constraints on the ability to convert assets into cash or to access sources of funds (market liquidity), and contingent liquidity events. Changes in economic conditions or exposure to credit, market, operational, legal, and also can affect an institution’s liquidity risk profile. None of these risks are mutually exclusive, and interrelated risks may contribute to increase...

Not Your Mother’s Credit Union

“Stablecoins aren’t a speculative play. They’re the next evolution of payments — and a chance for credit unions to lead, not lag. It starts with connecting members to DLT rails - the digital wallet. Without that, nothing else can happen. It’s just a new payment rail - embrace it or lose the relationship. It’s that simple.” While ‘ stablecoins ’ were the prevailing buzzword across Money20/20 this year, the credit union industry had a significant presence. Small financial institutions have staked a place in the future of payments. Credit unions  received a significant boost this summer with the enactment of the stablecoin bill into law. The Guiding and Establishing National Innovation for U.S. Stablecoins Act authorizes subsidiaries of federally insured credit unions, such as credit union service organizations, to become issuers. Not Your Mother’s Credit Union A Money20/20  fireside chat  with the regulator for credit unions that I moderated focused on the rulemaking task a...

CFPB Issues Final Rule on Remittance Transfers; Proposes Changes As Well

On January 20, 2012, the CFPB adopted a final rule amending Regulation E (Electronic Fund Transfers) to include consumer protections for various types of remittance transfers. The rule was originally proposed by the Federal Reserve Board last May; however, authority to finalize the rule-making transferred to the CFPB on July 21, 2011  ****More At;  CFPB Issues Final Rule on Remittance Transfers; Proposes Changes As Well : Written by Bernadette Clair, Regulatory Compliance Counsel   

Dolphin Debit, Enters into Partnership With CUSI

 HOUSTON–  Dolphin Debit , a full-service ATM management company, said it has entered into a strategic partnership with Credit Union Services, Inc. (CUSI), the Service Corporation of the MD|DC Credit Union Association. “Through the strategic partnership, CUSI adds a budget-ready, industry-leading ATM management program to its portfolio of solutions for credit unions in the Maryland and D.C. region,” Dolphin Debit said. According to Dolphin Debit, its ATM outsourcing service includes purchase and deployment of new ATMs, purchase of the financial institution’s existing ATMs, terminal driving, transaction processing, ATM maintenance, armored car service, communications, monitoring and dispatch, and cash management. “We welcome this oppor...

Interest-bearing stablecoins could siphon deposits from community banks and credit unions

  WASHINGTON — Warning that interest-bearing stablecoins could siphon deposits from community banks and other traditional financial institutions, the American Bankers Association joined 52 state bankers associations from across the country in submitting a   letter   to the U.S. Department of the Treasury urging strong implementation of the GENIUS Act’s prohibition on interest for payment stablecoins. The letter, which responds to Treasury’s advance notice of proposed rulemaking regarding implementation of the GENIUS Act, emphasizes the need to preserve the law’s core intent: ensuring stablecoins serve as payment tools, not investment vehicles. iStock-Gri-spb “The GENIUS Act’s prohibition on a payment stablecoin issuer paying interest or yield on payment stablecoins reflects Congress’s intent for payment stablecoins to be used for transactions and not as investment vehicles,” the associations wrote. “Treasury must reinforce this intent.” The associations warn that wit...

What’s Ahead for U.S. Economy? Here’s What One Former Fed Chair is Saying

 WASHINGTON–Former Federal Reserve Chairman Ben Bernanke, who headed the central bank during the 2008 financial crisis, is now warning that the United States is headed for a situation similar to that of the 1970s, when Americans were losing their jobs but still facing higher prices at the grocery store and at the pump. Ben Bernanke “Even under the benign scenario, we should have a slowing economy,” Bernanke told the New York Times in an interview in conjunction with his new book, “ 21st Century Monetary Policy: The Federal Reserve From the Great Inflation to Covid-19 ,” which is scheduled to publish today. “So, there should be a period in the next year...

Sunday Reading - Near-death experiences, 101

  Scrapes with Death   Near-death experiences, 101 A near-death experience usually occurs in the wake of a traumatic physical event or a reversible clinical death, such as when someone is  revived after a heart attack . While the experience varies, NDEs commonly feature a feeling of detachment from the body, visions of bright lights, a warped sense of time, or religious experiences. Records of NDEs go back to the ancient Greeks and are found across cultures all over the world. The first known clinical observation was recorded  in 18th-century France . In the 1970s, psychiatrist Raymond Moody pioneered the academic study of NDEs as medical events after an acquaintance relayed his own near-death experience. Roughly  5% of the population  is estimated to have a memory of an NDE, with common reports of a feeling of peacefulness (80%), followed by bright lights (69%) and encountering other people or spirits (64%). ... Read our full  explainer on NDEs here ....