Skip to main content

Ransomware: 'It's A Growing Issue'

MADISON, Wis.—Ransomware attacks, already a quiet concern that has been growing among credit unions, are expected to dramatically increase this year—with one analyst saying there is “no silver bullet” to prevent the threat.
Ransomware is a type of malicious software designed to block access to a computer system or PC until a sum of money is paid. In the case of a financial institution, crooks first use the malware to encrypt the contents of the FI’s data and then extract a ransom in exchange for decrypting the information and allowing the victim to regain access.

It’s an issue, according to one regulator source who asked for anonymity that has been growing within credit unions, many of which have paid ransoms to regain access to their data and have chosen not to speaking publicly about the crime.
“This has become a huge problem,” said Ken Otsuka, senior consultant in CUNA Mutual Group’s risk management department, adding that CUNA Mutual Group’s cyber liability coverage data does not break down the type of cyber-attack that leads to a claim. “The FBI statistics are unnerving.”
According to the FBI, between April 2014 and June 2015 the agency received 992 ransomware complaints, with victims reporting losses of more than $18 million. Overall, reports indicate that losses from ransomware to date range from tens of millions to hundreds of millions of dollars.
Experts are predicting the threat will spread in 2016 due to inexpensive, do-it-yourself ransomware kits that are beginning to become available in underground markets.
“Analysts are concerned that cyber criminals are on the verge of widening the scope of their attacks,” reported ThirdCertainty’s Jaikumar Vijayan. “Researchers at security vendor Emsisoft analyzed a malware tool dubbed Ransom32 that many believe is a harbinger of things to come on the ransomware front.”
Portabile Platform
Ransom32 is the first ransomware tool written entirely in Javascript. That makes it easily portable to other platforms such as Linux and Mac OS X, Vijayan reported.
While reports indicate that ransomware costs can reach as high as $5,000 per user on an infected system, the bigger costs, sources say, come from staff downtime and from the credit union’s damaged reputation among its members.
According to a survey conducted by cloud IT services company Intermedia, many firms do not have a business continuity plan that would help them continue working while under a ransomware attack. Instead, they suffer costly downtime, with 72% not being able to access their files for two days, and 32% for five days or more.
Otsuka confirmed that a business continuity plan to address a ransomware attack is necessary today. He also outlined several steps credit unions should take to defend against ransomware, none more important that backing up data regularly.
“The big item is making sure the credit union has an effective data backup strategy in place so that if the credit union is hit with a ransomware attack and files are unreadable, it can go back to the most recent backup media tape and restore the data and not have to pay the ransom,” said Otsuka.
Otsuka said credit unions should periodically conduct “restore tests,” where they test to see if the data they would use to restore compromised files is usable.
“The time to find out your backup data is not usable is not during the middle of a ransomware attack,” he said.
Steps to Take
Noting there is no “silver bullet,” Otsuka outlined other important steps to guard against ransomware:
·         Securely configure systems and services.
·         Protect against unauthorized access.
·         Perform security monitoring, prevention and risk mitigation.
·         Update information security awareness and training programs to include cyber-attacks involving extortion.
·         Implement and regularly test controls around critical systems.
·         Review, update and test incident response and business continuity plans periodically.
·         Ensure antivirus programs are kept up-to-date.
·         Confirm operating systems and software are kept up-to-date with the latest patches.
·         Block access to personal email accounts.
·         Deploy spam and web filters.
·         Enable pop-up blockers.
As if often the case, in many successful cyber-attacks, staff are often the weak link, said Otsuka. He emphasized that credit unions should regularly test employees to make sure they understand how to prevent against phishing attacks and other email scams that can infect the system.
“I would test employees by sending them phishing-like emails to see how susceptible they are,” said Otsuka, explaining that cyber security companies can provide these “test” emails.
Otsuka said another key guiding principle is to network on risks, such as in industry information-sharing forums, and share information regarding threat intelligence.
“Credit unions with a CUNA Mutual Group cyber liability insurance policy may be eligible for a discounted membership fee for the Financial Services Information Sharing and Analysis Center (FS-ISAC),” said Otsuka.

To learn more, visit www.cunamutual.com/fs-isac

Comments

Popular posts from this blog

Growing Your Credit Union Without Expanding Your FOM

For many firefighter and other credit union primarly serving first responders, growth often feels tied to one big decision: expanding the Field of Membership (FOM). But what if you didn’t have to? What if growth could come from within —by deepening relationships, increasing engagement, and capturing more of the financial lives of the members you already serve? The truth is: it can. But it requires a shift in strategy. Rethinking What “Growth” Really Means Most institutions define growth as adding more members. But for single-sponsor credit unions, especially those serving first responders, a more powerful definition is: Growth = more value per member Many members only use one or two products—often a checking account and maybe an auto loan. Meanwhile, larger banks capture mortgages, credit cards, and investments. The opportunity isn’t just new members. It’s: More products per member Higher balances per relationship Greater share of wallet Your Biggest Advantage: The First Responder Life...

When Vendors Price for Giants

 Grant Sheehan CCUE | CEO Opinion: When Vendors Price for Giants, They Shrink the Future of Small Credit Unions ! There’s a quiet squeeze happening in the credit union industry, and it’s not coming from regulators or competition from big banks. It’s coming from the very vendors that claim to support the ecosystem. For small credit unions, the problem is increasingly simple and factual: the tools required to compete with digital banking platforms, fraud systems, compliance software, analytics, and payments infrastructure are priced for institutions ten or even 100 times their size. The result is a market where access to essential services is determined not by mission or member need, but by asset size. This isn’t just inconvenient. It’s structurally threatening. Vendors often defend their pricing models as a reflection of complexity or scale. Larger credit unions have more users, more transactions, more integrations, so they pay more, and that seems fair on the surface. But t...

Credit Union Lending Picks Up in Most Areas

Credit unions were increasing their portfolios in most areas in June, except business lending and new car loans, where portfolios fell for the 24th month in a row after seasonal adjustments, according to a CUNA Mutual Group report released Tuesday. The Madison, Wis., trade group’s Credit Union Trends Report showed new auto loan balances were $141 billion on June 30, falling at a 3.3% seasonally adjusted, annualized rate from May to June, part of the May-through-October peak car-buying season. Credit unions held $252.4 billion in used car loans on June 30, up 1.2% from May without seasonal adjustments. The Trends Report made slight adjustments to CUNA’s Monthly Credit Union Estimates released earlier in the month. In this case, its changes allowed total auto loan balances to show a slight 0.3% un-adjusted May-to-June gain, compared to being flat in the CUNA report. Steve Rick, chief economist for CUNA Mutual Group and the report’s author, said gains were stronger in other areas, includ...

The FedNow Service will launch in 2023 "Are you ready?"

The FedNow Service is a new instant payment service that the Federal Reserve Banks are developing to enable financial institutions of every size, and in every community across the U.S., to provide safe and efficient instant payment services in real-time, around the clock, every day of the year. Through financial institutions participating in the FedNow Service, businesses and individuals will be able to send and receive instant payments conveniently, and recipients will have full access to funds immediately, giving them greater flexibility to manage their money and make time-sensitive payments. Consistent with the Federal Reserve’s historical role of providing payment services alongside private-sector providers, the FedNow Service will provide choice in the market for clearing and settling instant payments as well as promote resiliency through redundancy. Financial institutions and their service providers will be able to use the service as a springboard to provide innovative instant p...

Rick Metsger reminded credit unions the National Credit Union Share Insurance Fund may be required to increase loss reserves as the values of taxi medallions decline.

A LEXANDRIA, Va. (Dec. 8, 2017)  – National Credit Union Administration Board Member Rick Metsger today reminded credit unions the National Credit Union Share Insurance Fund may be required to increase loss reserves as the values of taxi medallions decline. “Prices for New York taxi medallions at two recent public auctions have been considerably lower,” Metsger said. “That, combined with a continued increase in already high delinquency rates on medallion loans, suggests the Share Insurance Fund’s reserves may have to increase in the very near future.” Metsger spoke today to the Oregon Department of Financial Services CEO roundtable in Salem, Oregon. His remarks covered various issues related to credit union regulation and the Share Insurance Fund.  Metsger said the NCUA issued a Letter to Credit Unions in 2010,   warning of concentration risk , and the agency issued a more specific letter on   taxi medallion lending in 2014​ . “We have known, and warned ...

Facial recognition to secure payments will exceed 1.4 billion globally by 2025

BASINGSTOKE, U.K.– The number of users of software-based facial recognition to secure payments will exceed 1.4 billion globally by 2025, from just 671 million in 2020, according to a new study from Juniper Research. “This rapid growth of 120% demonstrates how widespread facial recognition has become; fueled by its low barriers to entry, a front-facing camera and appropriate software,” Juniper said, noting the research identified the implementation of FaceID by Apple as accelerating the growth of the wider facial recognition market, despite the challenges to facial recognition during the pandemic with face mask use. The research recommends that facial recognition vendors implement robust and rapidly evolving AI based verification checks to ensure the validity of user identity, or risk losing user trust in the authentication method as spoofing attempts increase, Juniper reported. Fingerprint Sensors The new research, Mobile Payment Authentication: Biometrics, Regulation & Market Fore...

Credit unions lending rose at a faster pace in most sectors than the small banks last year, according to data released this week by the FDIC and CUNA Mutual Group.

What credit unions lacked in size they made up for in speed compared with community banks and savings institutions in 2017. Credit unions lending rose at a faster pace in most sectors than the small banks last year, according to data released this week by the FDIC and CUNA Mutual Group. CUNA Mutual’s monthly  trends report  showed credit unions held $984.8 billion in total loans at Dec. 31, up 10.7% from a year earlier and a growth rate more than twice as fast as community banks. Credit union assets rose 6.3% to $1.4 trillion due to a 6.3% increase in deposits, a 3% drop in borrowings and a 7.7% increase in capital. With loan balances growing faster than assets, the loan-to-asset ratio ended 2017 at 70.4%, up from 67.5% a year earlier. The fast loan growth also helped loan delinquency rates fall to 0.79% in December, down from 0.83% a year earlier, according to CUNA Mutual. The FDIC’s Quarterly Banking Profile showed loans at the nation’s 5,670 community banks ...

Don't say NO to your members anymore!

Does the following scenario occur at your credit union? If it does, we have a solution for you! A member comes in into your credit union and wants to know if you will loan them a couple of hundred thousand $$$ to buy a building, or can you loan him some seed money to start a new business or purchase equipment for the company they currently own, and you say,  “the credit union doesn't do those kinds of loans”.  Does this sound familiar? How many times do you and your staff say NO and literally tell a member to  “go down the street or go somewhere else” ?  Well, now, you have another option.   CU First Responders Finance (CUFR) CU First Responders Finance, LLC (CUFR)  is a partnership between the National Council of Firefighter Credit Unions, Inc.   (NCOFCU) , and Biz Lending & Insurance Center, Inc. to provide business lending origination programs to NCOFCU member credit unions. CUFR  will provide you with a turnkey operati...

Americans are using alternative financing arrangements, such as rent-to-own

CUToday PHILADELPHIA–Many Americans are using alternative financing arrangements, such as rent-to-own, that a new report from Pew Charitable Trusts indicates are generally riskier, more costly, and subject to far weaker consumer protections and regulatory oversight than traditional mortgages. Pew Trusts sad the “evidence suggests that a shortage of small mortgages, those for less than $150,000, may be driving some home borrowers (i.e., people who purchase a home with financing) who could qualify for a mortgage into these alternative arrangements. And other factors related to a home’s habitability and the ownership of the land beneath a manufactured home—the modern version of a mobile home—can make certain homes ineligible for mortgage financing altogether.” According to Pew, the evidence of potential consumer harm, little is known about the prevalence of alternative financing in the U.S., primarily because no systematic national data collection exists. Pew said approximate...

What should your credit union budget for in 2025?

As we enter the fourth quarter, many credit union leaders are starting to turn their attention toward planning for 2025. With a myriad of options and new technology, it’s crucial to prioritize services that set credit unions apart while encouraging growth. In this article, we explore several key areas credit unions should consider when preparing their budgets for the coming year. Expanding membership One significant trend shaping the financial landscape is the exodus of big banks from rural communities . This presents a golden opportunity to expand membership to new communities. However, this expansion doesn’t necessarily require traditional brick-and-mortar branches. Credit unions can leverage technology to provide services efficiently and cost-effectively. Some alternative service delivery methods include: Interactive Teller Machines (ITMs) : These advanced ATMs allow members to interact with a live teller via video, providing a personal touc...