Skip to main content

Ransomware: 'It's A Growing Issue'

MADISON, Wis.—Ransomware attacks, already a quiet concern that has been growing among credit unions, are expected to dramatically increase this year—with one analyst saying there is “no silver bullet” to prevent the threat.
Ransomware is a type of malicious software designed to block access to a computer system or PC until a sum of money is paid. In the case of a financial institution, crooks first use the malware to encrypt the contents of the FI’s data and then extract a ransom in exchange for decrypting the information and allowing the victim to regain access.

It’s an issue, according to one regulator source who asked for anonymity that has been growing within credit unions, many of which have paid ransoms to regain access to their data and have chosen not to speaking publicly about the crime.
“This has become a huge problem,” said Ken Otsuka, senior consultant in CUNA Mutual Group’s risk management department, adding that CUNA Mutual Group’s cyber liability coverage data does not break down the type of cyber-attack that leads to a claim. “The FBI statistics are unnerving.”
According to the FBI, between April 2014 and June 2015 the agency received 992 ransomware complaints, with victims reporting losses of more than $18 million. Overall, reports indicate that losses from ransomware to date range from tens of millions to hundreds of millions of dollars.
Experts are predicting the threat will spread in 2016 due to inexpensive, do-it-yourself ransomware kits that are beginning to become available in underground markets.
“Analysts are concerned that cyber criminals are on the verge of widening the scope of their attacks,” reported ThirdCertainty’s Jaikumar Vijayan. “Researchers at security vendor Emsisoft analyzed a malware tool dubbed Ransom32 that many believe is a harbinger of things to come on the ransomware front.”
Portabile Platform
Ransom32 is the first ransomware tool written entirely in Javascript. That makes it easily portable to other platforms such as Linux and Mac OS X, Vijayan reported.
While reports indicate that ransomware costs can reach as high as $5,000 per user on an infected system, the bigger costs, sources say, come from staff downtime and from the credit union’s damaged reputation among its members.
According to a survey conducted by cloud IT services company Intermedia, many firms do not have a business continuity plan that would help them continue working while under a ransomware attack. Instead, they suffer costly downtime, with 72% not being able to access their files for two days, and 32% for five days or more.
Otsuka confirmed that a business continuity plan to address a ransomware attack is necessary today. He also outlined several steps credit unions should take to defend against ransomware, none more important that backing up data regularly.
“The big item is making sure the credit union has an effective data backup strategy in place so that if the credit union is hit with a ransomware attack and files are unreadable, it can go back to the most recent backup media tape and restore the data and not have to pay the ransom,” said Otsuka.
Otsuka said credit unions should periodically conduct “restore tests,” where they test to see if the data they would use to restore compromised files is usable.
“The time to find out your backup data is not usable is not during the middle of a ransomware attack,” he said.
Steps to Take
Noting there is no “silver bullet,” Otsuka outlined other important steps to guard against ransomware:
·         Securely configure systems and services.
·         Protect against unauthorized access.
·         Perform security monitoring, prevention and risk mitigation.
·         Update information security awareness and training programs to include cyber-attacks involving extortion.
·         Implement and regularly test controls around critical systems.
·         Review, update and test incident response and business continuity plans periodically.
·         Ensure antivirus programs are kept up-to-date.
·         Confirm operating systems and software are kept up-to-date with the latest patches.
·         Block access to personal email accounts.
·         Deploy spam and web filters.
·         Enable pop-up blockers.
As if often the case, in many successful cyber-attacks, staff are often the weak link, said Otsuka. He emphasized that credit unions should regularly test employees to make sure they understand how to prevent against phishing attacks and other email scams that can infect the system.
“I would test employees by sending them phishing-like emails to see how susceptible they are,” said Otsuka, explaining that cyber security companies can provide these “test” emails.
Otsuka said another key guiding principle is to network on risks, such as in industry information-sharing forums, and share information regarding threat intelligence.
“Credit unions with a CUNA Mutual Group cyber liability insurance policy may be eligible for a discounted membership fee for the Financial Services Information Sharing and Analysis Center (FS-ISAC),” said Otsuka.

To learn more, visit www.cunamutual.com/fs-isac

Comments

Popular posts from this blog

Sunday Reading - Changing the Map

  Changing the Map     Redistricting, explained Congressional redistricting is the process by which states redraw electoral district boundaries   that determine representation in the US House of Representatives. The Constitution, federal law, and court rulings require districts to have roughly equal populations, avoid discrimination against racial or language minorities, and, in most states, be geographically contiguous. For most of American history, redistricting has followed a predictable cycle, occurring every 10 years after the census.   Gerrymandering is the deliberate manipulation of district boundaries to advantage one political party. Common tactics  by both major American political parties include packing opposition voters i...

Reuters: Trump Regulators Launch Biggest Bank Oversight Overhaul Since 2008

Is NCUA next? WASHINGTON—Federal banking regulators under President Trump are undertaking what Reuters described as the most significant overhaul of bank supervision since the 2008 financial crisis, shifting examiner focus away from process and compliance issues and toward what agencies consider “material” financial risks. According to Reuters, the Federal Reserve, the Office of the Comptroller of the Currency and the Federal Deposit Insurance Corp. have directed examiners to concentrate on risks that pose direct threats to a bank’s safety and soundness, rather than on paperwork deficiencies, governance concerns or procedural issues that do not immediately affect financial stability. Reuters reported that regulators have also moved away from evaluating banks based on “reputational risk,” a supervisory concept long criticized by banks as overly subjective. The change follows complaints from President Trump and others that financial institutions have used reputational-risk considerations...

Hauptman Tells Congress CU Health is Strong; Responds to Questions from Committee

WASHINGTON — National Credit Union Administration Chairman Kyle Hauptman told members of the House Financial Services Committee on Thursday that the nation’s credit union system remains financially strong, while warning that rising delinquencies and consumer financial stress continue to warrant close monitoring. Hauptman also responded to a handful of questions from members of Congress, as well. Hauptman appeared as part of the regular hearings on Oversight of Prudential Regulators. Also appearing as witnesses were Michelle Bowman, vice chair for supervision with the Federal Reserve; Travis Hill, FDIC chairman, and Jonathan Gould, the acting Comptroller of the Currency. Kyle Hauptman In his prepared statement, Hauptman said federally insured credit unions remain well-capitalized and continue to meet members’ borrowing needs despite economic headwinds. He said the NCUA is focused on maintaining safety and soundness, protecting the National Credit Union Share Insurance Fund and creating...

The Role of the Board Chair

Tim Harrington, CPA   CEO, TEAM Resources The Role of the Board Chair Recently I had the chance to spend some time with a great group of board members . One of the things we talked about was the role of the board chair. I thought this well worth putting down on *paper* as it were. The role of the chairperson is multi-faceted, complex, and often changing within the context of the organization’s dynamic. Unfortunately, there’s no perfect set of “rules.” But there are some guidelines. Here are our “tips” on navigating the position successfully: Roles Facilitator  – The board chair must draw together the individual directors into a team, working together on behalf of the membership and the credit union. To do that, s/he must wrangle individual personalities, draw out conversation from some, and rein it in from others. Having a solid understanding of the personalities of each director … and the CEO helps the chair keep things on track, moving forward, and civil. ...

Trump Accounts Program For Children Moves Forward With New Mobile App Launch

  WASHINGTON—The Treasury Department on Thursday announced the launch of the new Trump Accounts mobile app, marking the next phase of the Administration’s rollout of its new federally backed investment savings program for children ahead of the program’s official July 4 launch date. Donald Trump The app, now available through major mobile app stores, will serve as the primary platform for families to manage and activate Trump Accounts. Treasury Secretary Scott Bessent said the app is intended to give parents and guardians a “simple, secure way” to participate in the program, which was created under the 2025 Republican tax-and-spending package. Families that already submitted IRS Form 4547 to enroll children in the program will begin receiving phased activation emails between now and July 4, according to Treasury. Under the program, eligible children born between Jan. 1, 2025, and Dec. 31, 2028, can receive a one-time $1,000 federal seed contribution into a tax-deferred investment ac...

Cheer Up and Change: "Wait and see is not a plan."

I posted this a year ago and thought I would bring it back to see if any of his predictions came true. Take a look and tell us what you think. Grant Sheehan CEO Cheer Up and Change: The Demographic Mandate At a conference I recently attended Monday morning started off with a great session by demographer and futurist Ken Gronbach, who laid out his predictions on where we’re going and what we can expect as demographics change. I was pleasantly surprised that the future isn’t sounding as bleak as the news might have you believe. Gronbach offered lots of predictions for where our society and our world is headed. His predictions were given with a purpose: To help associations build their vision and plan for the future. As Gronbach stressed,  "Wait and see is not a plan." I’ve decided to arrange this recap into a list of my takeaways rather than a narrative recap. I hope you get as much out of this information as I did! Things to Expect: Big Changes in Retail : Gronbach ...

Supplemental Capital to be Considered by NCUA

Supplemental Capital At the NCUA’s October board meeting, senior staff of the NCUA submitted a briefing report (the “Report”) to the NCUA Board (the “Board”) on the issues concerning the use of supplemental capital by federally insured credit unions (“FICUs”).  The use of supplemental capital presents a number of regulatory and policy issues that would need to be addressed prior to authorizing this form of capital for all FICUs.  The Board considered issuing an advanced notice of proposed rulemaking (“ANPR”) in the near future which would give credit unions and the public the opportunity to provide comment before the proposed rule stage.  Supplemental capital does not provide any capital support under the NCUA’s net worth requirements because it does not count as equity under generally accepted accounting principles, but it would allow FICUs to have a greater concentration of member business loans and long term mortgage loans since it could be used by FICUs to meet...

Letter to Credit Unions Says NCUA Exam Modernization Now Underway

ALEXANDRIA, Va.—NCUA has sent a Letter to Credit Unions ( 21-CU-08 ) detailing the agency's transition to modernized systems. The agency said it will begin this transition in August. NCUA’s efforts will include the implementation of emerging and secure technology that supports the NCUA’s examination, data collection, field of membership, and reporting efforts. “These new applications will streamline processes and procedures and provide significant benefits to credit union users,” NCUA said. Key areas affected: NCUA Connect Admin Portal Consumer Access Process and Reporting Information System (CAPRIS) 1 Modern Examination & Risk Identification Tool (MERIT) Data Exchange Application (DEXA) Training Available To prepare credit unions for the transition to these new systems, NCUA said it will provide credit union user training through various avenues, including: A self-paced training curriculum covering MERIT functionality available through the NCUA’s Learning Management Service An...

IRS Reporting Requirement Has Turned Into Uphill Battle for CUs

  It’s in. It’s out. It’s in again. On Thursday, NAFCU, CUNA and more than 100 associations sent a letter to all members of the U.S. House of Representatives and Senate asking them to reject a proposed IRS reporting requirement that credit union trades have been pushing back against since July . The proposed IRS reporting requirement would require financial institutions, including credit unions, to report the inflows and outflows of personal and business accounts, as well as transfers between accounts of the same owner, if it is more than $600 per year. The proposal found new life inside the House version of the budget reconciliation bill after it was rejected in the version approved by the House Ways and Means Committee last month. On Tuesday, Speaker of the House Nancy Pelosi (D-Calif.) said the IRS reporting requirement would be included in the House version of the bill. CUNA, NAFCU and other organizations voiced their objections to the proposal in a joint letter. While the l...