Skip to main content

Ransomware: 'It's A Growing Issue'

MADISON, Wis.—Ransomware attacks, already a quiet concern that has been growing among credit unions, are expected to dramatically increase this year—with one analyst saying there is “no silver bullet” to prevent the threat.
Ransomware is a type of malicious software designed to block access to a computer system or PC until a sum of money is paid. In the case of a financial institution, crooks first use the malware to encrypt the contents of the FI’s data and then extract a ransom in exchange for decrypting the information and allowing the victim to regain access.

It’s an issue, according to one regulator source who asked for anonymity that has been growing within credit unions, many of which have paid ransoms to regain access to their data and have chosen not to speaking publicly about the crime.
“This has become a huge problem,” said Ken Otsuka, senior consultant in CUNA Mutual Group’s risk management department, adding that CUNA Mutual Group’s cyber liability coverage data does not break down the type of cyber-attack that leads to a claim. “The FBI statistics are unnerving.”
According to the FBI, between April 2014 and June 2015 the agency received 992 ransomware complaints, with victims reporting losses of more than $18 million. Overall, reports indicate that losses from ransomware to date range from tens of millions to hundreds of millions of dollars.
Experts are predicting the threat will spread in 2016 due to inexpensive, do-it-yourself ransomware kits that are beginning to become available in underground markets.
“Analysts are concerned that cyber criminals are on the verge of widening the scope of their attacks,” reported ThirdCertainty’s Jaikumar Vijayan. “Researchers at security vendor Emsisoft analyzed a malware tool dubbed Ransom32 that many believe is a harbinger of things to come on the ransomware front.”
Portabile Platform
Ransom32 is the first ransomware tool written entirely in Javascript. That makes it easily portable to other platforms such as Linux and Mac OS X, Vijayan reported.
While reports indicate that ransomware costs can reach as high as $5,000 per user on an infected system, the bigger costs, sources say, come from staff downtime and from the credit union’s damaged reputation among its members.
According to a survey conducted by cloud IT services company Intermedia, many firms do not have a business continuity plan that would help them continue working while under a ransomware attack. Instead, they suffer costly downtime, with 72% not being able to access their files for two days, and 32% for five days or more.
Otsuka confirmed that a business continuity plan to address a ransomware attack is necessary today. He also outlined several steps credit unions should take to defend against ransomware, none more important that backing up data regularly.
“The big item is making sure the credit union has an effective data backup strategy in place so that if the credit union is hit with a ransomware attack and files are unreadable, it can go back to the most recent backup media tape and restore the data and not have to pay the ransom,” said Otsuka.
Otsuka said credit unions should periodically conduct “restore tests,” where they test to see if the data they would use to restore compromised files is usable.
“The time to find out your backup data is not usable is not during the middle of a ransomware attack,” he said.
Steps to Take
Noting there is no “silver bullet,” Otsuka outlined other important steps to guard against ransomware:
·         Securely configure systems and services.
·         Protect against unauthorized access.
·         Perform security monitoring, prevention and risk mitigation.
·         Update information security awareness and training programs to include cyber-attacks involving extortion.
·         Implement and regularly test controls around critical systems.
·         Review, update and test incident response and business continuity plans periodically.
·         Ensure antivirus programs are kept up-to-date.
·         Confirm operating systems and software are kept up-to-date with the latest patches.
·         Block access to personal email accounts.
·         Deploy spam and web filters.
·         Enable pop-up blockers.
As if often the case, in many successful cyber-attacks, staff are often the weak link, said Otsuka. He emphasized that credit unions should regularly test employees to make sure they understand how to prevent against phishing attacks and other email scams that can infect the system.
“I would test employees by sending them phishing-like emails to see how susceptible they are,” said Otsuka, explaining that cyber security companies can provide these “test” emails.
Otsuka said another key guiding principle is to network on risks, such as in industry information-sharing forums, and share information regarding threat intelligence.
“Credit unions with a CUNA Mutual Group cyber liability insurance policy may be eligible for a discounted membership fee for the Financial Services Information Sharing and Analysis Center (FS-ISAC),” said Otsuka.

To learn more, visit www.cunamutual.com/fs-isac

Comments

Popular posts from this blog

The Skills Board Chairs Need Now: Leading Through Complexity, Not Control

NCOFCU Podcast   Grant Sheehan CCUE | CCUP | CEO-NCOFCU The role of the board chair has quietly—but fundamentally—changed. A decade ago, success was defined by experience, authority, and strategic judgment. Today, those traits are still relevant—but no longer sufficient. The modern board chair operates in a world shaped by competing stakeholder demands, technological disruption, geopolitical uncertainty, and increasing scrutiny. What emerges is a role that is less about control—and more about navigating complexity. Below are the core capabilities that now define effective board leadership. 1. From Authority to Orchestration The most important shift is conceptual. Board chairs are no longer expected to be the smartest voice in the room. Instead, they are expected to make the room smarter . This requires the ability to: Synthesize large volumes of information Reconcile conflicting perspectives Facilitate high-quality dialogue Traditional strengths like executive experience matter les...

It All Starts in the Boardroom

It all starts in the boardroom—but the consequences are felt far beyond it. When Governance Breaks Down, Members Pay the Price Credit unions are built on a simple but powerful idea: they are owned by their members. Unlike traditional banks, where shareholders drive decisions, credit unions are meant to operate democratically—guided by a volunteer board elected by the very people they serve. But that model only works when participation exists. A governance breakdown happens when the people elected to oversee an institution stop truly representing the people who own it. In credit unions, this breakdown doesn’t usually come from scandal or sudden failure. It happens quietly, over time—through disengagement. The Root of the Problem: Low Engagement Most credit union members don’t vote. Board election turnout is typically in the low single digits. In some cases, it’s barely measurable. That means a very small percentage of the membership is effectively deciding who governs an institution th...

On Stablecoins, NCUA Has Opportunity to Strike Right Balance and Get it Right

By Grant Sheehan As digital payments continue to evolve, the National Credit Union Administration’s (NCUA) efforts to establish a regulatory framework for stablecoins mark an important step forward. For credit unions, especially those serving mission-driven communities like firefighters and first responders, access to emerging financial technologies is not just an opportunity but a necessity to remain competitive and relevant. The  National Council of Firefighter Credit Unions  (NCOFCU) appreciates the  thoughtful input  provided by both America’s Credit Unions and the Defense Credit Union Council (DCUC) on the NCUA’s proposed stablecoin framework. We find strong merit in the recommendations of both organizations and believe their combined perspectives offer a constructive roadmap for getting this right. Important First Phase, But… At its core, the proposal represents an important first phase in implementing the stablecoin provisions of the GENIUS Act. Establishing a...

Sunday Reading - Why the IRS is necessary

  'Taxman'   Why the IRS is necessary The Internal Revenue Service, or IRS, is a division of the US Treasury Department created in 1862   that enforces the Internal Revenue Code —Title 26 of the US Code, a compilation of federal statutes—and, effectively, oversees tax collection. In 2024, the IRS's roughly 75,000 employees collected roughly $5T in tax revenue.   Given its role in diverting household income streams, it also has a bad reputation. Half of Americans had an "unfavorable view" of the IRS as of 2024 ( see data ). In a ranking of 16 well-known federal agencies by popularity that year, t...

It's Financial Literacy Month

April is Financial Literacy Month—a time dedicated to empowering individuals and families with the knowledge and tools needed to make informed financial decisions. Whether you're budgeting, saving, managing debt, or planning for the future, improving your financial literacy can have a lasting impact on your well-being. We invite you to explore our Consumer Education website, where you'll find helpful resources, tips, and guidance to support your financial journey. If you find it valuable, please share it with your family and friends—because financial knowledge is even more powerful when it’s shared. https://www.ncofcu.org/financial-literacy  ================================================= Remember, you're not alone with  NCOFCU.org Join/Upgrade Check out some of NCOFCU's additional features: Annual Conference First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Advocacy  

Growing Use of Stablecoins Could Reshape How FIs Manage Liquidity, Allocate Assets, NY Fed Report Suggests

NEW YORK — The growing use of stablecoins tied to the U.S. dollar could reshape how banks manage liquidity and allocate assets, potentially leading institutions that support the digital tokens to hold more reserves and make fewer loans, according to a new study from the  Federal Reserve Bank of New York . The paper, titled “ Stablecoin Disintermediation ,” was authored by economists Michael Junho Lee and Donny Tou and examines how stablecoin activity affects the balance sheets and liquidity management of banks that partner with stablecoin issuers. The researchers found that while stablecoins rely on traditional banks to function, the relationships can alter the liquidity demands placed on those institutions. Banks serving stablecoin issuers tend to hold larger reserve balances and reduce the share of assets devoted to lending, shifting toward a more reserve-heavy banking model. Focus of Study The study focused on developments following the March 2023 collapse of...

Why is NCUA Overlooking the Biggest Fee of All?

By Frank J. Diekmann NCUA has made a priority out of the F word in 2024—fees--announcing a special focus on NSF and OD fees this year.  And yet the agency seems to have little interest in the biggest and most egregious fee of all—the “merger” fee that comes when net worth isn’t returned to the people whose money it is in the first place, and it instead goes to insiders—often in amounts a multitude larger than any bounced check fee. It's sadly ironic that NCUA seems bothered by fees members opt into, but not by a merger fee they don’t seem able to opt out of. The merger fee is a hidden-in-plain-sight cost to members that is so brazen and increasingly occurring it has entered that dangerous territory of almost being taken for granted, wi...

Where are your children banking?

  Grant Sheehan CCUE | CCUP | CEO, NCOFCU The B reach  Between Purpose and Experience Just recently, I came across a story that has stayed with me. It wasn’t dramatic in the traditional sense. There was no scandal, no crisis, no headline-grabbing failure. In fact, it was something much quieter than that. It was simply the story of an eighteen-year-old leaving his credit union. On the surface, that might not sound remarkable. Young people move their money frequently. They open new accounts, experiment with apps, follow trends, and often make financial decisions influenced by the digital tools at their disposal. But this story was different. This young man had been a credit union member since he was a few weeks old, as many credit unions do. His mother has spent her career working inside the credit union movement as an executive. For eighteen years, his financial life was connected to a credit union. If anyone might be expected to remain a lifelong member, it wou...

NCUA REQUIRED INFORMATION FOR CREDIT UNION BOARD CHAIRMEN AND MANAGEMENT

Letter to Federal Credit Unions (20-FCU-03) Amended Field of Membership Application Requirements for Combined Statistical Area and Core-Based Statistical Area Dear Boards of Directors and Chief Executive Officers: On October 14, 2020, amendments to the NCUA’s chartering and field-of-membership rules ( 12 CFR Part 701 Appendix B ) will go into effect. These changes will allow a credit union applying for NCUA approval of a community charter, expansion, or conversion to designate a Combined Statistical Area (CSA) or an individual, contiguous portion of a CSA as a well-defined local community (WDLC) if the area has a population of 2.5 million or less. Beginning October 14, 2020, prospective and existing federal credit unions seeking a community charter may use a CSA or portions of a CSA (within certain limitations, as defined in the rule) as a basis for defining their proposed service area without documenting how a CSA’s residents interact or sha...

How Your Bank/Credit Union Can Fight ‘Soft Switching’ — and Even Steal a Few Accounts of Your Own

Your Members Aren't Leaving in a Huff, They're Just Fading Away. Here's How to Stop It. “Soft switching” is picking up as Americans’ financial activity continues to fragment among multiple players, according to new research from JD Power. This trend has implications both for banks and credit unions that want to retain and grow existing relationships, as well as those that would also like to expand by snapping up accounts from other institutions. Key risk:  Once someone establishes a relationship with another provider, their one-time primary financial institution risks slipping into second place — or even losing the relationship entirely. Need to Know: The average checking account customer now has three deposit accounts at different institutions, the study found. One out of five consumers moved money away from their primary financial institution in the past three months, according to the study, an increase over the 17% rate seen in the previous edition. Departures aren’t sud...