Skip to main content

Ransomware: 'It's A Growing Issue'

MADISON, Wis.—Ransomware attacks, already a quiet concern that has been growing among credit unions, are expected to dramatically increase this year—with one analyst saying there is “no silver bullet” to prevent the threat.
Ransomware is a type of malicious software designed to block access to a computer system or PC until a sum of money is paid. In the case of a financial institution, crooks first use the malware to encrypt the contents of the FI’s data and then extract a ransom in exchange for decrypting the information and allowing the victim to regain access.

It’s an issue, according to one regulator source who asked for anonymity that has been growing within credit unions, many of which have paid ransoms to regain access to their data and have chosen not to speaking publicly about the crime.
“This has become a huge problem,” said Ken Otsuka, senior consultant in CUNA Mutual Group’s risk management department, adding that CUNA Mutual Group’s cyber liability coverage data does not break down the type of cyber-attack that leads to a claim. “The FBI statistics are unnerving.”
According to the FBI, between April 2014 and June 2015 the agency received 992 ransomware complaints, with victims reporting losses of more than $18 million. Overall, reports indicate that losses from ransomware to date range from tens of millions to hundreds of millions of dollars.
Experts are predicting the threat will spread in 2016 due to inexpensive, do-it-yourself ransomware kits that are beginning to become available in underground markets.
“Analysts are concerned that cyber criminals are on the verge of widening the scope of their attacks,” reported ThirdCertainty’s Jaikumar Vijayan. “Researchers at security vendor Emsisoft analyzed a malware tool dubbed Ransom32 that many believe is a harbinger of things to come on the ransomware front.”
Portabile Platform
Ransom32 is the first ransomware tool written entirely in Javascript. That makes it easily portable to other platforms such as Linux and Mac OS X, Vijayan reported.
While reports indicate that ransomware costs can reach as high as $5,000 per user on an infected system, the bigger costs, sources say, come from staff downtime and from the credit union’s damaged reputation among its members.
According to a survey conducted by cloud IT services company Intermedia, many firms do not have a business continuity plan that would help them continue working while under a ransomware attack. Instead, they suffer costly downtime, with 72% not being able to access their files for two days, and 32% for five days or more.
Otsuka confirmed that a business continuity plan to address a ransomware attack is necessary today. He also outlined several steps credit unions should take to defend against ransomware, none more important that backing up data regularly.
“The big item is making sure the credit union has an effective data backup strategy in place so that if the credit union is hit with a ransomware attack and files are unreadable, it can go back to the most recent backup media tape and restore the data and not have to pay the ransom,” said Otsuka.
Otsuka said credit unions should periodically conduct “restore tests,” where they test to see if the data they would use to restore compromised files is usable.
“The time to find out your backup data is not usable is not during the middle of a ransomware attack,” he said.
Steps to Take
Noting there is no “silver bullet,” Otsuka outlined other important steps to guard against ransomware:
·         Securely configure systems and services.
·         Protect against unauthorized access.
·         Perform security monitoring, prevention and risk mitigation.
·         Update information security awareness and training programs to include cyber-attacks involving extortion.
·         Implement and regularly test controls around critical systems.
·         Review, update and test incident response and business continuity plans periodically.
·         Ensure antivirus programs are kept up-to-date.
·         Confirm operating systems and software are kept up-to-date with the latest patches.
·         Block access to personal email accounts.
·         Deploy spam and web filters.
·         Enable pop-up blockers.
As if often the case, in many successful cyber-attacks, staff are often the weak link, said Otsuka. He emphasized that credit unions should regularly test employees to make sure they understand how to prevent against phishing attacks and other email scams that can infect the system.
“I would test employees by sending them phishing-like emails to see how susceptible they are,” said Otsuka, explaining that cyber security companies can provide these “test” emails.
Otsuka said another key guiding principle is to network on risks, such as in industry information-sharing forums, and share information regarding threat intelligence.
“Credit unions with a CUNA Mutual Group cyber liability insurance policy may be eligible for a discounted membership fee for the Financial Services Information Sharing and Analysis Center (FS-ISAC),” said Otsuka.

To learn more, visit www.cunamutual.com/fs-isac

Comments

Popular posts from this blog

New York Stock Exchange building venue for 24/7 tokenized stock and ETF exchange

The New York Stock Exchange (NYSE), via its owner   Intercontinental Exchange (ICE) , is building a new digital trading venue for 24/7 trading of tokenized stocks and ETFs, using blockchain and stablecoin-based funding for instant settlement, aiming to modernize markets by running parallel to the traditional exchange. This platform will support native digital securities and traditional shares as tokens, allowing for continuous liquidity and integrating digital assets into mainstream finance, with plans to launch later in 2026 after regulatory approval.   Key Features of the New NYSE Platform: 24/7 Trading:  Operates continuously, unlike the traditional exchange's weekday hours. Instant Settlement:  Transactions settle immediately, moving away from the current T+1 (trade date plus one day) model. Stablecoin-Based Funding :  Uses stablecoins (digital tokens pegged to fiat currency like the USD) for funding and collateral, streamlining processes outside banking hou...

Breaking: NCUA Moves to Remove a Major Barrier to Board Service

NCUA just proposed a rule that would allow federal credit unions to reimburse or directly pay reasonable dependent care costs for volunteer officials when those costs are incurred while attending board meetings or performing official duties. Childcare and eldercare costs are real barriers to serving on a board — especially for working professionals, single parents, and caregivers. At the same time, expectations for board engagement, training, and oversight continue to rise. A few important guardrails remain: ✔️ Applies only to federal credit unions ✔️ Covers dependent care only — not lost wages or compensation ✔️ Requires written board policy and reasonable controls ✔️ IRS tax treatment still applies (talk to your CPA) Bottom line: this won't fix board recruitment challenges by itself, but it removes a real friction point for people who want to serve and simply can't absorb the added costs. NCUA is also asking for comments — including whether training and conferences...

Sunday Reading - How pensions work

  The Pension Promise   How pensions work Colloquially speaking, pensions are retirement plans that result in employees receiving a fixed amount of money from their former employers during retirement, often for life (although the technical legal definition of pensions is significantly more nuanced ). Unlike “defined contribution plans” like 401(k) plans, “defined benefit plans” like pensions make it so the employer , rather than the employee, determines how much money is set aside for the plan and how it’s invested (often in stocks, bonds, and other assets). In retirement, monthly payouts include both the principal and investment earnings. Employers often use fact...

Small credit union closures and mergers.

NCOFCU Podcast on the loss of small creditunions. Grant Sheehan CCUE | CEO-NCOFCU examines the rapid decline of small credit unions, why each closure matters to communities, and the threat this trend poses to the cooperative identity and tax protections of the movement. The episode explores practical solutions: larger credit unions acting as stewards, collaboration through shared resources and technology, and the advocacy work of the National Council of Firefighter Credit Unions to amplify every credit union's voice. Listen for a call to action on preserving community-focused financial cooperatives and strengthening the future of the credit union movement. Be sure to visit NCOFCU's "First Responders Credit Unions Academy" for your continued credit union education and certification in meeting N C U A’s requirements.  ================================================= Remember, you're not alone with  NCOFCU.org Join/Upgrade Check out some of NCOFCU's additional f...

NCUA Issues 2026 Supervisory Priorities Letter to Credit Unions

Alexandria, VA (January 14, 2026)  ― The National Credit Union Administration (NCUA) today announced its 2026 Supervisory Priorities, which continue the agency’s policy of “No Regulation by Enforcement,” while prioritizing safety and soundness. This policy underscores NCUA’s commitment to providing clarity and transparency in its oversight. The letter outlines NCUA’s priorities for the year and provides information to help credit unions prepare for examinations. This year, the agency will continue to focus on risk-based supervision, tailoring the examination scope to the credit union’s unique risk profile. Key Highlights of the 2026 Supervisory Priorities: Risk-Focused Examinations:  Examiners will concentrate on areas posing the greatest risk to credit union members, the credit union system, and the Share Insurance Fund. Balance Sheet Management and Lending:  With loan performance at its weakest point in over a decade, examiners will review credit risk management practic...

Moving to a Credit Union Doesn’t Mean Giving Up Rewards Credit Cards

Moving to a Credit Union Doesn’t Mean Giving Up Rewards Credit Cards : "We’ve received a couple questions at NerdWallet about credit unions and rewards credit cards. Generally, the perception is that while credit unions are great for low interest rates and fees, the major banks have the profit margins to spend on a great rewards program. But now, " 'via Blog this'

What Could Tokenized Deposits Mean for CUs?

WASHINGTON—Noting that the FDIC has expressed support for tokenized deposits as insured bank liabilities, not experimental digital assets, a new analysis offers some insights into what that could mean for financial institutions, credit unions and the market in 2026 and beyond.  As PYMNTS Intelligence pointed out in its report, regulatory clarity reduces risk for banks moving from pilots to live deployments, and large banks and infrastructure providers are already testing real-world tokenized deposit use cases.  “At its simplest, tokenization converts an existing claim into a digital representation on a distributed ledger,” the report explained. “The underlying asset does not change, but the infrastructure that tracks ownership and settlement does. In banking, that distinction is critical. Tokenized deposits do not create new money. They represent traditional bank deposits, issued and redeemed by regulated institutions but designed to operate on modern, programma...

How Does Compensation Compare for Women Credit Union Executives?

BFB a NCOFCU Supporter! Guest post written by Chris Burns-Fazzi, Principal, Burns-Fazzi, Brock For many industries, gender equity has been a topic of discussion. Have you ever wondered how men and women compare as credit union executives and the compensation they receive? We did too. The NAFCU Annual Conference coming up at the end of July in Nashvillewill feature a Women’s Leadership Summit , with a number of timely topics, including an initial look at how men and women credit union executives compare in regards to compensation and their presence in top executive positions. A bit of background – for five years now, Burns-Fazzi, Brock (the NAFCU Services Preferred Partner for Executive Compensation and Benefits) has underwritten the annual NAFCU-BFB Survey of Federal Credit Union Executive Benefits & Compensation. Conducted by an independent firm, Clark and Chase Research, there is no cost to participate, and the results are shared with participants as well as each yea...

The St. Louis Fed said that research shows that historically checking and savings rates show almost no response to the increase in the federal funds rate and have been near zero since the 2007-09 financial crisis.

 ST. LOUIS–As it is becoming more costly for people to hold not only cash but also bank deposits, new liquidity pressures are being felt by both financial institutions and depositors, creating a “liquidity premium,” according to new research by the St. Louis Federal Reserve Bank. With the Federal Open Market Committee (FOMC) raising the federal funds rate at its past four meetings, the St. Louis Fed has released new research that investigates the links between monetary policy and its macroeconomic effects, including in the 2022 tightening cycle. “Imagine a simple world where you can choose between three assets: cash, deposits, or bonds. Cash is the most liquid asset but pays no interest,” the St. Louis Fed stated. “Deposits, such as checking, savings, or time deposits, are less liquid than cash, but they pay rates set by the bank. Bonds are the least liquid among these assets, and assume, for simplicity, that bonds pay the federal funds rate. Banks raise deposits and ...

Mobile Bill Pay Demand Is the Future

Imagine paying your house payment while riding in a double decker bus in London or making your Visa payment while waiting for a plane. According to the Javelin report, after a pause in 2010, mobile banking adoption surged by 63% in 2011, rising to 57 million from 35 million in the United States. That’s a meteoric increase of 22 million consumers in one year. Over the next five years, mobile banking is projected to increase at a steady compound annual growth rate of 10.3% as financial institutions roll out new offerings, the data showed.   **** READ MORE: Mobile Bill Pay Demand Is the Future :