Skip to main content

BIN There, Done That: Air Force FCU Topples An Attack

In late April 2021, transactions totaling close to six figures from the same retailer hit the credit union in nearly one fell swoop. Transaction data from Air Force FCU’s core provider indicated all the charges were card-not-present purchases, which tipped Miller off to the fraud.

The cooperative had to act quickly.

Because the retailer, which Miller declines to name, is a large, legitimate business, the credit union couldn’t simply cut off those transactions. However, during its due diligence, Air Force FCU learned the attack came from only one of the several networks through which it processes transactions, and it could shut off transactions from specific card networks.

“We made the decision to stop all transactions from that network for two days,” Miller says. “It stopped the fraud in its tracks and gave us enough time to figure out our next move.”

The credit union’s chief technology officer along with several risk employees began to thoroughly review Air Force FCU’s daily credit card transaction reports. A pattern soon emerged. Miller says her exceptions report often state “card destroyed,” “card lost,” “card stolen,” or “wrong pin.” Not this time.

“We saw was a huge pattern of ‘card not found,’” Miller says. “Plus, these were all from the same vendor and the impacted card numbers ran in a sequential order. It just wasn’t normal.”

The fraudsters, however, had accurate card information so transactions were going through, putting the credit union on the hook for losses. And the hackers were sophisticated, Miller says. They used different names, different dollar amounts, and even different addresses — not always in the United States.

“People were really buying stuff,” Miller says. “It was going as far away as Colombia.”

The Response

Air Force FCU implemented immediate changes to its card numbering logic — no longer would the same several digits appear for each card. By altering the pattern, the credit union hoped to make hacking more complicated. Additionally, the credit union reissued every card that was affected by the attack, but it did not reissue cards en masse.

“It’s a long process to reissue like that,” Miller says. “And it wasn’t going to stop the bleeding.”

The fact the dollar amounts tended to be small posed a challenge to identifying fraudulent charges. And because it was a well-known retailer, members weren’t always aware they were victims. Air Force FCU posted a message on its home banking platform asking members to review their statements carefully for suspicious activity. It did not name the retailer because the attack ultimately wasn’t the retailer’s fault. In fact, the retailer was helpful.

“When we contacted them, they were eager to help us stop the fraud,” Miller says.

Internally, three employees in the risk department started reviewing daily core and card processor reports looking for context clues for potential fraud. Of primary focus are those “card not found” transactions, especially sequential card numbers used in close succession.

“The crook spends his whole day looking for ways in. We’re going to be behind the curve in trying to catch up, but we’ll do everything we can.” Cathy Miller, SVP & Chief Risk Officer, Air Force FCU

Looking forward, Air Force FCU hopes its risk review process will curb future fraudulent activity and is evolving its cybersecurity efforts, which include a new information security committee. Miller knows the battle is far from over, but that doesn’t mean it’s not worth the fight.

“The crook spends his whole day looking for ways in,” Miller says. “We’re going to be behind the curve in trying to catch up, but we’ll do everything we can.”

 Callahan & Associates, Inc.

Comments

Popular posts from this blog

New York Stock Exchange building venue for 24/7 tokenized stock and ETF exchange

The New York Stock Exchange (NYSE), via its owner   Intercontinental Exchange (ICE) , is building a new digital trading venue for 24/7 trading of tokenized stocks and ETFs, using blockchain and stablecoin-based funding for instant settlement, aiming to modernize markets by running parallel to the traditional exchange. This platform will support native digital securities and traditional shares as tokens, allowing for continuous liquidity and integrating digital assets into mainstream finance, with plans to launch later in 2026 after regulatory approval.   Key Features of the New NYSE Platform: 24/7 Trading:  Operates continuously, unlike the traditional exchange's weekday hours. Instant Settlement:  Transactions settle immediately, moving away from the current T+1 (trade date plus one day) model. Stablecoin-Based Funding :  Uses stablecoins (digital tokens pegged to fiat currency like the USD) for funding and collateral, streamlining processes outside banking hou...

Breaking: NCUA Moves to Remove a Major Barrier to Board Service

NCUA just proposed a rule that would allow federal credit unions to reimburse or directly pay reasonable dependent care costs for volunteer officials when those costs are incurred while attending board meetings or performing official duties. Childcare and eldercare costs are real barriers to serving on a board — especially for working professionals, single parents, and caregivers. At the same time, expectations for board engagement, training, and oversight continue to rise. A few important guardrails remain: ✔️ Applies only to federal credit unions ✔️ Covers dependent care only — not lost wages or compensation ✔️ Requires written board policy and reasonable controls ✔️ IRS tax treatment still applies (talk to your CPA) Bottom line: this won't fix board recruitment challenges by itself, but it removes a real friction point for people who want to serve and simply can't absorb the added costs. NCUA is also asking for comments — including whether training and conferences...

Sunday Reading - How pensions work

  The Pension Promise   How pensions work Colloquially speaking, pensions are retirement plans that result in employees receiving a fixed amount of money from their former employers during retirement, often for life (although the technical legal definition of pensions is significantly more nuanced ). Unlike “defined contribution plans” like 401(k) plans, “defined benefit plans” like pensions make it so the employer , rather than the employee, determines how much money is set aside for the plan and how it’s invested (often in stocks, bonds, and other assets). In retirement, monthly payouts include both the principal and investment earnings. Employers often use fact...

NCUA Issues 2026 Supervisory Priorities Letter to Credit Unions

Alexandria, VA (January 14, 2026)  ― The National Credit Union Administration (NCUA) today announced its 2026 Supervisory Priorities, which continue the agency’s policy of “No Regulation by Enforcement,” while prioritizing safety and soundness. This policy underscores NCUA’s commitment to providing clarity and transparency in its oversight. The letter outlines NCUA’s priorities for the year and provides information to help credit unions prepare for examinations. This year, the agency will continue to focus on risk-based supervision, tailoring the examination scope to the credit union’s unique risk profile. Key Highlights of the 2026 Supervisory Priorities: Risk-Focused Examinations:  Examiners will concentrate on areas posing the greatest risk to credit union members, the credit union system, and the Share Insurance Fund. Balance Sheet Management and Lending:  With loan performance at its weakest point in over a decade, examiners will review credit risk management practic...

Moving to a Credit Union Doesn’t Mean Giving Up Rewards Credit Cards

Moving to a Credit Union Doesn’t Mean Giving Up Rewards Credit Cards : "We’ve received a couple questions at NerdWallet about credit unions and rewards credit cards. Generally, the perception is that while credit unions are great for low interest rates and fees, the major banks have the profit margins to spend on a great rewards program. But now, " 'via Blog this'

What Could Tokenized Deposits Mean for CUs?

WASHINGTON—Noting that the FDIC has expressed support for tokenized deposits as insured bank liabilities, not experimental digital assets, a new analysis offers some insights into what that could mean for financial institutions, credit unions and the market in 2026 and beyond.  As PYMNTS Intelligence pointed out in its report, regulatory clarity reduces risk for banks moving from pilots to live deployments, and large banks and infrastructure providers are already testing real-world tokenized deposit use cases.  “At its simplest, tokenization converts an existing claim into a digital representation on a distributed ledger,” the report explained. “The underlying asset does not change, but the infrastructure that tracks ownership and settlement does. In banking, that distinction is critical. Tokenized deposits do not create new money. They represent traditional bank deposits, issued and redeemed by regulated institutions but designed to operate on modern, programma...

How Does Compensation Compare for Women Credit Union Executives?

BFB a NCOFCU Supporter! Guest post written by Chris Burns-Fazzi, Principal, Burns-Fazzi, Brock For many industries, gender equity has been a topic of discussion. Have you ever wondered how men and women compare as credit union executives and the compensation they receive? We did too. The NAFCU Annual Conference coming up at the end of July in Nashvillewill feature a Women’s Leadership Summit , with a number of timely topics, including an initial look at how men and women credit union executives compare in regards to compensation and their presence in top executive positions. A bit of background – for five years now, Burns-Fazzi, Brock (the NAFCU Services Preferred Partner for Executive Compensation and Benefits) has underwritten the annual NAFCU-BFB Survey of Federal Credit Union Executive Benefits & Compensation. Conducted by an independent firm, Clark and Chase Research, there is no cost to participate, and the results are shared with participants as well as each yea...

The St. Louis Fed said that research shows that historically checking and savings rates show almost no response to the increase in the federal funds rate and have been near zero since the 2007-09 financial crisis.

 ST. LOUIS–As it is becoming more costly for people to hold not only cash but also bank deposits, new liquidity pressures are being felt by both financial institutions and depositors, creating a “liquidity premium,” according to new research by the St. Louis Federal Reserve Bank. With the Federal Open Market Committee (FOMC) raising the federal funds rate at its past four meetings, the St. Louis Fed has released new research that investigates the links between monetary policy and its macroeconomic effects, including in the 2022 tightening cycle. “Imagine a simple world where you can choose between three assets: cash, deposits, or bonds. Cash is the most liquid asset but pays no interest,” the St. Louis Fed stated. “Deposits, such as checking, savings, or time deposits, are less liquid than cash, but they pay rates set by the bank. Bonds are the least liquid among these assets, and assume, for simplicity, that bonds pay the federal funds rate. Banks raise deposits and ...

Mobile Bill Pay Demand Is the Future

Imagine paying your house payment while riding in a double decker bus in London or making your Visa payment while waiting for a plane. According to the Javelin report, after a pause in 2010, mobile banking adoption surged by 63% in 2011, rising to 57 million from 35 million in the United States. That’s a meteoric increase of 22 million consumers in one year. Over the next five years, mobile banking is projected to increase at a steady compound annual growth rate of 10.3% as financial institutions roll out new offerings, the data showed.   **** READ MORE: Mobile Bill Pay Demand Is the Future :

Half of Small Biz Owners See a Risk of Failure by Fall if Conditions Don’t Improve

  BOSTON–A new survey of small business owners finds nearly half say their businesses are at risk of failing by the fall of this year unless economic conditions improve significantly. According to Alignable's Small Business Revenue Report  , which is based on a poll of 4,392 randomly selected small business owners conducted from June 10-July 13, 2022,  along with historic data from 680,000 surveyed since March 2020, key highlights include: 47% of small business owners (SMBs) say they're businesses are at risk of closing by Fall of '22, unless economic conditions improve significantly That's up 12 percentage points from last summer, when only 35% were concerned about economic issues forcing them to shut down, Alignable said. And SMBs in key industries face even bigger problems: 59% of retailers are at risk, along with 52% in construction, 51% in the automotive sector, and 50% of restaurant owners.  Suppo...