Skip to main content

BIN There, Done That: Air Force FCU Topples An Attack

In late April 2021, transactions totaling close to six figures from the same retailer hit the credit union in nearly one fell swoop. Transaction data from Air Force FCU’s core provider indicated all the charges were card-not-present purchases, which tipped Miller off to the fraud.

The cooperative had to act quickly.

Because the retailer, which Miller declines to name, is a large, legitimate business, the credit union couldn’t simply cut off those transactions. However, during its due diligence, Air Force FCU learned the attack came from only one of the several networks through which it processes transactions, and it could shut off transactions from specific card networks.

“We made the decision to stop all transactions from that network for two days,” Miller says. “It stopped the fraud in its tracks and gave us enough time to figure out our next move.”

The credit union’s chief technology officer along with several risk employees began to thoroughly review Air Force FCU’s daily credit card transaction reports. A pattern soon emerged. Miller says her exceptions report often state “card destroyed,” “card lost,” “card stolen,” or “wrong pin.” Not this time.

“We saw was a huge pattern of ‘card not found,’” Miller says. “Plus, these were all from the same vendor and the impacted card numbers ran in a sequential order. It just wasn’t normal.”

The fraudsters, however, had accurate card information so transactions were going through, putting the credit union on the hook for losses. And the hackers were sophisticated, Miller says. They used different names, different dollar amounts, and even different addresses — not always in the United States.

“People were really buying stuff,” Miller says. “It was going as far away as Colombia.”

The Response

Air Force FCU implemented immediate changes to its card numbering logic — no longer would the same several digits appear for each card. By altering the pattern, the credit union hoped to make hacking more complicated. Additionally, the credit union reissued every card that was affected by the attack, but it did not reissue cards en masse.

“It’s a long process to reissue like that,” Miller says. “And it wasn’t going to stop the bleeding.”

The fact the dollar amounts tended to be small posed a challenge to identifying fraudulent charges. And because it was a well-known retailer, members weren’t always aware they were victims. Air Force FCU posted a message on its home banking platform asking members to review their statements carefully for suspicious activity. It did not name the retailer because the attack ultimately wasn’t the retailer’s fault. In fact, the retailer was helpful.

“When we contacted them, they were eager to help us stop the fraud,” Miller says.

Internally, three employees in the risk department started reviewing daily core and card processor reports looking for context clues for potential fraud. Of primary focus are those “card not found” transactions, especially sequential card numbers used in close succession.

“The crook spends his whole day looking for ways in. We’re going to be behind the curve in trying to catch up, but we’ll do everything we can.” Cathy Miller, SVP & Chief Risk Officer, Air Force FCU

Looking forward, Air Force FCU hopes its risk review process will curb future fraudulent activity and is evolving its cybersecurity efforts, which include a new information security committee. Miller knows the battle is far from over, but that doesn’t mean it’s not worth the fight.

“The crook spends his whole day looking for ways in,” Miller says. “We’re going to be behind the curve in trying to catch up, but we’ll do everything we can.”

 Callahan & Associates, Inc.

Comments

Popular posts from this blog

NCUA Board Approves Final Rule on Dependent Care and Board Member Reimbursement

Alexandria, VA (June 8, 2026) ― The National Credit Union Administration today issued a final rule for Dependent Care and Board Member Reimbursement. The NCUA Board amended its regulations concerning the reimbursement of reasonable expenses for federal credit union officials to remove potential barriers to volunteer service. This final rule provides flexibility for a federal credit union’s board to adopt more family-friendly policies tailored to its size, region, and operations. Previously, dependent care costs had not been considered reasonable expenses under NCUA regulation 12 C.F.R. 701.33.  The final rule applies to all federal credit unions, including corporate federal credit unions. It will not apply to federally insured, state-chartered credit unions, which remain subject to state law. The final rule is effective 30 days from the date of publication in the Federal Register and takes into consideration public comments received from the proposed rule that was issued on Januar...

Update from TruStage - Forecast for CU, Economic Performance for Remainder of 2026, 2027

MADISON, Wis. — Credit unions are expected to post stronger loan, deposit , and asset growth in 2026 despite a slowing economy, persistent inflation, geopolitical uncertainty, and continued pressure on consumers, according to TruStage’s latest  Credit Union Trends Report . The report, prepared by TruStage Chief Economist Steve Rick and based on December 2025 data, forecasts credit union loan growth will accelerate to 5.5% in 2026 from 4.6% in 2025, while savings growth is projected to increase to 6.5% from 5.5%. Asset growth is expected to improve to 6.2% in 2026 from 5.4% in 2025. Credit union membership growth is forecast to reach 1.8% in 2026 and 2.0% in 2027. The CU Daily has separate reporting on credit union performance by category here .  According to TruStage, a changing global economic environment has altered its outlook for both the U.S. economy and the credit union system. The report noted disruptions stemming from the closing of the Strait of Hormuz have created su...

The Widely Cited Mortgage Lending Benchmark 45% DTI May No Longer Reflect How Lenders Evaluate Borrowers, Says Fed Bank

In an analysis of more than 30 million home-purchase mortgage applications filed between 2018 and 2024, researchers found that the long-discussed 43% debt-to-income ratio threshold has little apparent impact on mortgage approval decisions. Instead, denial rates begin to rise sharply once applicants exceed a debt-to-income ratio of 50%. The findings were published as part of a four-part series examining barriers facing prospective homebuyers. ‘Practical Lesson is Clear’ “For borrowers, the practical lesson is clear: A debt-to-income ratio of 45% is treated by lenders much like a ratio of 35%,” the researchers wrote. “But crossing 50% changes the game entirely.” The 43% debt-to-income ratio gained prominence under the 2010 Dodd-Frank Act, which established it as a key threshold for so-called qualified mortgages. Loans meeting that standard provided lenders with legal protections against ability-to-repay lawsuits. However, in 2021, the Consumer Financial Protection Bureau replaced the rat...

Reuters: Trump Regulators Launch Biggest Bank Oversight Overhaul Since 2008

Is NCUA next? WASHINGTON—Federal banking regulators under President Trump are undertaking what Reuters described as the most significant overhaul of bank supervision since the 2008 financial crisis, shifting examiner focus away from process and compliance issues and toward what agencies consider “material” financial risks. According to Reuters, the Federal Reserve, the Office of the Comptroller of the Currency and the Federal Deposit Insurance Corp. have directed examiners to concentrate on risks that pose direct threats to a bank’s safety and soundness, rather than on paperwork deficiencies, governance concerns or procedural issues that do not immediately affect financial stability. Reuters reported that regulators have also moved away from evaluating banks based on “reputational risk,” a supervisory concept long criticized by banks as overly subjective. The change follows complaints from President Trump and others that financial institutions have used reputational-risk considerations...

Trump Accounts Program For Children Moves Forward With New Mobile App Launch

  WASHINGTON—The Treasury Department on Thursday announced the launch of the new Trump Accounts mobile app, marking the next phase of the Administration’s rollout of its new federally backed investment savings program for children ahead of the program’s official July 4 launch date. Donald Trump The app, now available through major mobile app stores, will serve as the primary platform for families to manage and activate Trump Accounts. Treasury Secretary Scott Bessent said the app is intended to give parents and guardians a “simple, secure way” to participate in the program, which was created under the 2025 Republican tax-and-spending package. Families that already submitted IRS Form 4547 to enroll children in the program will begin receiving phased activation emails between now and July 4, according to Treasury. Under the program, eligible children born between Jan. 1, 2025, and Dec. 31, 2028, can receive a one-time $1,000 federal seed contribution into a tax-deferred investment ac...

Mortgage Rates Decline to Their Lowest Levels Since April

WASHINGTON–Mortgage rates fell last week to their lowest level since early April. According to Freddie Mac, the standard 30-year fixed-rate mortgage averaged 6.87% in the week ending June 20, which was down from the prior week’s 6.95% average and marks the third consecutive weekly decline. Rates are down from a 2024 peak of 7.22%. “Mortgage rates fell for the third straight week following signs of cooling inflation and market expectations of a future Federal Reserve rate cut,” Sam Khater, Freddie Mac’s chief economist, said in a statement. “These lower mortgage rates coupled with the gradually improving housing supply bodes well for the housing market.” Most economists and forecasters expect rates ...

Cutting Through The Stablecoin Noise—What Credit Unions Actually Need To Know Now

By Ray Birch DOVER, Del.—By any measure, stablecoins have quickly become one of the most talked-about—and least understood—topics in credit union boardrooms. The pressure to “do something” is building, fueled by headlines, fintech momentum and a growing fear of being left behind. But according to InvestiFi CEO Kian Sarreshteh, that urgency may be misplaced. “There’s a lot of FOMO right now,” Sarreshteh said. “If I don’t adopt a stablecoin solution this year, I’m going to be left behind. I would argue pretty strongly that’s very far from the truth.” Instead of rushing to sign up for a Stablecoin pilot, Sarreshteh said credit unions should begin with a more fundamental question: what problem are you actually trying to solve? While stablecoins are often discussed as a potential challenger to traditional payment rails dominated by Visa and Mastercard, he believes that kind of mass-market disruption remains years away—especially in the U.S., where consumers already have fast, convenient opt...

Sunday Reading - Changing the Map

  Changing the Map     Redistricting, explained Congressional redistricting is the process by which states redraw electoral district boundaries   that determine representation in the US House of Representatives. The Constitution, federal law, and court rulings require districts to have roughly equal populations, avoid discrimination against racial or language minorities, and, in most states, be geographically contiguous. For most of American history, redistricting has followed a predictable cycle, occurring every 10 years after the census.   Gerrymandering is the deliberate manipulation of district boundaries to advantage one political party. Common tactics  by both major American political parties include packing opposition voters i...

The FedNow Service will launch in 2023 "Are you ready?"

The FedNow Service is a new instant payment service that the Federal Reserve Banks are developing to enable financial institutions of every size, and in every community across the U.S., to provide safe and efficient instant payment services in real-time, around the clock, every day of the year. Through financial institutions participating in the FedNow Service, businesses and individuals will be able to send and receive instant payments conveniently, and recipients will have full access to funds immediately, giving them greater flexibility to manage their money and make time-sensitive payments. Consistent with the Federal Reserve’s historical role of providing payment services alongside private-sector providers, the FedNow Service will provide choice in the market for clearing and settling instant payments as well as promote resiliency through redundancy. Financial institutions and their service providers will be able to use the service as a springboard to provide innovative instant p...

Hauptman Tells Congress CU Health is Strong; Responds to Questions from Committee

WASHINGTON — National Credit Union Administration Chairman Kyle Hauptman told members of the House Financial Services Committee on Thursday that the nation’s credit union system remains financially strong, while warning that rising delinquencies and consumer financial stress continue to warrant close monitoring. Hauptman also responded to a handful of questions from members of Congress, as well. Hauptman appeared as part of the regular hearings on Oversight of Prudential Regulators. Also appearing as witnesses were Michelle Bowman, vice chair for supervision with the Federal Reserve; Travis Hill, FDIC chairman, and Jonathan Gould, the acting Comptroller of the Currency. Kyle Hauptman In his prepared statement, Hauptman said federally insured credit unions remain well-capitalized and continue to meet members’ borrowing needs despite economic headwinds. He said the NCUA is focused on maintaining safety and soundness, protecting the National Credit Union Share Insurance Fund and creating...