Skip to main content

BIN There, Done That: Air Force FCU Topples An Attack

In late April 2021, transactions totaling close to six figures from the same retailer hit the credit union in nearly one fell swoop. Transaction data from Air Force FCU’s core provider indicated all the charges were card-not-present purchases, which tipped Miller off to the fraud.

The cooperative had to act quickly.

Because the retailer, which Miller declines to name, is a large, legitimate business, the credit union couldn’t simply cut off those transactions. However, during its due diligence, Air Force FCU learned the attack came from only one of the several networks through which it processes transactions, and it could shut off transactions from specific card networks.

“We made the decision to stop all transactions from that network for two days,” Miller says. “It stopped the fraud in its tracks and gave us enough time to figure out our next move.”

The credit union’s chief technology officer along with several risk employees began to thoroughly review Air Force FCU’s daily credit card transaction reports. A pattern soon emerged. Miller says her exceptions report often state “card destroyed,” “card lost,” “card stolen,” or “wrong pin.” Not this time.

“We saw was a huge pattern of ‘card not found,’” Miller says. “Plus, these were all from the same vendor and the impacted card numbers ran in a sequential order. It just wasn’t normal.”

The fraudsters, however, had accurate card information so transactions were going through, putting the credit union on the hook for losses. And the hackers were sophisticated, Miller says. They used different names, different dollar amounts, and even different addresses — not always in the United States.

“People were really buying stuff,” Miller says. “It was going as far away as Colombia.”

The Response

Air Force FCU implemented immediate changes to its card numbering logic — no longer would the same several digits appear for each card. By altering the pattern, the credit union hoped to make hacking more complicated. Additionally, the credit union reissued every card that was affected by the attack, but it did not reissue cards en masse.

“It’s a long process to reissue like that,” Miller says. “And it wasn’t going to stop the bleeding.”

The fact the dollar amounts tended to be small posed a challenge to identifying fraudulent charges. And because it was a well-known retailer, members weren’t always aware they were victims. Air Force FCU posted a message on its home banking platform asking members to review their statements carefully for suspicious activity. It did not name the retailer because the attack ultimately wasn’t the retailer’s fault. In fact, the retailer was helpful.

“When we contacted them, they were eager to help us stop the fraud,” Miller says.

Internally, three employees in the risk department started reviewing daily core and card processor reports looking for context clues for potential fraud. Of primary focus are those “card not found” transactions, especially sequential card numbers used in close succession.

“The crook spends his whole day looking for ways in. We’re going to be behind the curve in trying to catch up, but we’ll do everything we can.” Cathy Miller, SVP & Chief Risk Officer, Air Force FCU

Looking forward, Air Force FCU hopes its risk review process will curb future fraudulent activity and is evolving its cybersecurity efforts, which include a new information security committee. Miller knows the battle is far from over, but that doesn’t mean it’s not worth the fight.

“The crook spends his whole day looking for ways in,” Miller says. “We’re going to be behind the curve in trying to catch up, but we’ll do everything we can.”

 Callahan & Associates, Inc.

Comments

Popular posts from this blog

Sunday Reading - What's the point of a consumer electronics show?

  What's the point of a consumer electronics show? Consumer electronics shows are large convention-type events where companies debut new technologies and products. The largest and most notable shows are CES in Las Vegas, a trade show every January, and IFA Berlin, which takes place annually in September. The events have historically introduced novel, cutting-edge products that later became household standards, like HDTVs, VCRs, DVDs, and gaming consoles ( see list ).   Over time, these shows evolved from product showcases ( see last year's coolest gadgets ) into complex industry ecosystems, serving as a meeting ground for startups, multinational technology companies, investors, and the media. Hardware launches, keynote speeches, and...

A Perfect Example - What Makes Credit Unions Different from Banks!

When the government shutdown hit in October and paychecks stopped, thousands of federal employees were left wondering how to make ends meet. Credit unions across the country stepped up—but Keesler Federal Credit Union went above and beyond. No loans, no hassle—just your paycheck Instead of making members apply for emergency loans, Keesler Federal launched its Paycheck Relief Program. Revolutionary in its simplicity, it worked like this: if you were a federal employee with direct deposit at Keesler Federal, your paycheck kept coming—interest-free, fee-free, and stress-free. Each qualified member could receive up to $6,000 per pay period for as long as 90 days. No hoops, no headaches. From October 1 until the shutdown ended, Keesler Federal advanced more than 5,000 paychecks totaling $6.5 million to 1,710 members. For non-members, they even offered zero-interest loans up to $6,500 with a year to pay it back. This proactive approach meant that before the first missed paycheck, Keesler Fed...

Eight Credit Unions Pay $42 Million in Special Dividends to 1.1 Million Members

  By  Jim DuPlessis   | January 05, 2026 at 04:00 PM So far this season, CU Times has tallied 19 credit unions, which have announced $160.3 million in special dividends for members.       Eight more credit unions have reported special dividends, paying their 1.1 million members $42.1 million in December and January. The bulk of the dividends came from Police and Fire Federal Credit Union of Philadelphia and Eastman Credit Union of Kingsport, Tenn., which each announced $16 million in rewards approved by their boards. The late January payout from Eastman ($9.7 billion, 356,492 members) will bring its total special dividends to $225 million since 1998. A news release from the credit union said “the Extraordinary Dividend is never guaranteed, but the strong financial performance of ECU in 2025 enabled the Board of Directors to approve this year’s $16 million payout.” Eastman’s $16 million payout represents about $47 per member and 19 basis points of its averag...

Auto Link, Home Link, and CalcuLink Unite Under New Parent Brand: Centergy Solutions

Auto Link, Home Link, and CalcuLink Unite Under New Parent Brand: Centergy Solutions Auto Link announced a major rebrand that unifies its three established product lines- Auto Link, Home Link, and CalcuLink- under one cohesive parent brand. The transition marks a strategic evolution designed to simplify the company’s ecosystem, strengthen product synergy, and enhance the overall experience for credit unions and the members they serve. The new Centergy Solutions brand reflects the company’s mission to deliver a more connected and integrated suite of digital tools across auto and home lending, auto and home buying, and financial decision-making. From an operational perspective, the unified brand also allows Centergy Solutions to accelerate innovation and improve platform alignment. Under the new parent brand: • Auto Link continues to support financial institutions with industry-leading digital auto lending tools that boost member engagement and loan volume. • Home Link provides consume...

Temporary Corporate Credit Union Share Guarantee Expires December 31, 2012

NCUA LETTER TO CREDIT UNIONS NATIONAL CREDIT UNION ADMINISTRATION 1775 Duke Street, Alexandria, VA 22314 DATE: March 2012 LETTER No.: 12-CU-03 TO: Federally Insured Credit Unions SUBJ: Temporary Corporate Credit Union Share Guarantee Expires December 31, 2012 Page Content ​ Dear Board of Directors and Chief Executive Officers: We are entering the final phase in the successful stabilization of the corporate credit union system. By the end of this year, all products and services offered by conserved corporate credit unions will be seamlessly transitioned to other providers – with no interruption of service to members. In the meantime, all ongoing corporate credit unions are meeting NCUA’s higher regulatory standards for capital, investments, and governance. ***READ COMPLETE LETTER; Temporary Corporate Credit Union Share Guarantee Expires December 3...

Become a Royal Credit Union

Welcome Royal Member Services Royal Member Services About Royal   We stand behind the most dependable automotive service plans in the business. We offer a range of automotive service plans for new and used vehicles that provide exceptional protection against repair costs while increasing dealer value on each and every sale. Our plans are backed by more than 50 years of dependability and customer satisfaction. We offer a world-class service organization, marketing, training, and a complete line of services. We have plans to fit most every vehicle and consumer budget. Call today and put Roya...

Rethinking Credit Union’s Social Media Strategy During Stressful Situations

By: Daniel Martinez, Social Media Marketing Specialist, PSCU So much has changed in the last few weeks as the COVID-19 crisis continues to unfold around the world. Here in the US, many organizations have been forced to quickly adapt to “social distancing,” teleworking, and stay-at-home orders within just a matter of days. Some have even ceased their operations entirely. As the focus on COVID-19 has dominated nearly all news sources, social media has been no exception. In fact, many organizations have been consistently using their social media accounts to share updates and important information about the coronavirus with their followers. For organizations across the country, this has been a significant shift away from their 2020 social media strategies or general marketing efforts. For credit unions, it’s an opportunity to stand out as a trusted and valued resource for not only their members but also for the communities they serve. To achieve this, credit unions will need to ...

No Fooling: Change from CAMEL to CAMELS Goes into Effect April 1

 WASHINGTON—Changes to NCUA’s rating system—to CAMELS from CAMEL—start April 1. Credit unions with examinations beginning on or after April 1 will fall under the new system. The CAMELS system, which stands for Capital adequacy, Asset quality, Management, Earnings, Liquidity, and now, Sensitivity to market risk, was approved by the NCUA board in 2021. CUNA reminded that under the CAMELS rating system: The “S” component addresses sensitivity to market risk and interest rate risk (IRR) governance. It documents a credit union’s market sensitivity level and how the credit union measures, monitors, and manages market sensitivity.  The “L” component evaluation has been modified to only consider available sources of funds and liquidity risk...

What You Can Do About Ransomware Threat

By Ray Birch RANCHO CUCAMONGA, Calif.—In the wake of a ransomware attack that shut down 60 credit unions, cyber security experts are warning many CUs are just one compromised key supplier away from being shut down, too. It’s a growing threat they say can have numerous  downstream effects on many organizations. No institution is immune, and the best line of defense remains educating employees on how to avoid making mistakes that place a credit union, CUSO or vendor right into the hands of criminals. “Co-op Solutions views ransomware attacks as an industry-wide threat that will continue for the foreseeable future with two main threat areas of concern,” said Christopher Williams, deputy chief information security officer at Co-op. The two ar...

PSCU: Inflation Helps Boost Member Spending in June

  The gains in the amount spent far outpace gains in the number of transactions. By Jim DuPlessis | July 2022 Source: Shutterstock. PSCU reported Tuesday that the value of purchases it handles for affiliated credit unions rose much faster than the number of transactions in June, which it said indicated inflation was a growing factor in purchasing growth. The St. Petersburg, Fla., payments CUSO found members whose credit unions use PSCU services spent 16% more by credit cards in value and 12% more in the number of transactions in June than they did in June 2021. By debit, they spent 7% more by value and 3% more by number. “While overall consumer spending remained strong throughout June, current inflationary pressures are keeping growth in purchases outpacing growth in transactions,” Brian Scott, PSCU’s chief growth officer, said. The U.S. Bureau of Labor Statistics reported July 13 that inflation rose a seasonally adjusted 1.3% from May...