Skip to main content

'Anatomy' Of A Ransomware Attack

By Ray Birch

BALTIMORE—Credit unions should brace for almost a month of major problems if they’re victimized by a ransomware attack, according to one cybersecurity expert, whose insights into the “anatomy” of a ransomware attack are coming at the same time nearly 60 CUs are currently trying to restore their own operations.

As those credit unions have come to learn, it takes on average 22 days to get through a ransomware attack and get to the other side, that same expert stated.

That information and additional insights were shared during a webinar hosted by cybersecurity firm Think/Stack, which that was held to provide CUs with insights and answers regarding ransomware in light of the recent attack that that continues to affect those five-dozen CUs hit by an attack on a common vendor.

Feature Ransomware Webinar 1

“We're all being targeted, and this (recent attack) could have happened to anybody,” said Cal Bowman, Think/Stack VP of client innovation and strategy, referring to an attack on the CUSO Ongoing Operations that in turn affected the data processor Fedcomp. “So, it's really important we all recognize that every one of you here has vendors, has partners that are vulnerable. Therefore, the question is, are you ready to respond to any type of large-scale event that really can cripple your organization?”

What’s Been Learned

bowman

Bowman said a goal of the webinar, which was attended by more than 300 credit unions, was to walk through what happens during a ransomware attack and share what his company has learned supporting CUs that have been victimized by such attacks.

Think/Stack VP of Security and Risk Jennifer Anthony said when a ransomware attack occurs in an organization it frequently creates the “fog of war.”

“What you will see in a generalized ransomware attack is the tactical and technical pieces that begin to happen over the first couple days,” Anthony explained.

But at the same time a credit union is seeking to find a tactical path through that fog, the emotional side of the battle must be given attention, as employees struggle to get the CU operating again, Anthony said.

“There is confusion and concern,” she said. “Maybe someone can't get on to a system they previously could access. Maybe there's a service that's not working and folks are starting to feel confused about what's going on. All this is happening as your technical teams in the background are beginning to quickly investigate the source of the problem.”

Anthony emphasized a credit union involved in a ransomware attack should be prepared to spend at least three weeks dealing with it.  

The Internal Threat

As CUToday.info has reported and as credit unions are frequently warned, ransomware attacks often occur due to an employee opening the door by falling for a phishing scam or downloading a file they believe to be safe.

“This is a function of human performance,” she noted. “We all begin to look for who's at fault, who did something they were not supposed to do that caused this. What we tell organizations is that when you get caught in that space, you should not spend a lot of time trying to figure out who to point the finger at, (but instead spend) time trying to figure out how to get out of the situation.”

Not surprisingly, Anthony described the working environment following an attack as “chaotic.”

‘Everyone’s Scared’

“Everyone's scared. We're not sure what's going on and maybe we have members who are really angry. Maybe we have board members that are really angry, or leaders that are really angry,” she said. “The goal at this point is to figure out how to get past it. We'll figure out who's to blame or what's to blame, or how we can prevent it in the future at a later point.”

It's an issue credit unions should take seriously, according to Anthony, who said there is a growing ransomware threat to the not-for-profit co-ops.

“In the last seven months we worked with six credit unions who individually found themselves in this space,” she said. “This is something that's happening on a regular basis, across all industries.”

Anthony reminded that as the credit union moves through a ransomware incident many employees will be feelin remorse and concern over fellow workers in IT who are working feverishly to restore operations.

“They feel like they are at fault for what is going on, and that is a very difficult place to be,” she said. “The technical teams are trying to figure out how to remediate the situation. I've been in organizations where technical teams are working nonstop, around the clock, for days and days. The credit union then is trying to figure out how do we feed people? How are we going to send people home to sleep so they can come back and be effective—because you are in this fight for a long time and there is a lot of pressure on everyone.”

Like Being in a Battle

Anthony likened the experience to those who fight in a war.

“I spent 20 years in the in the United States military, and this is a roller coaster akin to what a service member might experience in their daily lives—and this can be traumatic,” she said.

anthony

She urged credit unions to consider where they are vulnerable.  

“We know 93% of ransomware attacks are in Windows-based environment,” she said. “If we listed them in order of frequency of occurrence, how they occur, here's what they would be: Number one is e-mail phishing campaigns. Number two would be (remote desktop protocol or RDP) vulnerabilities. And number three would be software vulnerabilities.”

The Long-Term Affects

While those 22 days are the typical time from attack to restoration of service, Anthony said the repercussions are felt for many months afterward.

“With the recovery efforts and return to operation, the average time for an organization to move through that is about nine months,” she said. “The attack is not the only thing organizations have to grapple with; there are follow-on impacts that are significant. If you're an organization that has about 500 employees, your average recovery cost is going to be about $3.1 million. If an attacker is successful in extracting information from your environment, you'll have to deal with the impacts of that.”

Steps to Take

What steps should credit unions take today to prevent an attack? CUToday.info will share those in a follow-up report.

Comments

Popular posts from this blog

Honoring Our Member Credit Unions Ranked Among the Top 100 in 2025

Celebrating Excellence: Honoring Our Member Credit Unions Ranked Among the Top 100 in 2025   Best-performing US credit unions of 2025 At NCOFCU, we take immense pride in the strength, resilience, and impact of our member credit unions. Today, we are thrilled to recognize and celebrate several of our members who have earned a place among the Top 100 Best Performing Credit Unions of 2025 —a testament to their unwavering commitment to service, financial stewardship, and community leadership. This achievement is not just about rankings—it reflects the daily dedication to members, the trust built within communities, and the innovation that continues to drive our movement forward. 🌟 Our Honored Members We proudly congratulate the following institutions for their outstanding performance: #7 – Long Beach Firemen's Credit Union A remarkable top-10 finish that highlights exceptional operational excellence and member value. Long Beach Firemen’s CU continues to set a high bar for perform...

The United States at 250: How the Country Has Changed in the Past 50 Years

  In July, the United States will celebrate its 250th anniversary. The country’s last major milestone was 50 years ago, at its bicentennial on July 4, 1976. U.S. society has changed profoundly since then. Over the past five decades, the U.S. population has  aged significantly,  with the percentage of people 65 and older nearly doubling. The country has also become  more racially and ethnically diverse,  as growing shares of people identify as Asian or Hispanic. And following more than 70 million immigrant arrivals, the percentage of  foreign-born people  in the population has more than tripled.  Americans are also  less likely to be married  than ever before. Women – who now have far more options outside of the home than they did in 1976 – have contributed to a  boom in higher education  and helped  expand the workforce.  And even though many Americans are financially better off than they were 50 years ago,  econ...

Fire Police City County FCU rebrands to reflect company growth

FORT WAYNE, Ind. (WANE) – A federal credit union with a long history in the Fort Wayne area is changing its name to something that the company said Tuesday reflects its ability to serve a larger sector. Fire Police City County Federal Credit Union, founded in 1933, will go by Summit Choice Credit Union starting in April. Members and locals will start to notice new signage and aesthetic changes at each branch throughout the month. The rebranding does not affect the credit union’s structure, ownership, or member accounts, according to the news release. Summit Choice Credit Union remains a member-owned financial cooperative, governed by the same principles and operated by the same team.  Its website  reminds members that new cards are being issued due to the rebranding. The credit union was originally formed for the families of local firefighters. Today, it serves employees of more than 350 local businesses around greater Fort Wayne. “Adopting the name Summit Choice Credi...

When Cooperation Turns To Competition: A Turning Point For The Firefighter Credit Union Movement

  By Grant Sheehan For decades, firefighter credit unions have stood as a model of what cooperative finance is meant to be—institutions built not to compete ruthlessly, but to serve a shared mission: supporting the financial well-being of those who risk their lives in service to others. That’s what makes the recent actions of Firefighter First Credit Union so concerning. Firefighter First FCU was not just another participant; it was a founding member of the National Council of Firefighter Credit Unions (NCOFCU). It helped shape the very principles of collaboration, mutual respect, and non-encroachment that have long defined our community. Those principles weren’t accidental; they were intentional safeguards to ensure that firefighter-focused credit unions could grow together, not at each other’s expense. But something has changed. Firefighter First FCU’s decision to pursue a nationwide charter marks a clear shift in direction—from cooperation to direct competition. This isn’t simpl...

Agencies Issue Exemption Order To Customer Identification Program (CIP) Requirements

WASHINGTON--The Federal Deposit Insurance Corporation, the Office of Comptroller of the Currency, and NCUA, with the concurrence of the Financial Crimes Enforcement Network, issued an order Friday granting an exemption from a requirement of the Customer Identification Program (CIP) Rule implementing Section 326 of the USA PATRIOT Act. The CIP Rule requires a bank or credit union to obtain taxpayer identification number (TIN) information from its customer before opening an account, and the exemption permits a bank or credit union to use an alternative collection method to obtain TIN information from a third-party rather than from the customer, the agencies stated in a joint release. The order applies to accounts at all entities supervised by the agencies. "Since the CIP Rule was issued initially in 2003, there has been a significant evolution in the ways consumers access financial services, along with a rise in reported customer reluctance to provide their full TIN due, in part, to...

What Gen Z Is Really Looking For In A Credit Union

  Gen Z’s faith in traditional institutions gives credit unions a rich opportunity to serve as a key source of financial guidance. Sponsored Content By Adrenaline, Inc. Credit unions can strengthen loyalty with the influential Generation Z by connecting their brand’s purpose, financial guidance, and in-branch experience. Widely described as digital natives, Gen Z meets many of their everyday banking needs with mobile apps and digital tools across multiple providers. While younger consumers certainly expect seamless digital functionality from their primary financial provider, what they value even more is meaningful advice and trusting relationships. Because beneath Gen Z’s technological savvy is a measurable confidence gap —  one that impacts every aspect of their financial lives. According to  Adrenaline’s 2026 Gen Z research  conducted with Alexander Babbage, 36% of Gen Z say they find financial matters confusing, and one in three report feeling overwhelmed by money...

Employers should take note, as company culture starts with professional development.

Employees and employers alike may have thought they understood company culture, and likely did until recently. Coming to work, knowing company values, interacting with others are all no brainers when it comes to the driving forces that make up company culture. Buy a seismic shift is occurring on two fronts. One, various generations are working together in multiple industries and two; the pandemic has changed attitudes about where work can occur and how that may or may not affect culture. The Linkedin Global Trends 2022 report says more freedom to work where and when employees want, as well as attention to wellbeing, are important demands employers need to consider. Consider the numbers: when picking a new job, 63% of professionals put work-life balance as the top priority. Sixty percent are interested in compensation and benefits and 40% say the colleagues and culture they will be working with are their top priorities. Employers should take note as company culture starts with profess...

Fed Gets Green Light for Interest Rate Cuts as Unemployment Rate Jumps to 4-Year High

The Federal Reserve is now seen as likely to   cut interest rates   multiple times before the end of the year, following another weak jobs report that showed unemployment jumping to a four-year high. The U.S. economy added just 22,000 jobs in August, less than economists had expected, the  Bureau of Labor Statistics  reported Friday. The unemployment rate rose to 4.3%, up slightly from 4.2% in July but hitting the highest level seen since October 2021, when the economy was still recovering from pandemic-driven layoffs. Although the new jobs report was troubling news for the economy, for prospective homebuyers with secure jobs it likely means further easing in  mortgage rates  in the days to come. Mortgage rates hinge primarily on the yields of  10-year Treasury notes , which plunged Friday to their lowest level since early April, when President  Donald Trump 's Liberation Day tariff announcement sparked panic in financial markets. It signals furth...

Long-Stalled Credit Card Competition Act Moves Forward In Senate Clarity Act Markup

WASHINGTON—A long-stalled bipartisan push to boost competition in the credit card market moved closer to becoming law late Friday, as Sens. Roger Marshall (R-KS) and Dick Durbin (D-IL) advanced a new amendment attached to the Senate Agriculture Committee’s markup of the Digital Asset Market Structure and Investor Protection Act, commonly known as the Clarity Act. Dick Durbin The amendment, a core component of the long-debated Credit Card Competition Act, would prohibit major credit-card networks and large issuing banks from enforcing network exclusivity on credit cards. Supporters argue the measure would expand transaction-routing competition, weaken the dominance of the largest payment networks, and reduce swipe fees that merchants say inflate consumer prices. The renewed momentum reflects President Trump’s recent backing of efforts to rein in credit card costs, a shift that has altered the political trajectory of legislation that has struggled to advance in prior Congresses. With Tru...

One Fed Bank President Wants to See Rates at 3% or Higher by Year-End

James Bullard  ST. LOUIS–Federal Reserve Bank of St. Louis President James Bullard said he would like to see the Fed’s benchmark rate increased to at least 3% by year-end 2022 to counter the highest inflation in four decades. Bullard also said he favors shrinking the Fed’s bloated balance sheet. “I would like the committee to get to 3-3.25% on the policy rate in the second half of this year,” Bullard told reporters after a speech at the University of Missouri, Bloomberg reported. “We have to move forthrightly in order to get the policy rate to the right level to deal with the inflation we have got in front of us.” As CUToday.info reported, the Fed raised its benchmark overnight rate by 25 basis points last month to a target range of 0.25% to 0.5%. Bullard, who favored a half-point increase, was the lone dissenter in the 8-1 policy vote. Bloomberg noted forecasts released with their policy decision showed officials expect to raise rates to 1.9% by the end of the year, ac...