Skip to main content

'Anatomy' Of A Ransomware Attack

By Ray Birch

BALTIMORE—Credit unions should brace for almost a month of major problems if they’re victimized by a ransomware attack, according to one cybersecurity expert, whose insights into the “anatomy” of a ransomware attack are coming at the same time nearly 60 CUs are currently trying to restore their own operations.

As those credit unions have come to learn, it takes on average 22 days to get through a ransomware attack and get to the other side, that same expert stated.

That information and additional insights were shared during a webinar hosted by cybersecurity firm Think/Stack, which that was held to provide CUs with insights and answers regarding ransomware in light of the recent attack that that continues to affect those five-dozen CUs hit by an attack on a common vendor.

Feature Ransomware Webinar 1

“We're all being targeted, and this (recent attack) could have happened to anybody,” said Cal Bowman, Think/Stack VP of client innovation and strategy, referring to an attack on the CUSO Ongoing Operations that in turn affected the data processor Fedcomp. “So, it's really important we all recognize that every one of you here has vendors, has partners that are vulnerable. Therefore, the question is, are you ready to respond to any type of large-scale event that really can cripple your organization?”

What’s Been Learned

bowman

Bowman said a goal of the webinar, which was attended by more than 300 credit unions, was to walk through what happens during a ransomware attack and share what his company has learned supporting CUs that have been victimized by such attacks.

Think/Stack VP of Security and Risk Jennifer Anthony said when a ransomware attack occurs in an organization it frequently creates the “fog of war.”

“What you will see in a generalized ransomware attack is the tactical and technical pieces that begin to happen over the first couple days,” Anthony explained.

But at the same time a credit union is seeking to find a tactical path through that fog, the emotional side of the battle must be given attention, as employees struggle to get the CU operating again, Anthony said.

“There is confusion and concern,” she said. “Maybe someone can't get on to a system they previously could access. Maybe there's a service that's not working and folks are starting to feel confused about what's going on. All this is happening as your technical teams in the background are beginning to quickly investigate the source of the problem.”

Anthony emphasized a credit union involved in a ransomware attack should be prepared to spend at least three weeks dealing with it.  

The Internal Threat

As CUToday.info has reported and as credit unions are frequently warned, ransomware attacks often occur due to an employee opening the door by falling for a phishing scam or downloading a file they believe to be safe.

“This is a function of human performance,” she noted. “We all begin to look for who's at fault, who did something they were not supposed to do that caused this. What we tell organizations is that when you get caught in that space, you should not spend a lot of time trying to figure out who to point the finger at, (but instead spend) time trying to figure out how to get out of the situation.”

Not surprisingly, Anthony described the working environment following an attack as “chaotic.”

‘Everyone’s Scared’

“Everyone's scared. We're not sure what's going on and maybe we have members who are really angry. Maybe we have board members that are really angry, or leaders that are really angry,” she said. “The goal at this point is to figure out how to get past it. We'll figure out who's to blame or what's to blame, or how we can prevent it in the future at a later point.”

It's an issue credit unions should take seriously, according to Anthony, who said there is a growing ransomware threat to the not-for-profit co-ops.

“In the last seven months we worked with six credit unions who individually found themselves in this space,” she said. “This is something that's happening on a regular basis, across all industries.”

Anthony reminded that as the credit union moves through a ransomware incident many employees will be feelin remorse and concern over fellow workers in IT who are working feverishly to restore operations.

“They feel like they are at fault for what is going on, and that is a very difficult place to be,” she said. “The technical teams are trying to figure out how to remediate the situation. I've been in organizations where technical teams are working nonstop, around the clock, for days and days. The credit union then is trying to figure out how do we feed people? How are we going to send people home to sleep so they can come back and be effective—because you are in this fight for a long time and there is a lot of pressure on everyone.”

Like Being in a Battle

Anthony likened the experience to those who fight in a war.

“I spent 20 years in the in the United States military, and this is a roller coaster akin to what a service member might experience in their daily lives—and this can be traumatic,” she said.

anthony

She urged credit unions to consider where they are vulnerable.  

“We know 93% of ransomware attacks are in Windows-based environment,” she said. “If we listed them in order of frequency of occurrence, how they occur, here's what they would be: Number one is e-mail phishing campaigns. Number two would be (remote desktop protocol or RDP) vulnerabilities. And number three would be software vulnerabilities.”

The Long-Term Affects

While those 22 days are the typical time from attack to restoration of service, Anthony said the repercussions are felt for many months afterward.

“With the recovery efforts and return to operation, the average time for an organization to move through that is about nine months,” she said. “The attack is not the only thing organizations have to grapple with; there are follow-on impacts that are significant. If you're an organization that has about 500 employees, your average recovery cost is going to be about $3.1 million. If an attacker is successful in extracting information from your environment, you'll have to deal with the impacts of that.”

Steps to Take

What steps should credit unions take today to prevent an attack? CUToday.info will share those in a follow-up report.

Comments

Popular posts from this blog

Why Auto Lending Is Starting To Stand Out As A Real Threat To CUs

  By Ray Birch MILWAUKEE—Auto lending is emerging as one of the biggest areas of risk for credit unions, even as the broader U.S. economy continues to perform better than many expected, according to Bill Handel, chief economist at Raddon, a Fiserv company. Delinquency trends in auto portfolios are now approaching levels last seen during the Great Financial Crisis, Handel said, driven by a combination of high vehicle prices, elevated interest rates and increasing financial pressure on lower-income consumers. “There’s probably still a lot of risk in the auto portfolios,” Handel said. “Our numbers in terms of delinquency behavior in the United States are now rivaling what they were during the Great Financial Crisis.” Economy Holding Up Better Than Expected Despite those pockets of risk, Handel said the broader economy remains surprisingly resilient. “If you look at the U.S. economy, it’s actually performing quite well—probably better than most people would have anticipated,” he said. ...

When Cooperation Turns To Competition: A Turning Point For The Firefighter Credit Union Movement

  By Grant Sheehan For decades, firefighter credit unions have stood as a model of what cooperative finance is meant to be—institutions built not to compete ruthlessly, but to serve a shared mission: supporting the financial well-being of those who risk their lives in service to others. That’s what makes the recent actions of Firefighter First Credit Union so concerning. Firefighter First FCU was not just another participant; it was a founding member of the National Council of Firefighter Credit Unions (NCOFCU). It helped shape the very principles of collaboration, mutual respect, and non-encroachment that have long defined our community. Those principles weren’t accidental; they were intentional safeguards to ensure that firefighter-focused credit unions could grow together, not at each other’s expense. But something has changed. Firefighter First FCU’s decision to pursue a nationwide charter marks a clear shift in direction—from cooperation to direct competition. This isn’t simpl...

Small Credit Unions Don’t Lack Representation—They Lack Board Education

  By Grant Sheehan Let’s be clear— representation  for small credit unions is not something new that suddenly needs to be invented. For more than 150 years in Europe and 115 years in the U.S., many of us—along with numerous trade groups representing postal workers, schools, hospitals, the military, first responders, electricians, welders, auto workers, and many other sponsor employee groups—have been actively representing and supporting small credit unions. The mission has always been the same: protect these institutions and ensure they have a voice. The real challenge facing small credit unions has never been a lack of organizations claiming to represent them. The challenge has been engagement and education. Many small credit unions operate with extremely limited resources. Their boards are made up of volunteers who already have full-time careers. Even when scholarships, training opportunities, and conferences are offered, the realities of travel costs, staffing shortages, op...

With Graham Signaling New Budget Bill, Credit Unions Brace For Tax Debate

By Ray Birch WASHINGTON— Senate Budget Committee Chairman Lindsey Graham’s comments Wednesday that Republicans will “expeditiously move toward creating a second budget reconciliation bill” are giving new shape to what had been a speculative discussion in Washington—and prompting renewed attention within the credit union industry to whether the movement’s federal tax exemption could again surface as lawmakers look for possible offsets. In a post on X, Graham said that after consulting with President Trump, his team and Senate Majority Leader John Thune, the Senate Budget Committee will move quickly on a second reconciliation package focused on “adequate funding to secure our homeland” and support for the military. The remarks are notable because they offer one of the clearest indications yet that a second fast-track budget measure—previously discussed but far from certain—may now be gaining traction. CUToday.info on Wednesday reached out to House Budget Committee Chairman Jodey Arringto...

The United States at 250: How the Country Has Changed in the Past 50 Years

  In July, the United States will celebrate its 250th anniversary. The country’s last major milestone was 50 years ago, at its bicentennial on July 4, 1976. U.S. society has changed profoundly since then. Over the past five decades, the U.S. population has  aged significantly,  with the percentage of people 65 and older nearly doubling. The country has also become  more racially and ethnically diverse,  as growing shares of people identify as Asian or Hispanic. And following more than 70 million immigrant arrivals, the percentage of  foreign-born people  in the population has more than tripled.  Americans are also  less likely to be married  than ever before. Women – who now have far more options outside of the home than they did in 1976 – have contributed to a  boom in higher education  and helped  expand the workforce.  And even though many Americans are financially better off than they were 50 years ago,  econ...

Honoring Our Member Credit Unions Ranked Among the Top 100 in 2025

Celebrating Excellence: Honoring Our Member Credit Unions Ranked Among the Top 100 in 2025   Best-performing US credit unions of 2025 At NCOFCU, we take immense pride in the strength, resilience, and impact of our member credit unions. Today, we are thrilled to recognize and celebrate several of our members who have earned a place among the Top 100 Best Performing Credit Unions of 2025 —a testament to their unwavering commitment to service, financial stewardship, and community leadership. This achievement is not just about rankings—it reflects the daily dedication to members, the trust built within communities, and the innovation that continues to drive our movement forward. 🌟 Our Honored Members We proudly congratulate the following institutions for their outstanding performance: #7 – Long Beach Firemen's Credit Union A remarkable top-10 finish that highlights exceptional operational excellence and member value. Long Beach Firemen’s CU continues to set a high bar for perform...

What Gen Z Is Really Looking For In A Credit Union

  Gen Z’s faith in traditional institutions gives credit unions a rich opportunity to serve as a key source of financial guidance. Sponsored Content By Adrenaline, Inc. Credit unions can strengthen loyalty with the influential Generation Z by connecting their brand’s purpose, financial guidance, and in-branch experience. Widely described as digital natives, Gen Z meets many of their everyday banking needs with mobile apps and digital tools across multiple providers. While younger consumers certainly expect seamless digital functionality from their primary financial provider, what they value even more is meaningful advice and trusting relationships. Because beneath Gen Z’s technological savvy is a measurable confidence gap —  one that impacts every aspect of their financial lives. According to  Adrenaline’s 2026 Gen Z research  conducted with Alexander Babbage, 36% of Gen Z say they find financial matters confusing, and one in three report feeling overwhelmed by money...

Employers should take note, as company culture starts with professional development.

Employees and employers alike may have thought they understood company culture, and likely did until recently. Coming to work, knowing company values, interacting with others are all no brainers when it comes to the driving forces that make up company culture. Buy a seismic shift is occurring on two fronts. One, various generations are working together in multiple industries and two; the pandemic has changed attitudes about where work can occur and how that may or may not affect culture. The Linkedin Global Trends 2022 report says more freedom to work where and when employees want, as well as attention to wellbeing, are important demands employers need to consider. Consider the numbers: when picking a new job, 63% of professionals put work-life balance as the top priority. Sixty percent are interested in compensation and benefits and 40% say the colleagues and culture they will be working with are their top priorities. Employers should take note as company culture starts with profess...

Credit Unions Look For Answers After NCUA Shake-Up

FAQ on Recent Firing of NCUA Board Members ,   click here. WASHINGTON—Do Todd Harper and Tanya Otsuka have legal standing to contest their removal from the NCUA board by President Donald Trump? Has any past president taken similar action? Can NCUA continue functioning without a quorum on its board? Is this the first step toward consolidating federal banking regulators? In light of President Trump’s decision to remove Democratic NCUA board members Harper and Otsuka, many in the credit union community have expressed concerns and raised important questions. In response, America’s Credit Unions has prepared a detailed Q&A document addressing the implications of the White House’s actions announced on Wednesday. Below are key takeaways from the document ACU has shared with its members: President Trump may now nominate either one or two new board members to fill these vacant positions. At least one must be from a different political party, as statutorily required by the FCU Act. Or, l...

One Fed Bank President Wants to See Rates at 3% or Higher by Year-End

James Bullard  ST. LOUIS–Federal Reserve Bank of St. Louis President James Bullard said he would like to see the Fed’s benchmark rate increased to at least 3% by year-end 2022 to counter the highest inflation in four decades. Bullard also said he favors shrinking the Fed’s bloated balance sheet. “I would like the committee to get to 3-3.25% on the policy rate in the second half of this year,” Bullard told reporters after a speech at the University of Missouri, Bloomberg reported. “We have to move forthrightly in order to get the policy rate to the right level to deal with the inflation we have got in front of us.” As CUToday.info reported, the Fed raised its benchmark overnight rate by 25 basis points last month to a target range of 0.25% to 0.5%. Bullard, who favored a half-point increase, was the lone dissenter in the 8-1 policy vote. Bloomberg noted forecasts released with their policy decision showed officials expect to raise rates to 1.9% by the end of the year, ac...