Skip to main content

'Anatomy' Of A Ransomware Attack

By Ray Birch

BALTIMORE—Credit unions should brace for almost a month of major problems if they’re victimized by a ransomware attack, according to one cybersecurity expert, whose insights into the “anatomy” of a ransomware attack are coming at the same time nearly 60 CUs are currently trying to restore their own operations.

As those credit unions have come to learn, it takes on average 22 days to get through a ransomware attack and get to the other side, that same expert stated.

That information and additional insights were shared during a webinar hosted by cybersecurity firm Think/Stack, which that was held to provide CUs with insights and answers regarding ransomware in light of the recent attack that that continues to affect those five-dozen CUs hit by an attack on a common vendor.

Feature Ransomware Webinar 1

“We're all being targeted, and this (recent attack) could have happened to anybody,” said Cal Bowman, Think/Stack VP of client innovation and strategy, referring to an attack on the CUSO Ongoing Operations that in turn affected the data processor Fedcomp. “So, it's really important we all recognize that every one of you here has vendors, has partners that are vulnerable. Therefore, the question is, are you ready to respond to any type of large-scale event that really can cripple your organization?”

What’s Been Learned

bowman

Bowman said a goal of the webinar, which was attended by more than 300 credit unions, was to walk through what happens during a ransomware attack and share what his company has learned supporting CUs that have been victimized by such attacks.

Think/Stack VP of Security and Risk Jennifer Anthony said when a ransomware attack occurs in an organization it frequently creates the “fog of war.”

“What you will see in a generalized ransomware attack is the tactical and technical pieces that begin to happen over the first couple days,” Anthony explained.

But at the same time a credit union is seeking to find a tactical path through that fog, the emotional side of the battle must be given attention, as employees struggle to get the CU operating again, Anthony said.

“There is confusion and concern,” she said. “Maybe someone can't get on to a system they previously could access. Maybe there's a service that's not working and folks are starting to feel confused about what's going on. All this is happening as your technical teams in the background are beginning to quickly investigate the source of the problem.”

Anthony emphasized a credit union involved in a ransomware attack should be prepared to spend at least three weeks dealing with it.  

The Internal Threat

As CUToday.info has reported and as credit unions are frequently warned, ransomware attacks often occur due to an employee opening the door by falling for a phishing scam or downloading a file they believe to be safe.

“This is a function of human performance,” she noted. “We all begin to look for who's at fault, who did something they were not supposed to do that caused this. What we tell organizations is that when you get caught in that space, you should not spend a lot of time trying to figure out who to point the finger at, (but instead spend) time trying to figure out how to get out of the situation.”

Not surprisingly, Anthony described the working environment following an attack as “chaotic.”

‘Everyone’s Scared’

“Everyone's scared. We're not sure what's going on and maybe we have members who are really angry. Maybe we have board members that are really angry, or leaders that are really angry,” she said. “The goal at this point is to figure out how to get past it. We'll figure out who's to blame or what's to blame, or how we can prevent it in the future at a later point.”

It's an issue credit unions should take seriously, according to Anthony, who said there is a growing ransomware threat to the not-for-profit co-ops.

“In the last seven months we worked with six credit unions who individually found themselves in this space,” she said. “This is something that's happening on a regular basis, across all industries.”

Anthony reminded that as the credit union moves through a ransomware incident many employees will be feelin remorse and concern over fellow workers in IT who are working feverishly to restore operations.

“They feel like they are at fault for what is going on, and that is a very difficult place to be,” she said. “The technical teams are trying to figure out how to remediate the situation. I've been in organizations where technical teams are working nonstop, around the clock, for days and days. The credit union then is trying to figure out how do we feed people? How are we going to send people home to sleep so they can come back and be effective—because you are in this fight for a long time and there is a lot of pressure on everyone.”

Like Being in a Battle

Anthony likened the experience to those who fight in a war.

“I spent 20 years in the in the United States military, and this is a roller coaster akin to what a service member might experience in their daily lives—and this can be traumatic,” she said.

anthony

She urged credit unions to consider where they are vulnerable.  

“We know 93% of ransomware attacks are in Windows-based environment,” she said. “If we listed them in order of frequency of occurrence, how they occur, here's what they would be: Number one is e-mail phishing campaigns. Number two would be (remote desktop protocol or RDP) vulnerabilities. And number three would be software vulnerabilities.”

The Long-Term Affects

While those 22 days are the typical time from attack to restoration of service, Anthony said the repercussions are felt for many months afterward.

“With the recovery efforts and return to operation, the average time for an organization to move through that is about nine months,” she said. “The attack is not the only thing organizations have to grapple with; there are follow-on impacts that are significant. If you're an organization that has about 500 employees, your average recovery cost is going to be about $3.1 million. If an attacker is successful in extracting information from your environment, you'll have to deal with the impacts of that.”

Steps to Take

What steps should credit unions take today to prevent an attack? CUToday.info will share those in a follow-up report.

Comments

Popular posts from this blog

The Case for Sharing a CEO Between Credit Unions

  Embracing Collaboration: The Case for Sharing a CEO Between Credit Unions In recent years, credit unions have faced numerous challenges, from regulatory pressures to evolving member expectations. As many seasoned leaders retire, smaller credit unions often find themselves at a turning point. In this landscape, one innovative solution is gaining traction: sharing a CEO between two credit unions. This approach not only addresses financial constraints but also fosters collaboration and enhances service delivery. The Rationale Behind Sharing a CEO 1. Financial Sustainability One of the most pressing concerns for small credit unions is maintaining financial health amid rising operational costs. A shared CEO model alleviates the financial burden of hiring and compensating a full-time executive. By splitting salary and benefits, both credit unions can allocate resources more effectively, allowing for investment in member services, technology, and community initiatives. ...

Reading Up On Recessions

  Reading Up On Recessions       Background Stemming from the Latin word “recessus” (meaning “a retreat”), recessions are  sustained periods  of declining activity in a country’s economy. During a recession, unemployment rises while economic output falls across a large swath of industries. Recessions are inevitable in modern economies, with one occurring about every six to seven years ( What causes recessions ?).   One common definition of a recession is when a country logs two consecutive quarters of shrinking gross domestic product, but in practice, ...

Sunday Reading - Landmine Rat Honored

  Landmine Rat Honored   Cambodia unveiled the world’s first statue honoring a landmine-detecting rat (w/photo) Friday. Magawa the rat lived to 8 years old and identified more than 100 landmines and other explosives from 2016 to 2021.  There are more than 100 African pouched rats deployed in landmine detection operations across the world. To identify mines, the rats are trained to sniff out explosive compounds like trinitrotoluene, or TNT. (The rats are not heavy enough to trigger detonation.) In Cambodia, up to 6 million landmines remain undiscovered, most planted during three decades of conflict, from the Vietnam War era through Cambodia's civil war . Since 1979, roughly 20,000 people have been killed in Cambodia, and roughly 40,000 wounded as a result of the mines. Magawa cleared more than ...

Sunday Reading - The gold standard, explained

  Gold Standard       The gold standard, explained A gold standard is a system where a country’s currency is pegged to, and can be converted into, a fixed amount of gold. It’s typically meant to create a sense of security in the country’s currency: When a government uses a gold standard , its currency can be exchanged for an equivalent amount of gold—although regulations around redemption vary by country.   After the Civil War, in 1873, America adopted the gold standard for the first time. At the time, if gold was priced at $100 an ounce, each dollar  rep...

Open Banking Pushes Leading Credit Unions Ahead In Race For Member Loyalty

  https://youtu.be/pUIV8hwSDCE NEW YORK—Credit unions that embrace open banking aren’t just keeping pace with competitors—they’re pulling ahead, new data show. A new report finds that innovation in digital tools and personalized experiences is emerging as the decisive factor separating credit unions that win lasting member loyalty from those at risk of losing ground. “ The 2025 Credit Union Innovation Readiness Index: Closing Gaps, Winning Members ,” a June report produced in collaboration between  Velera  and PYMNTS Intelligence, underscores innovation as a defining factor for credit union success. iStock-Korakrich Suntornnites “Facing shifting expectations from both consumers and small to medium-sized businesses (SMBs) toward digital convenience and tailored experiences, credit unions must modernize not just to compete with traditional banks, but to remain relevant to their members. The report, based surveys of 500 credit union executives, 15,000 U.S. consumers, and nea...

Long-Stalled Credit Card Competition Act Moves Forward In Senate Clarity Act Markup

WASHINGTON—A long-stalled bipartisan push to boost competition in the credit card market moved closer to becoming law late Friday, as Sens. Roger Marshall (R-KS) and Dick Durbin (D-IL) advanced a new amendment attached to the Senate Agriculture Committee’s markup of the Digital Asset Market Structure and Investor Protection Act, commonly known as the Clarity Act. Dick Durbin The amendment, a core component of the long-debated Credit Card Competition Act, would prohibit major credit-card networks and large issuing banks from enforcing network exclusivity on credit cards. Supporters argue the measure would expand transaction-routing competition, weaken the dominance of the largest payment networks, and reduce swipe fees that merchants say inflate consumer prices. The renewed momentum reflects President Trump’s recent backing of efforts to rein in credit card costs, a shift that has altered the political trajectory of legislation that has struggled to advance in prior Congresses. With Tru...

USPS Defends Banking Pilot, While Opponents Call It Illegal

  By David Baumann - July 11, 2022 Program has faced opposition from the outset, including from credit union groups, and has struggled to gain real traction. The U.S. Postal Service (USPS) argued this week that the controversial pilot program it is operating i...

Meet Spokane Firefighter Credit Union (SFCU) New President/CEO - Troy Clute

Meet SFCU's New President/CEO - Troy Clute  Troy Clute serves as the President and Chief Executive Officer of Spokane Firefighters Credit Union, bringing 29 years of experience in banking and finance. His career includes extensive leadership roles across the industry, with a strong foundation in consumer lending and member-focused financial services. Troy is a graduate of the renowned CUES CEO Institute Program, having earned the Certified Chief Executive (CCE) designation—one of the highest leadership credentials in the credit union movement. His leadership is defined by strategic vision, operational excellence, and a deep commitment to serving Spokane’s firefighter community and their families. Beyond his professional role, Troy values family above all. He and his wife, Karri, have been married for 36 years and share two grown children, Kellen and Kennadie, as well as three grandchildren—Tyus, Izze, and Major—who keep life joyful and full of adventure. When he’s not leading the c...

The impact of recent bank failures could impact credit unions.

The failures of Silicon Valley Bank (SVB) and Signature Bank, combined with the FDIC’s decision to cover all depositors could have an impact on credit unions. With over 93% of their deposits uninsured, SVB appears to be the poster child for poor strategic planning. The bank got caught short when the Fed raised rates. For credit unions, the real story is the decision to cover ALL accounts regardless of the amount in the account. Where is the threat to credit unions? Credit unions had no role in the failures of SVB and Signature Bank. The threat lies in the Treasury and FDIC’s decision to guarantee the funds in every account…no matter how much was in that account. While the Treasury Secretary and FDIC Chairman Gruenberg may have felt the need to do so to restore confidence, this action just kicks the can down the road. And the road will have no end if NCUA feels the pressure to do the same thing if a similar situation hits the credit union movement. Should there be a conservatorship or...