Skip to main content

'Anatomy' Of A Ransomware Attack

By Ray Birch

BALTIMORE—Credit unions should brace for almost a month of major problems if they’re victimized by a ransomware attack, according to one cybersecurity expert, whose insights into the “anatomy” of a ransomware attack are coming at the same time nearly 60 CUs are currently trying to restore their own operations.

As those credit unions have come to learn, it takes on average 22 days to get through a ransomware attack and get to the other side, that same expert stated.

That information and additional insights were shared during a webinar hosted by cybersecurity firm Think/Stack, which that was held to provide CUs with insights and answers regarding ransomware in light of the recent attack that that continues to affect those five-dozen CUs hit by an attack on a common vendor.

Feature Ransomware Webinar 1

“We're all being targeted, and this (recent attack) could have happened to anybody,” said Cal Bowman, Think/Stack VP of client innovation and strategy, referring to an attack on the CUSO Ongoing Operations that in turn affected the data processor Fedcomp. “So, it's really important we all recognize that every one of you here has vendors, has partners that are vulnerable. Therefore, the question is, are you ready to respond to any type of large-scale event that really can cripple your organization?”

What’s Been Learned

bowman

Bowman said a goal of the webinar, which was attended by more than 300 credit unions, was to walk through what happens during a ransomware attack and share what his company has learned supporting CUs that have been victimized by such attacks.

Think/Stack VP of Security and Risk Jennifer Anthony said when a ransomware attack occurs in an organization it frequently creates the “fog of war.”

“What you will see in a generalized ransomware attack is the tactical and technical pieces that begin to happen over the first couple days,” Anthony explained.

But at the same time a credit union is seeking to find a tactical path through that fog, the emotional side of the battle must be given attention, as employees struggle to get the CU operating again, Anthony said.

“There is confusion and concern,” she said. “Maybe someone can't get on to a system they previously could access. Maybe there's a service that's not working and folks are starting to feel confused about what's going on. All this is happening as your technical teams in the background are beginning to quickly investigate the source of the problem.”

Anthony emphasized a credit union involved in a ransomware attack should be prepared to spend at least three weeks dealing with it.  

The Internal Threat

As CUToday.info has reported and as credit unions are frequently warned, ransomware attacks often occur due to an employee opening the door by falling for a phishing scam or downloading a file they believe to be safe.

“This is a function of human performance,” she noted. “We all begin to look for who's at fault, who did something they were not supposed to do that caused this. What we tell organizations is that when you get caught in that space, you should not spend a lot of time trying to figure out who to point the finger at, (but instead spend) time trying to figure out how to get out of the situation.”

Not surprisingly, Anthony described the working environment following an attack as “chaotic.”

‘Everyone’s Scared’

“Everyone's scared. We're not sure what's going on and maybe we have members who are really angry. Maybe we have board members that are really angry, or leaders that are really angry,” she said. “The goal at this point is to figure out how to get past it. We'll figure out who's to blame or what's to blame, or how we can prevent it in the future at a later point.”

It's an issue credit unions should take seriously, according to Anthony, who said there is a growing ransomware threat to the not-for-profit co-ops.

“In the last seven months we worked with six credit unions who individually found themselves in this space,” she said. “This is something that's happening on a regular basis, across all industries.”

Anthony reminded that as the credit union moves through a ransomware incident many employees will be feelin remorse and concern over fellow workers in IT who are working feverishly to restore operations.

“They feel like they are at fault for what is going on, and that is a very difficult place to be,” she said. “The technical teams are trying to figure out how to remediate the situation. I've been in organizations where technical teams are working nonstop, around the clock, for days and days. The credit union then is trying to figure out how do we feed people? How are we going to send people home to sleep so they can come back and be effective—because you are in this fight for a long time and there is a lot of pressure on everyone.”

Like Being in a Battle

Anthony likened the experience to those who fight in a war.

“I spent 20 years in the in the United States military, and this is a roller coaster akin to what a service member might experience in their daily lives—and this can be traumatic,” she said.

anthony

She urged credit unions to consider where they are vulnerable.  

“We know 93% of ransomware attacks are in Windows-based environment,” she said. “If we listed them in order of frequency of occurrence, how they occur, here's what they would be: Number one is e-mail phishing campaigns. Number two would be (remote desktop protocol or RDP) vulnerabilities. And number three would be software vulnerabilities.”

The Long-Term Affects

While those 22 days are the typical time from attack to restoration of service, Anthony said the repercussions are felt for many months afterward.

“With the recovery efforts and return to operation, the average time for an organization to move through that is about nine months,” she said. “The attack is not the only thing organizations have to grapple with; there are follow-on impacts that are significant. If you're an organization that has about 500 employees, your average recovery cost is going to be about $3.1 million. If an attacker is successful in extracting information from your environment, you'll have to deal with the impacts of that.”

Steps to Take

What steps should credit unions take today to prevent an attack? CUToday.info will share those in a follow-up report.

Comments

Popular posts from this blog

Trump Administration Declares CFPB Funding Illegal, Bureau’s Cash To Run Out By Early 2026

WASHINGTON—Credit-unions face a potential regulatory vacuum as the Trump Administration formally has determined the CFPB’s current self-funding mechanism unlawful—a move that could put the agency on a path to closure in early 2026 unless Congress steps in. For credit-union leaders, who rely on the Bureau’s oversight of consumer-finance markets and enforcement of unfair practices, the decision signals a major disruption to the regulatory environment CUs navigate daily. In a court filing released late Monday, the Administration declared that the CFPB is now legally barred from seeking additional funds from the Federal Reserve System—the agency’s usual funding source under the Dodd‑Frank Wall Street Reform and Consumer Protection Act, POLITICO reported. That means the Bureau’s remaining resources will likely carry it only through the end of the year, after which it “anticipates exhausting its currently available funds in early 2026.” CUToday.info has tracked this story, noting in  Oct...

Sheehans Consulting LLC - "We only have one goal in mind!"

We have one goal in mind: “What is best for you? We achieve strategic initiatives, develop products, optimize profitability and productivity through best practices, and make our firm a strong asset for professional services.  With over 30 years of experience in public administration, credit union, and association management, I have developed a solid track record in leadership and development.  Please visit us at https://www.sheehansconsultingllc.com/ to learn more about what we can do for you.   _________________________________________ Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board

Now Available - "Financial Literacy" From NCOFCU

https://www.ncofcu.org/financial-literacy The National Council of Firefighter Credit Unions (NCOFCU) is dedicated to enhancing financial literacy among our members, members, particularly targeting the Millennial and Gen Z demographics. We are excited to share our engaging financial education video series, designed to address their key concerns regarding earning, saving, and spending money wisely. Here are several critical financial lessons that can significantly impact your personal finance management and long-term financial health. Discover how staying informed and educated about financial products and market trends can empower you to make smarter financial decisions. https://www.youtube.com/playlist?list=PLT3lzRTXnHw4LjHuOIk31eTDxaQ7J7B0f   _________________________________________ Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board

NCUA Reports Continued Credit Union Loan Growth in First Quarter of 2016

"ALEXANDRIA, Va. (June 3, 2016) – Credit unions continued to increase their lending, with loans outstanding increasing 10.7 percent in the year ending in the first quarter of 2016, the National Credit Union Administration reported today.  “The credit union system again experienced solid performance during the first quarter of 2016,” NCUA Board Chairman Rick Metsger said. “Overall, new and used auto lending was especially strong, and the system gained one million members. With an influx of deposits, federally insured shares at credit unions also neared the $1 trillion mark coming in at $991.7 billion.  “As credit union lending has increased, long-term investments have declined and reduced the system’s interest rate risk. However, delinquency and charge-off rates are slightly higher than a year ago, and member-business loan delinquencies are rising even more. Credit unions making such loans should take note and ensure that they perform proper due diligence to mitigate the r...

Best Places to Retire

  List: Best Places to Retire Midland, Michigan , was ranked the best place to retire , according to a ranking of 850 cities by U.S. News . The top locations had the best mix of affordability, quality of life, health care access, and other benefits. The top five were rounded out by Weirton, West Virginia , Homosassa Springs, Florida , The Woodlands, Texas , and Spring, Texas . Midland scored top marks on walkability , culture , retail establishments , and restaurants . The town is just a short drive from beaches at the edge of Lake Huron . The top 25 included nine cities in Florida and six in Texas. See the full list here . _________________________________________ Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board

NCUA Letter to Credit Unions: Interagency Statement on LIBOR Transition

Dear Boards of Directors and Chief Executive Officers: As a follow-up to Letter to Credit Unions 21-CU-03, LIBOR Transition , this letter provides additional reminders related to LIBOR’s discontinuance. Five federal financial institution regulatory agencies, in conjunction with the state bank and state credit union regulators, are jointly issuing the enclosed statement to emphasize the expectation that supervised institutions with LIBOR exposure will continue to progress toward an orderly transition away from LIBOR. [1] The NCUA encourages all federally insured credit unions to transition away from using U.S. dollar LIBOR as a reference rate as soon as possible, but no later than December 31, 2021, and to ensure existing contracts have robust fallback language that includes a clearly defined alternative reference rate. Please contact your NCUA Regional Office or state supervisory authority if you have any questions about this important topic. Read the Letter to Credit Unions   Sav...

House Vote Ends Longest Shutdown In U.S. History

WASHINGTON—The House late Wednesday approved a sweeping funding measure to end the longest federal government shutdown in U.S. history, clearing the way for federal agencies to reopen within hours and for hundreds of thousands of workers and service members to receive long-delayed pay. The vote was 222-209, with just six Democrats breaking with their leadership, POLITOCO said. President Trump is expected to sign the measure before night’s end, allowing federal operations to resume Thursday morning. The chamber’s vote—coming after days of intense negotiations and following the Senate’s 60–40 passage—sent the bipartisan agreement to President Donald Trump for his signature, effectively ending a shutdown that stretched well past six weeks and rattled everything from military readiness to basic government services. The package includes a continuing resolution funding the government through Jan. 30. The measure also includes a three-bill “minibus” of full-year funding for the Department...

Fed Governor Warns ‘Global Stablecoin Glut’ Could Reshape Monetary Policy

  NEW YORK—Federal Reserve Governor Stephen Miran believes the rapid rise of stablecoins could become a major force shaping U.S. monetary policy. Once seen as a niche digital tool for crypto traders, stablecoins have evolved into a global conduit for dollar-denominated transactions, enabling users worldwide to store value and move capital more efficiently. Their growing prominence, Miran noted during his speech at the BCVC Summit 2025 at the Harvard Club, reflects continued demand for dollars—and with the GENIUS Act now providing a clear regulatory framework for U.S.-issued stablecoins, the sector is poised for broader adoption across payment systems. Stephen Miran Stablecoins’ link to the U.S. dollar is reinforcing the currency’s global dominance while simultaneously creating new implications for monetary policy. Miran argued that stablecoins are already increasing demand for U.S. Treasury bills and other dollar-based assets, especially from investors outside the United States. Th...

Current Geopolitical Events Increase Likelihood of Imminent Cyberattacks on Financial Institutions

Current Geopolitical Events Increase Likelihood of Imminent Cyberattacks on Financial Institutions Financial Institutions, Large and Small, Included in Potential Targets to U.S. Critical Infrastructure The U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) has recently issued two alerts addressing risks from Russian State-Sponsored cyber threats and highlighting recent malicious cyber incidents suffered by public and private entities in Ukraine . Given current geopolitical events, the NCUA, along with CISA, the Federal Bureau of Investigation, and the National Security Agency encourage credit unions of all sizes and their cybersecurity teams nationwide to adopt a heightened state of awareness and to conduct proactive threat hunting. In addition, COVID-related supply chain disruptions may require management to reevaluate previously held assumptions for business continuity and disaster recovery pla...

Zero - Cost - Zero - Risk

  https://synergycu.org/ _______________________________________________ Check out some of NCOFCU's additional features: First Responder Credit Union Academy Podcasts YouTube Mini's Blog Job Board