Skip to main content

'Anatomy' Of A Ransomware Attack

By Ray Birch

BALTIMORE—Credit unions should brace for almost a month of major problems if they’re victimized by a ransomware attack, according to one cybersecurity expert, whose insights into the “anatomy” of a ransomware attack are coming at the same time nearly 60 CUs are currently trying to restore their own operations.

As those credit unions have come to learn, it takes on average 22 days to get through a ransomware attack and get to the other side, that same expert stated.

That information and additional insights were shared during a webinar hosted by cybersecurity firm Think/Stack, which that was held to provide CUs with insights and answers regarding ransomware in light of the recent attack that that continues to affect those five-dozen CUs hit by an attack on a common vendor.

Feature Ransomware Webinar 1

“We're all being targeted, and this (recent attack) could have happened to anybody,” said Cal Bowman, Think/Stack VP of client innovation and strategy, referring to an attack on the CUSO Ongoing Operations that in turn affected the data processor Fedcomp. “So, it's really important we all recognize that every one of you here has vendors, has partners that are vulnerable. Therefore, the question is, are you ready to respond to any type of large-scale event that really can cripple your organization?”

What’s Been Learned

bowman

Bowman said a goal of the webinar, which was attended by more than 300 credit unions, was to walk through what happens during a ransomware attack and share what his company has learned supporting CUs that have been victimized by such attacks.

Think/Stack VP of Security and Risk Jennifer Anthony said when a ransomware attack occurs in an organization it frequently creates the “fog of war.”

“What you will see in a generalized ransomware attack is the tactical and technical pieces that begin to happen over the first couple days,” Anthony explained.

But at the same time a credit union is seeking to find a tactical path through that fog, the emotional side of the battle must be given attention, as employees struggle to get the CU operating again, Anthony said.

“There is confusion and concern,” she said. “Maybe someone can't get on to a system they previously could access. Maybe there's a service that's not working and folks are starting to feel confused about what's going on. All this is happening as your technical teams in the background are beginning to quickly investigate the source of the problem.”

Anthony emphasized a credit union involved in a ransomware attack should be prepared to spend at least three weeks dealing with it.  

The Internal Threat

As CUToday.info has reported and as credit unions are frequently warned, ransomware attacks often occur due to an employee opening the door by falling for a phishing scam or downloading a file they believe to be safe.

“This is a function of human performance,” she noted. “We all begin to look for who's at fault, who did something they were not supposed to do that caused this. What we tell organizations is that when you get caught in that space, you should not spend a lot of time trying to figure out who to point the finger at, (but instead spend) time trying to figure out how to get out of the situation.”

Not surprisingly, Anthony described the working environment following an attack as “chaotic.”

‘Everyone’s Scared’

“Everyone's scared. We're not sure what's going on and maybe we have members who are really angry. Maybe we have board members that are really angry, or leaders that are really angry,” she said. “The goal at this point is to figure out how to get past it. We'll figure out who's to blame or what's to blame, or how we can prevent it in the future at a later point.”

It's an issue credit unions should take seriously, according to Anthony, who said there is a growing ransomware threat to the not-for-profit co-ops.

“In the last seven months we worked with six credit unions who individually found themselves in this space,” she said. “This is something that's happening on a regular basis, across all industries.”

Anthony reminded that as the credit union moves through a ransomware incident many employees will be feelin remorse and concern over fellow workers in IT who are working feverishly to restore operations.

“They feel like they are at fault for what is going on, and that is a very difficult place to be,” she said. “The technical teams are trying to figure out how to remediate the situation. I've been in organizations where technical teams are working nonstop, around the clock, for days and days. The credit union then is trying to figure out how do we feed people? How are we going to send people home to sleep so they can come back and be effective—because you are in this fight for a long time and there is a lot of pressure on everyone.”

Like Being in a Battle

Anthony likened the experience to those who fight in a war.

“I spent 20 years in the in the United States military, and this is a roller coaster akin to what a service member might experience in their daily lives—and this can be traumatic,” she said.

anthony

She urged credit unions to consider where they are vulnerable.  

“We know 93% of ransomware attacks are in Windows-based environment,” she said. “If we listed them in order of frequency of occurrence, how they occur, here's what they would be: Number one is e-mail phishing campaigns. Number two would be (remote desktop protocol or RDP) vulnerabilities. And number three would be software vulnerabilities.”

The Long-Term Affects

While those 22 days are the typical time from attack to restoration of service, Anthony said the repercussions are felt for many months afterward.

“With the recovery efforts and return to operation, the average time for an organization to move through that is about nine months,” she said. “The attack is not the only thing organizations have to grapple with; there are follow-on impacts that are significant. If you're an organization that has about 500 employees, your average recovery cost is going to be about $3.1 million. If an attacker is successful in extracting information from your environment, you'll have to deal with the impacts of that.”

Steps to Take

What steps should credit unions take today to prevent an attack? CUToday.info will share those in a follow-up report.

Comments

Popular posts from this blog

Honoring Our Member Credit Unions Ranked Among the Top 100 in 2025

Celebrating Excellence: Honoring Our Member Credit Unions Ranked Among the Top 100 in 2025   Best-performing US credit unions of 2025 At NCOFCU, we take immense pride in the strength, resilience, and impact of our member credit unions. Today, we are thrilled to recognize and celebrate several of our members who have earned a place among the Top 100 Best Performing Credit Unions of 2025 —a testament to their unwavering commitment to service, financial stewardship, and community leadership. This achievement is not just about rankings—it reflects the daily dedication to members, the trust built within communities, and the innovation that continues to drive our movement forward. 🌟 Our Honored Members We proudly congratulate the following institutions for their outstanding performance: #7 – Long Beach Firemen's Credit Union A remarkable top-10 finish that highlights exceptional operational excellence and member value. Long Beach Firemen’s CU continues to set a high bar for perform...

The United States at 250: How the Country Has Changed in the Past 50 Years

  In July, the United States will celebrate its 250th anniversary. The country’s last major milestone was 50 years ago, at its bicentennial on July 4, 1976. U.S. society has changed profoundly since then. Over the past five decades, the U.S. population has  aged significantly,  with the percentage of people 65 and older nearly doubling. The country has also become  more racially and ethnically diverse,  as growing shares of people identify as Asian or Hispanic. And following more than 70 million immigrant arrivals, the percentage of  foreign-born people  in the population has more than tripled.  Americans are also  less likely to be married  than ever before. Women – who now have far more options outside of the home than they did in 1976 – have contributed to a  boom in higher education  and helped  expand the workforce.  And even though many Americans are financially better off than they were 50 years ago,  econ...

Fire Police City County FCU rebrands to reflect company growth

FORT WAYNE, Ind. (WANE) – A federal credit union with a long history in the Fort Wayne area is changing its name to something that the company said Tuesday reflects its ability to serve a larger sector. Fire Police City County Federal Credit Union, founded in 1933, will go by Summit Choice Credit Union starting in April. Members and locals will start to notice new signage and aesthetic changes at each branch throughout the month. The rebranding does not affect the credit union’s structure, ownership, or member accounts, according to the news release. Summit Choice Credit Union remains a member-owned financial cooperative, governed by the same principles and operated by the same team.  Its website  reminds members that new cards are being issued due to the rebranding. The credit union was originally formed for the families of local firefighters. Today, it serves employees of more than 350 local businesses around greater Fort Wayne. “Adopting the name Summit Choice Credi...

The Unique Challenges, Opportunities for CUs in Attracting & Retaining Top Talent

Affinity FCU shares the details of its strategies, including a comprehensive benefits program. By Pam Cohen | September 09, 2024 at 09:00 AM Credit/AdobeStock Attracting and retaining top talent is an ongoing challenge for many organizations, but credit unions face a unique set of obstacles. Unlike larger financial institutions, credit unions often operate with resource constraints and have less brand recognition, which can make it difficult to compete for top-tier talent. Despite these challenges, credit unions have unique strengths that can be leveraged to attract individuals who value a strong sense of community and a supportive work environment. Being Innovative When Growing Talent At Affinity Federal Credit Union, we have implemented several innovative strategies to attract and retain top talent. One key approach is our comprehensive benefits program, which emphasize...

Agencies Issue Exemption Order To Customer Identification Program (CIP) Requirements

WASHINGTON--The Federal Deposit Insurance Corporation, the Office of Comptroller of the Currency, and NCUA, with the concurrence of the Financial Crimes Enforcement Network, issued an order Friday granting an exemption from a requirement of the Customer Identification Program (CIP) Rule implementing Section 326 of the USA PATRIOT Act. The CIP Rule requires a bank or credit union to obtain taxpayer identification number (TIN) information from its customer before opening an account, and the exemption permits a bank or credit union to use an alternative collection method to obtain TIN information from a third-party rather than from the customer, the agencies stated in a joint release. The order applies to accounts at all entities supervised by the agencies. "Since the CIP Rule was issued initially in 2003, there has been a significant evolution in the ways consumers access financial services, along with a rise in reported customer reluctance to provide their full TIN due, in part, to...

Great News From AutoLink

Great news!  AUTOLink has teamed up with SiriusXM! Last month, Auto Link told you about a new benefit coming to our program for your members – a free 3-month trial subscription to SiriusXM.  We are pleased to announce that this benefit will be going live for our credit union clients on December 1 st !   However,  action on your part is needed. This e-mail will briefly explain how the program will work for members, and the options you have for offering this benefit to your auto loan members.  We recommend that someone from your credit union attend one of our upcoming webinars, which will explain the process in greater detail. Read More

NEURAL PAYMENTS Will be in Key West

Neural Payments is a payments engine that simplifies the complex landscape of money movement between diverse financial applications. Neural Payments builds a bridge between payment rails to allow fintechs and financial institutions to deliver seamless commerce for consumers and businesses via a single point of send. This allows money to move between applications and networks in real-time without needing core integration. Stop by their booth in Key West, Florida. Jenn Petry Director Strategic Partnerships | Neural Payments 859.663.7197 | https://neuralpayments.com

What Gen Z Is Really Looking For In A Credit Union

  Gen Z’s faith in traditional institutions gives credit unions a rich opportunity to serve as a key source of financial guidance. Sponsored Content By Adrenaline, Inc. Credit unions can strengthen loyalty with the influential Generation Z by connecting their brand’s purpose, financial guidance, and in-branch experience. Widely described as digital natives, Gen Z meets many of their everyday banking needs with mobile apps and digital tools across multiple providers. While younger consumers certainly expect seamless digital functionality from their primary financial provider, what they value even more is meaningful advice and trusting relationships. Because beneath Gen Z’s technological savvy is a measurable confidence gap —  one that impacts every aspect of their financial lives. According to  Adrenaline’s 2026 Gen Z research  conducted with Alexander Babbage, 36% of Gen Z say they find financial matters confusing, and one in three report feeling overwhelmed by money...

Employers should take note, as company culture starts with professional development.

Employees and employers alike may have thought they understood company culture, and likely did until recently. Coming to work, knowing company values, interacting with others are all no brainers when it comes to the driving forces that make up company culture. Buy a seismic shift is occurring on two fronts. One, various generations are working together in multiple industries and two; the pandemic has changed attitudes about where work can occur and how that may or may not affect culture. The Linkedin Global Trends 2022 report says more freedom to work where and when employees want, as well as attention to wellbeing, are important demands employers need to consider. Consider the numbers: when picking a new job, 63% of professionals put work-life balance as the top priority. Sixty percent are interested in compensation and benefits and 40% say the colleagues and culture they will be working with are their top priorities. Employers should take note as company culture starts with profess...

Fed Gets Green Light for Interest Rate Cuts as Unemployment Rate Jumps to 4-Year High

The Federal Reserve is now seen as likely to   cut interest rates   multiple times before the end of the year, following another weak jobs report that showed unemployment jumping to a four-year high. The U.S. economy added just 22,000 jobs in August, less than economists had expected, the  Bureau of Labor Statistics  reported Friday. The unemployment rate rose to 4.3%, up slightly from 4.2% in July but hitting the highest level seen since October 2021, when the economy was still recovering from pandemic-driven layoffs. Although the new jobs report was troubling news for the economy, for prospective homebuyers with secure jobs it likely means further easing in  mortgage rates  in the days to come. Mortgage rates hinge primarily on the yields of  10-year Treasury notes , which plunged Friday to their lowest level since early April, when President  Donald Trump 's Liberation Day tariff announcement sparked panic in financial markets. It signals furth...