Skip to main content

'Anatomy' Of A Ransomware Attack

By Ray Birch

BALTIMORE—Credit unions should brace for almost a month of major problems if they’re victimized by a ransomware attack, according to one cybersecurity expert, whose insights into the “anatomy” of a ransomware attack are coming at the same time nearly 60 CUs are currently trying to restore their own operations.

As those credit unions have come to learn, it takes on average 22 days to get through a ransomware attack and get to the other side, that same expert stated.

That information and additional insights were shared during a webinar hosted by cybersecurity firm Think/Stack, which that was held to provide CUs with insights and answers regarding ransomware in light of the recent attack that that continues to affect those five-dozen CUs hit by an attack on a common vendor.

Feature Ransomware Webinar 1

“We're all being targeted, and this (recent attack) could have happened to anybody,” said Cal Bowman, Think/Stack VP of client innovation and strategy, referring to an attack on the CUSO Ongoing Operations that in turn affected the data processor Fedcomp. “So, it's really important we all recognize that every one of you here has vendors, has partners that are vulnerable. Therefore, the question is, are you ready to respond to any type of large-scale event that really can cripple your organization?”

What’s Been Learned

bowman

Bowman said a goal of the webinar, which was attended by more than 300 credit unions, was to walk through what happens during a ransomware attack and share what his company has learned supporting CUs that have been victimized by such attacks.

Think/Stack VP of Security and Risk Jennifer Anthony said when a ransomware attack occurs in an organization it frequently creates the “fog of war.”

“What you will see in a generalized ransomware attack is the tactical and technical pieces that begin to happen over the first couple days,” Anthony explained.

But at the same time a credit union is seeking to find a tactical path through that fog, the emotional side of the battle must be given attention, as employees struggle to get the CU operating again, Anthony said.

“There is confusion and concern,” she said. “Maybe someone can't get on to a system they previously could access. Maybe there's a service that's not working and folks are starting to feel confused about what's going on. All this is happening as your technical teams in the background are beginning to quickly investigate the source of the problem.”

Anthony emphasized a credit union involved in a ransomware attack should be prepared to spend at least three weeks dealing with it.  

The Internal Threat

As CUToday.info has reported and as credit unions are frequently warned, ransomware attacks often occur due to an employee opening the door by falling for a phishing scam or downloading a file they believe to be safe.

“This is a function of human performance,” she noted. “We all begin to look for who's at fault, who did something they were not supposed to do that caused this. What we tell organizations is that when you get caught in that space, you should not spend a lot of time trying to figure out who to point the finger at, (but instead spend) time trying to figure out how to get out of the situation.”

Not surprisingly, Anthony described the working environment following an attack as “chaotic.”

‘Everyone’s Scared’

“Everyone's scared. We're not sure what's going on and maybe we have members who are really angry. Maybe we have board members that are really angry, or leaders that are really angry,” she said. “The goal at this point is to figure out how to get past it. We'll figure out who's to blame or what's to blame, or how we can prevent it in the future at a later point.”

It's an issue credit unions should take seriously, according to Anthony, who said there is a growing ransomware threat to the not-for-profit co-ops.

“In the last seven months we worked with six credit unions who individually found themselves in this space,” she said. “This is something that's happening on a regular basis, across all industries.”

Anthony reminded that as the credit union moves through a ransomware incident many employees will be feelin remorse and concern over fellow workers in IT who are working feverishly to restore operations.

“They feel like they are at fault for what is going on, and that is a very difficult place to be,” she said. “The technical teams are trying to figure out how to remediate the situation. I've been in organizations where technical teams are working nonstop, around the clock, for days and days. The credit union then is trying to figure out how do we feed people? How are we going to send people home to sleep so they can come back and be effective—because you are in this fight for a long time and there is a lot of pressure on everyone.”

Like Being in a Battle

Anthony likened the experience to those who fight in a war.

“I spent 20 years in the in the United States military, and this is a roller coaster akin to what a service member might experience in their daily lives—and this can be traumatic,” she said.

anthony

She urged credit unions to consider where they are vulnerable.  

“We know 93% of ransomware attacks are in Windows-based environment,” she said. “If we listed them in order of frequency of occurrence, how they occur, here's what they would be: Number one is e-mail phishing campaigns. Number two would be (remote desktop protocol or RDP) vulnerabilities. And number three would be software vulnerabilities.”

The Long-Term Affects

While those 22 days are the typical time from attack to restoration of service, Anthony said the repercussions are felt for many months afterward.

“With the recovery efforts and return to operation, the average time for an organization to move through that is about nine months,” she said. “The attack is not the only thing organizations have to grapple with; there are follow-on impacts that are significant. If you're an organization that has about 500 employees, your average recovery cost is going to be about $3.1 million. If an attacker is successful in extracting information from your environment, you'll have to deal with the impacts of that.”

Steps to Take

What steps should credit unions take today to prevent an attack? CUToday.info will share those in a follow-up report.

Comments

Popular posts from this blog

Why Decision Intelligence Will be What Really Defines the Future of Credit Union Growth

By Alisha Crafton For years, credit union marketing has been built around a familiar formula: understand your members, segment your audiences, develop targeted campaigns, and deliver the right message through the right channel to the right audience.  Although that approach still matters, it is relationships that serve as the foundation of the credit union model. The challenge for every credit union is that member expectations, competitive pressures, and technological capabilities are changing rapidly. Members increasingly expect financial institutions to understand their needs, anticipate life events, and provide relevant guidance at the right moment. Meeting those expectations requires more than better campaigns. It requires better decision-making. The future of credit union growth will not be defined by who can create more content, launch more campaigns, or automate more emails. It will be defined by which institutions can interpret information more effectively, identify opportun...

Report Probes Just How Sophisticated and Pervasive Fraud Has Become

BOSTON–Fraud threats facing credit unions are becoming more sophisticated and pervasive as digital banking expands and artificial intelligence tools enable increasingly complex attacks, according to new research and analysis from PYMNTS Intelligence .  The report said fraud has evolved from isolated incidents into a “persistent, systemwide threat” that affects every stage of the member journey, from onboarding and authentication to transactions and account servicing.  According to the report, fraudsters are increasingly using coordinated, multichannel schemes that challenge traditional fraud detection and response systems. PYMNTS Intelligence said attackers are no longer exploiting single vulnerabilities but are instead orchestrating broader campaigns involving impersonation, credential theft and unauthorized transfers.  The Findings Among the report’s findings, according to PYMNTS: One in 10 consumers encountered card fraud during the past year. Most fraud incidents occu...

NCUA Board Nominee John Crews Moves to Full Senate

  WASHINGTON–By a voice vote, the Senate Banking, Housing, and Urban Affairs Committee has advanced to the Senate floor the nomination of John Crews to become the next chairman of NCUA. John Crews “Credit unions thank Chairman Scott and the members of the Senate Banking Committee for advancing John Crews nomination to the NCUA Board,” America’s Credit Unions Chief Advocacy Officer Kathleen Coulombe said in a statement. “We appreciate that the Committee recognizes a robust credit union industry requires a fully staffed NCUA Board and John Crews possesses the necessary experience and knowledge to efficiently lead the NCUA. We urge the Senate to quickly vote to confirm his nomination.” About John Crews Crews is the assistant secretary for financial institutions policy in the Treasury department. Crews was appointed to the position in mid-2025 and has a long history in Washington. Prior to joining the Treasury Department, he served as a policy advisor to Majority Leader Rep. Steve Scal...

More Consumers Turning to Digital Wallets to Manage Finances

BOSTON — Consumers facing financial pressure are increasingly turning to digital wallets not only for convenience, but also as a way to better manage their household finances, according to a new report from PYMNTS Intelligence . The report, titled “ The New Checkout: Crimped Consumers Lean Into Online Retail and Digital Wallets, ” is based on a survey of 2,108 U.S. adults and found digital wallet adoption is growing fastest among younger consumers and those experiencing financial stress. According to PYMNTS Intelligence, digital wallets are evolving beyond simple payment tools by offering features such as buy now, pay later options, real-time balance information and spending management tools that help consumers monitor their finances. Source: PYMNTS Intelligence Among consumers experiencing high financial stress, 28% said they used a digital wallet for their most recent retail purchase, compared with 11% of consumers reporting low financial stress. For grocery purchases, 21% of financi...

Unemployment 101

   Unemployment 101    For millions of Americans , the prospect of becoming unemployed is a persistent source of financial anxiety. The US unemployment rate, or the percentage of people in the labor force who are actively looking for work but aren't currently employed, has long been considered an economic bellwether. Many economists agree that a rate between 4% and 5% is considered healthy. As of June 2026, the US unemployment rate was 4.2%. > Learn how the unemployment rate is calculated. ( More ) > The US Bureau of Labor Statistics' monthly jobs report tracks the unemployment rate and more. ( More ) Americans who are unemployed for up to 26 weeks ...

Coffee Consumption Guidance

Most adults can safely drink  up to five 8-ounce cups of black coffee per day, and regular consumption may improve cardiovascular health, the American Heart Association said yesterday. An analysis of recent studies suggests that consuming about 400 milligrams of caffeine daily may lower the risk of Type 2 diabetes, stroke, heart disease, and heart failure. However, because most research is observational, scientists are still unsure why caffeine may benefit heart health. Some studies suggest antioxidants  in coffee help reduce inflammation, indicating not all caffeine sources offer the same effects. Synthetic caffeine products, such as energy drinks, have been linked to a higher risk of high blood pressure and irregular heart rhythms. Coffee's benefits also diminish when sugar and high-fat creamers are added.  Brewing methods may matter, too. Cardiovascular benefits have been linked most strongly to paper-filtered or instant coffee. Unfilter...

2026 Volunteer of the Year Award

  www.ncofcu.org/voy ================================================= Remember, you're not alone with NCOFCU.org Join/Upgrade Check out some of NCOFCU's additional features: Advocacy   Annual Conference First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's

Sunday Reading - The Fab Four (Beatles)

  The Fab Four   The Beatles were a 20th-century British band credited with innovating the sound of popular music and, in the process, helping to legitimize rock 'n' roll as an art form. > How the Beatles became the most influential band on Earth. ( More , w/podcast) > Explore Abbey Road Studios, the site of the first ever stereo recordings and home to most of the Beatles' songs. ( More ) The intense fandom for the band, called Beatlemania, began in the United Kingdom in 1963 but did not initially translate into success in the United States. In fact, the band's American label rejected the band's first two singles. Eventually, the band gained tra...

LA County firefighters help each other cope with toughest part of the job

This is an excellent program, and no matter what size your department is, you should be prepared. Scott Ross  talks over issues with Firefighter Richard Conejo who was recently affected by the death of a fellow firefighter . They meet under the auspices of the LA County Fire Department's Peer Support Program. **** Read More ; LA County <b>firefighters</b> help each other cope with toughest part of the job :

Management Team of New Trade Group, America's Credit Unions, is Named

 WASHINGTON–The management team for the new trade group that is being created by the merger of CUNA and NAFCU on Jan. 1 has been named. Jim Nussle, the current CUNA CEO who is to also be CEO of the trade group America’s Credit Unions, has named six people who will lead the organization.  They include: Jill Tomalin, executive vice president.  Tomalin is currently EVP and COO with CUNA, and has Tomalin has more than 30 years of experience within credit unions. Tomalin will oversee membership and engagement, communications and marketing, operations and finance, and association services. Carrie Hunt, chief advocacy officer . Hunt is currently president and CEO of the Virginia Credit Union League and prior to that had a long career as an executive at NAFCU. Overall, Hunt has more than 20 years of experience in consumer finance and financial services law, credit union regulations, and association lobbying.  Anthony Demangone, chief membership and engagem...