Skip to main content

What You Can Do About Ransomware Threat

By Ray Birch

RANCHO CUCAMONGA, Calif.—In the wake of a ransomware attack that shut down 60 credit unions, cyber security experts are warning many CUs are just one compromised key supplier away from being shut down, too. It’s a growing threat they say can have numerous  downstream effects on many organizations.

No institution is immune, and the best line of defense remains educating employees on how to avoid making mistakes that place a credit union, CUSO or vendor right into the hands of criminals.

“Co-op Solutions views ransomware attacks as an industry-wide threat that will continue for the foreseeable future with two main threat areas of concern,” said Christopher Williams, deputy chief information security officer at Co-op.

Feature Ransomware

The two areas of concern, according to Williams, are Ransomware-as-a-Service (RaaS) models and cyber supply chain threats.

A Proliferating Model

“With the RaaS model, an attacker doesn’t need to develop their own ransomware capability to turn a system compromise into a ransomware attack. This model has proliferated the cybercrime world. The model can quickly incorporate new tactics, techniques and procedures (TTPs) to be used by a wide range of threat actors,” he said. “The second threat area is the cyber supply chain. Attacks against key suppliers have a ripple effect across the supplier’s client-base. Many companies are one compromised key supplier away from a business crippling service impact.”

How to Respond

wlliams

Christopher Williams

Given that growing threat, what should credit unions be doing now?

“Credit unions should continue to educate their employees on the risk of ransomware attacks and the methods used to gain initial unauthorized access,” Williams advised. “Phishing remains a top attack vector, and social engineering of the service or help desk to compromise user credentials is on the rise.”

Credit unions also need to have robust backup capability—restoring to a clean and non-infected copy of system data, Williams added.

“That can help with the recovery of a ransomware attack,” he said. “In addition, they should become active members of the local area U.S. Secret Service Electronic Crimes Task Forces (ECTF) or Financial Crimes Task Forces (FCTF), which can provide advice in preventing attacks and support during suspected or actual attacks. In addition, monitor threat intelligence type sources for indications of attacks against their organizations or their vendors and new TTPs being used by attackers.

“Finally, practice the incident response to a ransomware attack. Drilling the panic and unknowns out of the process will help increase the chance of a successful recovery if an actual attack occurs,” he said.

The Good News? CUs Not Alone

Jim Stickley, CEO of Stickley on Security, said credit unions are one of many industries being affected by ransomware.

“I am not certain that ransomware is specific (to any organization), and credit unions and fintechs are just part of the much bigger picture of the state of ransomware in general,” said Stickley, who is also CEO of Troy, Mich.-based Mahalo Technologies. “Most people have this idea that cybercriminals are targeting a specific business type. While it’s true that healthcare and education are targeted directly and we also see banks and credit unions get targeted, when it comes to more general business, such as fintechs, we have not seen that level of direct attacks. Instead, what you see is employees who fall victim to phishing attacks or malicious websites.”

‘Average’ People, Not an Average Website

Stickley said when those incidents are investigated, what’s all-to-often discovered is that it was a phishing email that had been sent to hundreds of thousands of organizations that is the culprit, often in in the guise of te malicious websites that have been promoted though malvertising to “average” people. 

stickleyJim

Jim Stickley

“In these cases it’s just the low-hanging fruit. If an employee clicks the link, opens the attachment or browses to malicious sites, they open the door to the criminals. The criminals really don’t care if that organization is fintech, credit union or other business segment,” said Stickley, adding adding he does not believe the recent attack that hit DP vendor Fedcomp and than affected 60 credit unions had any company or credit union as a specific target.

“For criminals, there is little need to put a direct focus on fintech at this time since just about every business entity has similar value and so they will continue to cast a very wide net and whoever gets caught up will be their next victim,” he said.

Advice Shared

For credit unions looking to take some practical steps to defend themselves from ransomware, TruStage is sharing some strategies.

“Responding to the immediate threat of a ransomware attack or any cyber incident in a timely manner is critical to minimize data loss, contain the threat and restore operations,” Chris Gill, TruStage senior manager, risk and compliance solutions, told CUToday.info. “This is true even when that threat originates with a credit union’s third-party service provider or partner. Security incidents that do not originate at a credit union can still have a large impact on credit unions’ operations and reputation.”

Noting the affects such attacks have on member service, Gill added, “It reminds us all of the importance of having strong controls in place to minimize exposure, and to have a comprehensive business resiliency plan that is regularly tested and updated.”

Comments

Popular posts from this blog

NCUA Board Approves 11 Final Rules for Deregulation Project

Alexandria, VA (August 5, 2026) ― The National Credit Union Administration (NCUA) today finalized eleven rules that were proposed for changes through the Deregulation Project. This is the first round of final rules from the ongoing Deregulation Project which is an initiative to review NCUA’s regulations and ensure they are focused on credit unions’ safety, soundness, and resilience. The final rules include: This is an external link to a website belonging to another federal agency, private organization, or commercial entity. Surety and Guarantor Requirements – 12 CFR 701.20(c)(3) and 701.20(d) (Opens new window) This is an external link to a website belonging to another federal agency, private organization, or commercial entity. Limits on Loan to Other Credit Unions – 12 CFR 701.25(b) (Opens new window) This is an external link to a website belonging to another federal agency, private organization, or commercial entity. Service to Underserved Areas – IRPS 08-2 (Opens new window) This is...

Making the Most of the Final Five Years Before Retirement

  NATIONAL COUNCIL OF FIRST RESPONDER CREDIT UNIONS RETIREMENT READINESS Making the Most of the Final Five Years Before Retirement A practical planning guide for first responders, credit union volunteers, employees, and their families Five years before retirement is an important checkpoint. It is the time to confirm what you have saved, understand the income you can expect, and decide whether your retirement plans match the life you want to lead.   1. Review Your Retirement Savings Start by taking a fresh look at your retirement accounts, personal savings, investments, and other assets. A retirement calculator can help estimate whether you are on track and show how additional saving during the next five years may strengthen your plan.   2. Identify Every Source of Retirement Income List the income you may receive in retirement, including pensions, Social Security, retirement-plan withdrawals, invest...

Senate, 51-47, has confirmed John Crews to the NCUA board

WASHINGTON—The U.S. Senate, 51-47, has confirmed John Crews to the NCUA board, clearing the way for him to succeed Kyle Hauptman and return the agency to a single-member board following the Trump Administration's removal of Democratic board members Todd Harper and Tanya Otsuka earlier this year. Maintaining the foundational stability of the credit union system Supporting efficient, risk-based regulation that accounts for institutional size and operational differences Preparing for technological advancement while safeguarding member assets Encouraging the growth of new credit unions to serve underbanked and military communities Preserving an open, accessible, and collaborative dialogue between the NCUA and the credit union movement Crews, who most recently served in the Treasury Department, has said his priorities include reducing regulatory burden for smaller credit unions, encouraging innovation and supporting the chartering of new credit unions, while maintaining the safety and s...

What’s Ahead for U.S. Economy? Here’s What One Former Fed Chair is Saying

 WASHINGTON–Former Federal Reserve Chairman Ben Bernanke, who headed the central bank during the 2008 financial crisis, is now warning that the United States is headed for a situation similar to that of the 1970s, when Americans were losing their jobs but still facing higher prices at the grocery store and at the pump. Ben Bernanke “Even under the benign scenario, we should have a slowing economy,” Bernanke told the New York Times in an interview in conjunction with his new book, “ 21st Century Monetary Policy: The Federal Reserve From the Great Inflation to Covid-19 ,” which is scheduled to publish today. “So, there should be a period in the next year...

Fed Governors Signal Smaller Rate Increases Coming

WASHINGTON–There is a growing chorus among Federal Reserve governors that the central bank will be slowing it pace of rate increases when the Federal Open Markets Committee meets next on Feb. 1. Christopher Waller Among those who have signaled the days of 50 - and 75-basis point increases are over is Federal Reserve Governor Christopher Waller, who said he believes it’s time to slow the pace of increases—but not eliminate them. If the forecast proves true, it will mark the end of the rapid increases that took place during 2022 as the Fed sought to tamp down high inflation. Central bankers are now “entering a new phase that is focused more on how high-inter...

NCUA"s new video module provides best practices for merging

The three-part video module provided by NCUA, available online   here , examines current trends in mergers, when a credit union board should consider a merger and how to negotiate a merger agreement that best serves the credit union’s interests. Every credit union should discuss the possibilities of a future merger in their strategic planning.

Credit Union Auto Loans Take a Slight Dip, Catalyst Strategist Says

Credit union vehicle loans outstanding have dropped 2.2% so far in 2012 but lending activity is still higher than it was a year ago..... Credit Union Auto Loans Take a Slight Dip, Catalyst Strategist Says :

Mobile Payments on the Rise

Firefighter credit unions cannot afford to miss out on this rapidly growing part of the financial services industry. By 2017, mobile commerce revenue will make up 50% of U.S. digital revenue. See complete story  HERE Source; CreditUnions.com

Cyber Security in Today's Credit Unions

"Credit unions and CUSOs that are quick to point to the strength of their firewalls are correct, said Stickley—those firewalls are excellent at keeping outsiders outside. The problem is the cybercrime is taking place due to insiders opening the door and letting scammers do their damage from the inside.  “If you look at every single breach today--Anthem, Home Depot, Target–I guarantee you every one started with an email, and that started the ball rolling to get the breach to happen. Email is the bane of your existence. Email is extremely dangerous to you, your organization and all your members.” So why email?  “Attacking a network via the Internet is hard,” said Stickley. “And employees have access to everything.  If I can gain access to an employee’s desktop or credentials, breaking in becomes much easier.”" Read complete article at: LinkedIn? Should be 'Let Them In' / THE boost / CUToday.info - CU Today :