Skip to main content

What You Can Do About Ransomware Threat

By Ray Birch

RANCHO CUCAMONGA, Calif.—In the wake of a ransomware attack that shut down 60 credit unions, cyber security experts are warning many CUs are just one compromised key supplier away from being shut down, too. It’s a growing threat they say can have numerous  downstream effects on many organizations.

No institution is immune, and the best line of defense remains educating employees on how to avoid making mistakes that place a credit union, CUSO or vendor right into the hands of criminals.

“Co-op Solutions views ransomware attacks as an industry-wide threat that will continue for the foreseeable future with two main threat areas of concern,” said Christopher Williams, deputy chief information security officer at Co-op.

Feature Ransomware

The two areas of concern, according to Williams, are Ransomware-as-a-Service (RaaS) models and cyber supply chain threats.

A Proliferating Model

“With the RaaS model, an attacker doesn’t need to develop their own ransomware capability to turn a system compromise into a ransomware attack. This model has proliferated the cybercrime world. The model can quickly incorporate new tactics, techniques and procedures (TTPs) to be used by a wide range of threat actors,” he said. “The second threat area is the cyber supply chain. Attacks against key suppliers have a ripple effect across the supplier’s client-base. Many companies are one compromised key supplier away from a business crippling service impact.”

How to Respond

wlliams

Christopher Williams

Given that growing threat, what should credit unions be doing now?

“Credit unions should continue to educate their employees on the risk of ransomware attacks and the methods used to gain initial unauthorized access,” Williams advised. “Phishing remains a top attack vector, and social engineering of the service or help desk to compromise user credentials is on the rise.”

Credit unions also need to have robust backup capability—restoring to a clean and non-infected copy of system data, Williams added.

“That can help with the recovery of a ransomware attack,” he said. “In addition, they should become active members of the local area U.S. Secret Service Electronic Crimes Task Forces (ECTF) or Financial Crimes Task Forces (FCTF), which can provide advice in preventing attacks and support during suspected or actual attacks. In addition, monitor threat intelligence type sources for indications of attacks against their organizations or their vendors and new TTPs being used by attackers.

“Finally, practice the incident response to a ransomware attack. Drilling the panic and unknowns out of the process will help increase the chance of a successful recovery if an actual attack occurs,” he said.

The Good News? CUs Not Alone

Jim Stickley, CEO of Stickley on Security, said credit unions are one of many industries being affected by ransomware.

“I am not certain that ransomware is specific (to any organization), and credit unions and fintechs are just part of the much bigger picture of the state of ransomware in general,” said Stickley, who is also CEO of Troy, Mich.-based Mahalo Technologies. “Most people have this idea that cybercriminals are targeting a specific business type. While it’s true that healthcare and education are targeted directly and we also see banks and credit unions get targeted, when it comes to more general business, such as fintechs, we have not seen that level of direct attacks. Instead, what you see is employees who fall victim to phishing attacks or malicious websites.”

‘Average’ People, Not an Average Website

Stickley said when those incidents are investigated, what’s all-to-often discovered is that it was a phishing email that had been sent to hundreds of thousands of organizations that is the culprit, often in in the guise of te malicious websites that have been promoted though malvertising to “average” people. 

stickleyJim

Jim Stickley

“In these cases it’s just the low-hanging fruit. If an employee clicks the link, opens the attachment or browses to malicious sites, they open the door to the criminals. The criminals really don’t care if that organization is fintech, credit union or other business segment,” said Stickley, adding adding he does not believe the recent attack that hit DP vendor Fedcomp and than affected 60 credit unions had any company or credit union as a specific target.

“For criminals, there is little need to put a direct focus on fintech at this time since just about every business entity has similar value and so they will continue to cast a very wide net and whoever gets caught up will be their next victim,” he said.

Advice Shared

For credit unions looking to take some practical steps to defend themselves from ransomware, TruStage is sharing some strategies.

“Responding to the immediate threat of a ransomware attack or any cyber incident in a timely manner is critical to minimize data loss, contain the threat and restore operations,” Chris Gill, TruStage senior manager, risk and compliance solutions, told CUToday.info. “This is true even when that threat originates with a credit union’s third-party service provider or partner. Security incidents that do not originate at a credit union can still have a large impact on credit unions’ operations and reputation.”

Noting the affects such attacks have on member service, Gill added, “It reminds us all of the importance of having strong controls in place to minimize exposure, and to have a comprehensive business resiliency plan that is regularly tested and updated.”

Comments

Popular posts from this blog

Sunday Reading - Landmine Rat Honored

  Landmine Rat Honored   Cambodia unveiled the world’s first statue honoring a landmine-detecting rat (w/photo) Friday. Magawa the rat lived to 8 years old and identified more than 100 landmines and other explosives from 2016 to 2021.  There are more than 100 African pouched rats deployed in landmine detection operations across the world. To identify mines, the rats are trained to sniff out explosive compounds like trinitrotoluene, or TNT. (The rats are not heavy enough to trigger detonation.) In Cambodia, up to 6 million landmines remain undiscovered, most planted during three decades of conflict, from the Vietnam War era through Cambodia's civil war . Since 1979, roughly 20,000 people have been killed in Cambodia, and roughly 40,000 wounded as a result of the mines. Magawa cleared more than ...

NCUA Board briefed on four topics

The NCUA Board heard briefings on four topics during its meeting Thursday, including the status of the deregulation initiative, a clarification regarding existing rules applicable to brokered and reciprocal deposit arrangements, and the agency’s 2026-2030 Strategic Plan and 2026 Annual Performance Plan.   Acting Director of the Office of Examination and Insurance Amanda Parkhill provided an overview of Phase 1 of the agency’s Deregulation Project, which focuses on targeted, technical changes to remove outdated or unnecessary requirements and improve clarity. The agency made it clear that the effort will likely continue into late 2026 or early 2027, evolving over time based on policy priorities and stakeholder input.   NCUA General Counsel Frank Kressman briefed the board on brokered and reciprocal deposit arrangements and the NCUA’s FAQs on this topic. The briefing demonstrated how a brokered deposit network operates with respect to low-income designated (LID) FICUs ...

How Your Bank/Credit Union Can Fight ‘Soft Switching’ — and Even Steal a Few Accounts of Your Own

Your Members Aren't Leaving in a Huff, They're Just Fading Away. Here's How to Stop It. “Soft switching” is picking up as Americans’ financial activity continues to fragment among multiple players, according to new research from JD Power. This trend has implications both for banks and credit unions that want to retain and grow existing relationships, as well as those that would also like to expand by snapping up accounts from other institutions. Key risk:  Once someone establishes a relationship with another provider, their one-time primary financial institution risks slipping into second place — or even losing the relationship entirely. Need to Know: The average checking account customer now has three deposit accounts at different institutions, the study found. One out of five consumers moved money away from their primary financial institution in the past three months, according to the study, an increase over the 17% rate seen in the previous edition. Departures aren’t sud...

The Case for Sharing a CEO Between Credit Unions

  Embracing Collaboration: The Case for Sharing a CEO Between Credit Unions In recent years, credit unions have faced numerous challenges, from regulatory pressures to evolving member expectations. As many seasoned leaders retire, smaller credit unions often find themselves at a turning point. In this landscape, one innovative solution is gaining traction: sharing a CEO between two credit unions. This approach not only addresses financial constraints but also fosters collaboration and enhances service delivery. The Rationale Behind Sharing a CEO 1. Financial Sustainability One of the most pressing concerns for small credit unions is maintaining financial health amid rising operational costs. A shared CEO model alleviates the financial burden of hiring and compensating a full-time executive. By splitting salary and benefits, both credit unions can allocate resources more effectively, allowing for investment in member services, technology, and community initiatives. ...

Reading Up On Recessions

  Reading Up On Recessions       Background Stemming from the Latin word “recessus” (meaning “a retreat”), recessions are  sustained periods  of declining activity in a country’s economy. During a recession, unemployment rises while economic output falls across a large swath of industries. Recessions are inevitable in modern economies, with one occurring about every six to seven years ( What causes recessions ?).   One common definition of a recession is when a country logs two consecutive quarters of shrinking gross domestic product, but in practice, ...

Sunday Reading - The gold standard, explained

  Gold Standard       The gold standard, explained A gold standard is a system where a country’s currency is pegged to, and can be converted into, a fixed amount of gold. It’s typically meant to create a sense of security in the country’s currency: When a government uses a gold standard , its currency can be exchanged for an equivalent amount of gold—although regulations around redemption vary by country.   After the Civil War, in 1873, America adopted the gold standard for the first time. At the time, if gold was priced at $100 an ounce, each dollar  rep...

Open Banking Pushes Leading Credit Unions Ahead In Race For Member Loyalty

  https://youtu.be/pUIV8hwSDCE NEW YORK—Credit unions that embrace open banking aren’t just keeping pace with competitors—they’re pulling ahead, new data show. A new report finds that innovation in digital tools and personalized experiences is emerging as the decisive factor separating credit unions that win lasting member loyalty from those at risk of losing ground. “ The 2025 Credit Union Innovation Readiness Index: Closing Gaps, Winning Members ,” a June report produced in collaboration between  Velera  and PYMNTS Intelligence, underscores innovation as a defining factor for credit union success. iStock-Korakrich Suntornnites “Facing shifting expectations from both consumers and small to medium-sized businesses (SMBs) toward digital convenience and tailored experiences, credit unions must modernize not just to compete with traditional banks, but to remain relevant to their members. The report, based surveys of 500 credit union executives, 15,000 U.S. consumers, and nea...

Long-Stalled Credit Card Competition Act Moves Forward In Senate Clarity Act Markup

WASHINGTON—A long-stalled bipartisan push to boost competition in the credit card market moved closer to becoming law late Friday, as Sens. Roger Marshall (R-KS) and Dick Durbin (D-IL) advanced a new amendment attached to the Senate Agriculture Committee’s markup of the Digital Asset Market Structure and Investor Protection Act, commonly known as the Clarity Act. Dick Durbin The amendment, a core component of the long-debated Credit Card Competition Act, would prohibit major credit-card networks and large issuing banks from enforcing network exclusivity on credit cards. Supporters argue the measure would expand transaction-routing competition, weaken the dominance of the largest payment networks, and reduce swipe fees that merchants say inflate consumer prices. The renewed momentum reflects President Trump’s recent backing of efforts to rein in credit card costs, a shift that has altered the political trajectory of legislation that has struggled to advance in prior Congresses. With Tru...

USPS Defends Banking Pilot, While Opponents Call It Illegal

  By David Baumann - July 11, 2022 Program has faced opposition from the outset, including from credit union groups, and has struggled to gain real traction. The U.S. Postal Service (USPS) argued this week that the controversial pilot program it is operating i...