Skip to main content

What You Can Do About Ransomware Threat

By Ray Birch

RANCHO CUCAMONGA, Calif.—In the wake of a ransomware attack that shut down 60 credit unions, cyber security experts are warning many CUs are just one compromised key supplier away from being shut down, too. It’s a growing threat they say can have numerous  downstream effects on many organizations.

No institution is immune, and the best line of defense remains educating employees on how to avoid making mistakes that place a credit union, CUSO or vendor right into the hands of criminals.

“Co-op Solutions views ransomware attacks as an industry-wide threat that will continue for the foreseeable future with two main threat areas of concern,” said Christopher Williams, deputy chief information security officer at Co-op.

Feature Ransomware

The two areas of concern, according to Williams, are Ransomware-as-a-Service (RaaS) models and cyber supply chain threats.

A Proliferating Model

“With the RaaS model, an attacker doesn’t need to develop their own ransomware capability to turn a system compromise into a ransomware attack. This model has proliferated the cybercrime world. The model can quickly incorporate new tactics, techniques and procedures (TTPs) to be used by a wide range of threat actors,” he said. “The second threat area is the cyber supply chain. Attacks against key suppliers have a ripple effect across the supplier’s client-base. Many companies are one compromised key supplier away from a business crippling service impact.”

How to Respond

wlliams

Christopher Williams

Given that growing threat, what should credit unions be doing now?

“Credit unions should continue to educate their employees on the risk of ransomware attacks and the methods used to gain initial unauthorized access,” Williams advised. “Phishing remains a top attack vector, and social engineering of the service or help desk to compromise user credentials is on the rise.”

Credit unions also need to have robust backup capability—restoring to a clean and non-infected copy of system data, Williams added.

“That can help with the recovery of a ransomware attack,” he said. “In addition, they should become active members of the local area U.S. Secret Service Electronic Crimes Task Forces (ECTF) or Financial Crimes Task Forces (FCTF), which can provide advice in preventing attacks and support during suspected or actual attacks. In addition, monitor threat intelligence type sources for indications of attacks against their organizations or their vendors and new TTPs being used by attackers.

“Finally, practice the incident response to a ransomware attack. Drilling the panic and unknowns out of the process will help increase the chance of a successful recovery if an actual attack occurs,” he said.

The Good News? CUs Not Alone

Jim Stickley, CEO of Stickley on Security, said credit unions are one of many industries being affected by ransomware.

“I am not certain that ransomware is specific (to any organization), and credit unions and fintechs are just part of the much bigger picture of the state of ransomware in general,” said Stickley, who is also CEO of Troy, Mich.-based Mahalo Technologies. “Most people have this idea that cybercriminals are targeting a specific business type. While it’s true that healthcare and education are targeted directly and we also see banks and credit unions get targeted, when it comes to more general business, such as fintechs, we have not seen that level of direct attacks. Instead, what you see is employees who fall victim to phishing attacks or malicious websites.”

‘Average’ People, Not an Average Website

Stickley said when those incidents are investigated, what’s all-to-often discovered is that it was a phishing email that had been sent to hundreds of thousands of organizations that is the culprit, often in in the guise of te malicious websites that have been promoted though malvertising to “average” people. 

stickleyJim

Jim Stickley

“In these cases it’s just the low-hanging fruit. If an employee clicks the link, opens the attachment or browses to malicious sites, they open the door to the criminals. The criminals really don’t care if that organization is fintech, credit union or other business segment,” said Stickley, adding adding he does not believe the recent attack that hit DP vendor Fedcomp and than affected 60 credit unions had any company or credit union as a specific target.

“For criminals, there is little need to put a direct focus on fintech at this time since just about every business entity has similar value and so they will continue to cast a very wide net and whoever gets caught up will be their next victim,” he said.

Advice Shared

For credit unions looking to take some practical steps to defend themselves from ransomware, TruStage is sharing some strategies.

“Responding to the immediate threat of a ransomware attack or any cyber incident in a timely manner is critical to minimize data loss, contain the threat and restore operations,” Chris Gill, TruStage senior manager, risk and compliance solutions, told CUToday.info. “This is true even when that threat originates with a credit union’s third-party service provider or partner. Security incidents that do not originate at a credit union can still have a large impact on credit unions’ operations and reputation.”

Noting the affects such attacks have on member service, Gill added, “It reminds us all of the importance of having strong controls in place to minimize exposure, and to have a comprehensive business resiliency plan that is regularly tested and updated.”

Comments

Popular posts from this blog

Syracuse Fire Department Credit Union

Remember, you're not alone with  NCOFCU.org Join/Upgrade Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board

Happy Holidays To All Who Serve

  Happy Holidays To All Who Serve 12/22/2025 10:28 am   By Grant Sheehan and Anthony Hernandez Every year, many Americans celebrate the joy of family and relief from work the holidays bring. Apart from the hustle and bustle, the holiday season is a special time to be with loved ones, engaging in family traditions and rituals, and making memories that will last a lifetime. However, not everyone gets to partake in the holiday gatherings.   There are over a hundred thousand military members serving in harm’s way or in 24-hour command center...

Sunday Reading - The gold standard, explained

  Gold Standard       The gold standard, explained A gold standard is a system where a country’s currency is pegged to, and can be converted into, a fixed amount of gold. It’s typically meant to create a sense of security in the country’s currency: When a government uses a gold standard , its currency can be exchanged for an equivalent amount of gold—although regulations around redemption vary by country.   After the Civil War, in 1873, America adopted the gold standard for the first time. At the time, if gold was priced at $100 an ounce, each dollar  rep...

Is another housing bubble brewing?

While there have been fears expressed by some of a repeat of the housing bubble that led to the housing crisis just over a decade ago, numerous real estate analysts say they believe the market fundamentals are much stronger now and that the sharp increase in home prices reflects low rates, a lack of inventory, and demographics. To be sure, the market is hot in many markets, with home sellers receiving multiple cash offers, often over the listed price, on homes. Some analysts, including those at Swiss banking giant UBS, have published charts showing how home prices are outstripping both wages and rents, reported USA Today. Home prices have appreciated more than 60% since November 2012, incomes have only appreciated by 20% and rents by 30% over the same time period, the report added. “But unlike the real estate boom that led to the Great Recession, this nationwide price spike is not being fueled by a wholesale collapse in lender ethics,” USA Today reported “There aren't any low-doc o...

NAFCU Economist: U.S. Might Dodge Recession

Curt Long said a strong jobs report shows resilience despite the Fed’s escalation in interest rates. By Jim DuPlessis | January 06, 2023 CUTimes Source: Shutterstock. NAFCU Chief Economist Curt Long said Friday the continued strength in the job market has increased the odds the nation will dodge a recession this year. The U.S. Bureau of Labor Statistics reported Friday there were 153.7 million seasonally adjusted jobs in December, an increase of 223,000, or 0.1%, from November and up 3% from a year earlier. The unemployment rate was 3.5% in December, down from 3.6% in November and 3.9% in December 2021. Long said December’s rate was the lowest in more than 50 years, while the labor force participation rate rose slightly. Seasonally adjusted average hourly earnings were $32.82 in December, up 0.3% from November and up 4.6% from a year ago, a slightly lower rate of increase from previous months. Curt Long “This is an unambiguously positiv...

MBA Lowers Mortgage Outlook Through 2023 - The 30-year fixed-rate exceed the 5% mark at 5.13% — the highest since November 2018.

Existing home purchases are likely to fall this year, but higher prices will cause originations to rise slightly. The Mortgage Bankers Association on Wednesday lowered its forecast for both refinance and purchase originations this year and next as interest rates rise faster than it anticipated and expectations rise for more aggressive actions by the Fed to curb inflation. MBA Chief Economist Mike Fratantoni said mortgage rates have risen by more than 1.5 percentage points since Jan. 1. “This rapid increase in rates, caused by a much more rapid pace of rate hikes and balance sheet reduction from the Federal Reserve, is in response to the booming job market and inflation being at a 40-year high,” Fratantoni said. “The jump in mortgage rates will slow the housing market and further reduce refinance demand the rest of this year.” Also on Wednesday, the MBA reported the fifth consecutive drop in its Weekly Mortgage Applications Survey. The number of applications in the week en...

Email and Text Message Etiquette

As we navigate our everyday communications, I want to emphasize the importance of practicing good email and text message etiquette. This enhances clarity and ensures that everyone feels respected and valued in our interactions. Email Etiquette: 1. Use a Clear Subject Line: A subject line that accurately reflects the content of your email will help recipients know what to expect. 2. Greet Appropriately: Start with an appropriate greeting, such as "Dear [Name]", "Hello [Name]," or "Hi [Name], which sets a positive tone. 3. Acknowledge Receipt: If you receive an email that requires a response, action, or information, please acknowledge its receipt. A simple reply confirming that you have received the email helps the sender know their message was received and provides an opportunity to clarify expectations. 4. Be Concise: Keep your emails clear and to the point. Avoid excessive details unless necessary. 5. Professional Language: Use respectful and professional l...

“The July jobs report was almost uniformly positive with strong job gains resulting in a large drop in the unemployment rate,” said NAFCU Chief Economist and Vice President of Research Curt Long.

WASHINGTON–The U.S. economy roared into midsummer with strong gains in hiring, according to the latest jobs report, even as questions remain over the ability to maintain the momentum as the Delta variant of the coronavirus continues to spread. According to numbers released last week by the Labor Department, employers added 943,000 jobs in July. But the number comes with a caveat in that the data was collected in the first half of the month, before variant-related cases exploded in many parts of the United States. “The July jobs report was almost uniformly positive with strong job gains resulting in a large drop in the unemployment rate,” said NAFCU Chief Economist and Vice President of Research Curt Long. “The retail sector did not enjoy a share in the gains, losing over 5,000 jobs during the month, but otherwise gains were broad. This report will add to mounting pressure on the Fed to taper asset purchases.” The numbers marked the best monthly performance since August 2020, and under...

Mortgage Rates Decline to Their Lowest Levels Since April

WASHINGTON–Mortgage rates fell last week to their lowest level since early April. According to Freddie Mac, the standard 30-year fixed-rate mortgage averaged 6.87% in the week ending June 20, which was down from the prior week’s 6.95% average and marks the third consecutive weekly decline. Rates are down from a 2024 peak of 7.22%. “Mortgage rates fell for the third straight week following signs of cooling inflation and market expectations of a future Federal Reserve rate cut,” Sam Khater, Freddie Mac’s chief economist, said in a statement. “These lower mortgage rates coupled with the gradually improving housing supply bodes well for the housing market.” Most economists and forecasters expect rates ...

NCOFCU is working hard for you! Coalition of CU Groups Sends Letter to Congress on Tax Exemption

Take Action Coalition of CU Groups Sends Letter to Congress on Tax Exemption May 1, 2025 10:15 am No Comments WASHINGTON–A coalition of credit union organizations has sent a joint letter to Congress in support of the credit union tax exemption. As the CU Daily has been regularly reporting, credit unions are especially  concerned this year that Congress might revoke the tax exemption as it seeks ways to pay for expiring provisions of the 2017 tax cuts, which President Trump wants to see renewed. Sending the letter to Congress were the Defense Credit Union Council (DCUC), America’s Credit Unions (ACU), Credit Union Executive Society (CUES), National Association of Credit Union Chairs (NACUC), National Credit Union Management Association (NCUMA), Inclusiv, TruStage, Earnest Consulting Group (ECG), Callahan and Associates, National Council of Firefighter Credit Unions (NCOFCU), Metropolitan Area Credit Union Management Association (MACUMA), Association of Credit Union Audit and Ri...