Skip to main content

What You Can Do About Ransomware Threat

By Ray Birch

RANCHO CUCAMONGA, Calif.—In the wake of a ransomware attack that shut down 60 credit unions, cyber security experts are warning many CUs are just one compromised key supplier away from being shut down, too. It’s a growing threat they say can have numerous  downstream effects on many organizations.

No institution is immune, and the best line of defense remains educating employees on how to avoid making mistakes that place a credit union, CUSO or vendor right into the hands of criminals.

“Co-op Solutions views ransomware attacks as an industry-wide threat that will continue for the foreseeable future with two main threat areas of concern,” said Christopher Williams, deputy chief information security officer at Co-op.

Feature Ransomware

The two areas of concern, according to Williams, are Ransomware-as-a-Service (RaaS) models and cyber supply chain threats.

A Proliferating Model

“With the RaaS model, an attacker doesn’t need to develop their own ransomware capability to turn a system compromise into a ransomware attack. This model has proliferated the cybercrime world. The model can quickly incorporate new tactics, techniques and procedures (TTPs) to be used by a wide range of threat actors,” he said. “The second threat area is the cyber supply chain. Attacks against key suppliers have a ripple effect across the supplier’s client-base. Many companies are one compromised key supplier away from a business crippling service impact.”

How to Respond

wlliams

Christopher Williams

Given that growing threat, what should credit unions be doing now?

“Credit unions should continue to educate their employees on the risk of ransomware attacks and the methods used to gain initial unauthorized access,” Williams advised. “Phishing remains a top attack vector, and social engineering of the service or help desk to compromise user credentials is on the rise.”

Credit unions also need to have robust backup capability—restoring to a clean and non-infected copy of system data, Williams added.

“That can help with the recovery of a ransomware attack,” he said. “In addition, they should become active members of the local area U.S. Secret Service Electronic Crimes Task Forces (ECTF) or Financial Crimes Task Forces (FCTF), which can provide advice in preventing attacks and support during suspected or actual attacks. In addition, monitor threat intelligence type sources for indications of attacks against their organizations or their vendors and new TTPs being used by attackers.

“Finally, practice the incident response to a ransomware attack. Drilling the panic and unknowns out of the process will help increase the chance of a successful recovery if an actual attack occurs,” he said.

The Good News? CUs Not Alone

Jim Stickley, CEO of Stickley on Security, said credit unions are one of many industries being affected by ransomware.

“I am not certain that ransomware is specific (to any organization), and credit unions and fintechs are just part of the much bigger picture of the state of ransomware in general,” said Stickley, who is also CEO of Troy, Mich.-based Mahalo Technologies. “Most people have this idea that cybercriminals are targeting a specific business type. While it’s true that healthcare and education are targeted directly and we also see banks and credit unions get targeted, when it comes to more general business, such as fintechs, we have not seen that level of direct attacks. Instead, what you see is employees who fall victim to phishing attacks or malicious websites.”

‘Average’ People, Not an Average Website

Stickley said when those incidents are investigated, what’s all-to-often discovered is that it was a phishing email that had been sent to hundreds of thousands of organizations that is the culprit, often in in the guise of te malicious websites that have been promoted though malvertising to “average” people. 

stickleyJim

Jim Stickley

“In these cases it’s just the low-hanging fruit. If an employee clicks the link, opens the attachment or browses to malicious sites, they open the door to the criminals. The criminals really don’t care if that organization is fintech, credit union or other business segment,” said Stickley, adding adding he does not believe the recent attack that hit DP vendor Fedcomp and than affected 60 credit unions had any company or credit union as a specific target.

“For criminals, there is little need to put a direct focus on fintech at this time since just about every business entity has similar value and so they will continue to cast a very wide net and whoever gets caught up will be their next victim,” he said.

Advice Shared

For credit unions looking to take some practical steps to defend themselves from ransomware, TruStage is sharing some strategies.

“Responding to the immediate threat of a ransomware attack or any cyber incident in a timely manner is critical to minimize data loss, contain the threat and restore operations,” Chris Gill, TruStage senior manager, risk and compliance solutions, told CUToday.info. “This is true even when that threat originates with a credit union’s third-party service provider or partner. Security incidents that do not originate at a credit union can still have a large impact on credit unions’ operations and reputation.”

Noting the affects such attacks have on member service, Gill added, “It reminds us all of the importance of having strong controls in place to minimize exposure, and to have a comprehensive business resiliency plan that is regularly tested and updated.”

Comments

Popular posts from this blog

Why First Responder Credit Unions Are Built to Adopt Blockchain Faster

  For years, blockchain in financial services lived mostly in the world of experimentation—proofs of concept, pilot programs, and innovation labs that rarely touched day-to-day operations. That era is ending. Today, blockchain adoption is moving from experimentation to scale. Across payments, capital markets, and banking infrastructure, financial institutions are beginning to operate on new rails—powered by tokenized money, programmable assets, and always-on settlement models. For credit unions serving first responders, this shift presents not just a technology opportunity, but a strategic one. Blockchain Is Becoming Core Infrastructure The most important change isn’t the technology itself—it’s how it’s being used. Blockchain is no longer about testing what might work. It’s increasingly being deployed as infrastructure to solve long-standing problems in financial services, including slow settlement, trapped liquidity, manual reconciliation, and limited operating hours. Cr...

Sunday Reading - Budweiser 101

Draft Horses   Budweiser 101 Perhaps best known for its Super Bowl Clydesdale ads, Budweiser   is among the world’s most popular beer brands. It was among the first beers to achieve national distribution in the late 19th century, thanks to its revolutionary refrigeration and pasteurization techniques, setting the stage for the modern US beer industry.   Founded in the 1850s as the “Bavarian Brewery,” the company was acquired in 1860 by Eberhard Anheuser. He sold half of it to his son-in-law,  Adolphus Busch ,   in 1869, forming the partnership that would become Anheuser-Busch in St. Louis, Missouri.   In the 1870s, Carl Conrad , a St. Louis distributor, traveled through a Bohemian town called “Budweis” in German and drank a pale lager. Upon returning home, he worked with Anheuser-Busch to brew its own light lager, marketing it under the ...

Health Coverage Tailored for You! Allstate Health Solutions

Health Coverage Tailored for You!  Allstate Health Solutions At the National Council of Firefighter Credit Unions ( NCOFCU), we can help credit unions and their members find health coverage that supports their lifestyle and budget . Through our partnership with Allstate Health Solutions , you get access to flexible health plan options — including short-term medical, supplemental coverage, dental, and more — designed to fill gaps and bring peace of mind when life shifts or coverage matters most. Why choose Allstate Health Solutions?   https://ncofcu.allstatehealth.com/ Flexible health plan options — Explore short-term medical, supplemental accident, critical illness, and dental coverage that fits your needs and budget. Coverage made simple — Find and compare plans quickly with our easy online experience. Support for transitions — Ideal for periods between job-based coverage, changes in life circumstances, or when you want supplement...

Letter to Credit Unions (24-CU-03) Consumer Harm Stemming from Certain Overdraft and Non-Sufficient Funds Fee Practice

      Letter to Credit Unions (24-CU-03) Consumer Harm Stemming from Certain Overdraft and Non-Sufficient Funds Fee Practices Dear Boards of Directors and Chief Executive Officers: If your credit union assesses overdraft or non-sufficient funds (NSF) fees that your members cannot reasonably anticipate or avoid, your credit union may be exposing itself to heightened reputational, consumer compliance,...

Harper Issues Letter to CU Execs Outlining NCUA’s Approach to Overdraft, NSF Fees - Henry Meier, Esq

Legal and compliance expert,  Henry Meier, Esq,  says this is an “unequivocal warning” to credit unions to address the issue sooner than later. The issue of overdraft and non-sufficient funds (NSF) fees has gone from a business practice that was seen as simply part of the credit union business plan, to a topic fraught with political and social ramifications. Much of the fee debate began earlier this year when the CFPB issued a proposed rule to clamp down on banks and credit unions issuing what  Director Rohit Chopra called “junk fees.”  From there, the overdraft and NSF issue became worrisome for many credit union leaders who have or continue to have some kind of reliance on the fee income. On Tuesday, NCUA Chairman Todd Harper  posted the guidance letter  on the agency’s website that gave credit unions a very clear picture of the NCUA’s stance on its approach to overdraft and NSF fees – these fees may be a significant legal, consumer compliance, third-part...

The NCOFCU Podcast: Clear Insight. No Jargon.

Every week, we cover the latest trends and developments within the credit union industry. At NCOFCU, we are dedicated to providing you with insightful discussions that cut through the clutter. Our podcast features expert opinions, in-depth analyses, and an exploration of the challenges and opportunities that credit unions, directors, and staff face today. Join us as we navigate the evolving industry and empower associations with the knowledge they need to thrive. https://ceohp.podbean.com/ ================================================= Remember, you're not alone with  NCOFCU.org Join/Upgrade Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board

NCUA: More than $1.3 Million will be Available; Applications Due by May 22

ALEXANDRIA, Va. (April 13, 2020) – Recognizing the immediate needs of credit unions and their members in the COVID-19 pandemic, the National Credit Union Administration is committing the majority of the 2020 Community Development Revolving Loan Fund appropriation for COVID-19 assistance. “The NCUA recognizes that federally insured credit unions will face unpredictable challenges and costs as a result of the COVID-19 pandemic,” NCUA Chairman Rodney E. Hood said. “The increase in available grant funding will help more low-income credit unions to continue offering quality and affordable financial services to their members and communities. I encourage all eligible credit unions in need to consider applying for these grants as a means to ensure service to their members.” The agency is committing $1,375,000 for grants to eligible low-income credit unions, an increase of $575,000 from the $800,000 originally announced on March 31. This funding will supplant the traditional Community Developm...

What Does PTSD in a Firefighter Look Like? A New Brain Scan Can Show You

Link Post-traumatic stress disorder (PTSD) is often described as one of the invisible scars that firefighters and others accumulate after years of dealing with trauma in their jobs. Now the scars are invisible no longer. A new tool—the SPECT scan—is offering a new way for firefighters and others with PTSD to visualize their injuries. SPECT stands for single photon emission computed tomography, and it creates 3-D scans of the patient’s brain that look at blood flow and brain activity, KTLA reports. Those scans can then be used to generate a treatment plan tailored to the specific patient based on the visual effects of PTSD. Retired Firefighter-Paramedic Matthew Fiorenza, a PTSD sufferer, told the station that the scans also help make the illness more tangible. “Looking at a picture of my brain, it just took the stigma out of it,” he told KTLA. “It’s like, okay, I’m not crazy.”  

'Tis the season for fraud! Teller questions if member fraud is suspected.

  When a credit union employee suspects a member may be subject to fraud, they should initiate a careful conversation focusing on the nature of the transaction and external influences. The goal is to help the member identify red flags without the employee asking for sensitive personal information that the credit union should already have on file.  Initial Verification Questions    .pdf Before discussing the specifics of the suspicious activity, the employee should confirm the member's identity in accordance with established internal protocols.  Questions About the Transaction/Activity If the member confirms they are conducting a suspicious transaction (e.g., a large wire transfer or purchase of gift cards ), the employee should ask questions to help the member pause and think critically:  "What is the purpose of this transaction?" "Do you personally know the person or business you are sending money to?" "Have you ever met the...

Chairman Hauptman’s Remarks for FLEC Public Meeting (Trump Accounts)

  As Prepared for Delivery on February 6, 2026 Meeting Focus: Implementation and Outreach for Trump Accounts Good morning and thank you to our colleagues at the U.S. Department of the Treasury and members of the Financial Literacy and Education Commission for convening today’s important discussion. I also want to express my appreciation for this body’s leadership in encouraging savings and advancing the broader goal we all share—ensuring that every American has a meaningful opportunity to build financial capability, resilience, and long-term financial security. There’s a lot to like about Trump Accounts, including how easy it is to start the process when filing your taxes. These accounts were clearly designed with behavioral economics in mind. That is to say, things that are easier to do are more likely to get done. Trump accounts also turn all these kids into investors. The more Americans that identify as investors, the better off we are. Investing done by regular people turns Mar...