Skip to main content

What You Can Do About Ransomware Threat

By Ray Birch

RANCHO CUCAMONGA, Calif.—In the wake of a ransomware attack that shut down 60 credit unions, cyber security experts are warning many CUs are just one compromised key supplier away from being shut down, too. It’s a growing threat they say can have numerous  downstream effects on many organizations.

No institution is immune, and the best line of defense remains educating employees on how to avoid making mistakes that place a credit union, CUSO or vendor right into the hands of criminals.

“Co-op Solutions views ransomware attacks as an industry-wide threat that will continue for the foreseeable future with two main threat areas of concern,” said Christopher Williams, deputy chief information security officer at Co-op.

Feature Ransomware

The two areas of concern, according to Williams, are Ransomware-as-a-Service (RaaS) models and cyber supply chain threats.

A Proliferating Model

“With the RaaS model, an attacker doesn’t need to develop their own ransomware capability to turn a system compromise into a ransomware attack. This model has proliferated the cybercrime world. The model can quickly incorporate new tactics, techniques and procedures (TTPs) to be used by a wide range of threat actors,” he said. “The second threat area is the cyber supply chain. Attacks against key suppliers have a ripple effect across the supplier’s client-base. Many companies are one compromised key supplier away from a business crippling service impact.”

How to Respond

wlliams

Christopher Williams

Given that growing threat, what should credit unions be doing now?

“Credit unions should continue to educate their employees on the risk of ransomware attacks and the methods used to gain initial unauthorized access,” Williams advised. “Phishing remains a top attack vector, and social engineering of the service or help desk to compromise user credentials is on the rise.”

Credit unions also need to have robust backup capability—restoring to a clean and non-infected copy of system data, Williams added.

“That can help with the recovery of a ransomware attack,” he said. “In addition, they should become active members of the local area U.S. Secret Service Electronic Crimes Task Forces (ECTF) or Financial Crimes Task Forces (FCTF), which can provide advice in preventing attacks and support during suspected or actual attacks. In addition, monitor threat intelligence type sources for indications of attacks against their organizations or their vendors and new TTPs being used by attackers.

“Finally, practice the incident response to a ransomware attack. Drilling the panic and unknowns out of the process will help increase the chance of a successful recovery if an actual attack occurs,” he said.

The Good News? CUs Not Alone

Jim Stickley, CEO of Stickley on Security, said credit unions are one of many industries being affected by ransomware.

“I am not certain that ransomware is specific (to any organization), and credit unions and fintechs are just part of the much bigger picture of the state of ransomware in general,” said Stickley, who is also CEO of Troy, Mich.-based Mahalo Technologies. “Most people have this idea that cybercriminals are targeting a specific business type. While it’s true that healthcare and education are targeted directly and we also see banks and credit unions get targeted, when it comes to more general business, such as fintechs, we have not seen that level of direct attacks. Instead, what you see is employees who fall victim to phishing attacks or malicious websites.”

‘Average’ People, Not an Average Website

Stickley said when those incidents are investigated, what’s all-to-often discovered is that it was a phishing email that had been sent to hundreds of thousands of organizations that is the culprit, often in in the guise of te malicious websites that have been promoted though malvertising to “average” people. 

stickleyJim

Jim Stickley

“In these cases it’s just the low-hanging fruit. If an employee clicks the link, opens the attachment or browses to malicious sites, they open the door to the criminals. The criminals really don’t care if that organization is fintech, credit union or other business segment,” said Stickley, adding adding he does not believe the recent attack that hit DP vendor Fedcomp and than affected 60 credit unions had any company or credit union as a specific target.

“For criminals, there is little need to put a direct focus on fintech at this time since just about every business entity has similar value and so they will continue to cast a very wide net and whoever gets caught up will be their next victim,” he said.

Advice Shared

For credit unions looking to take some practical steps to defend themselves from ransomware, TruStage is sharing some strategies.

“Responding to the immediate threat of a ransomware attack or any cyber incident in a timely manner is critical to minimize data loss, contain the threat and restore operations,” Chris Gill, TruStage senior manager, risk and compliance solutions, told CUToday.info. “This is true even when that threat originates with a credit union’s third-party service provider or partner. Security incidents that do not originate at a credit union can still have a large impact on credit unions’ operations and reputation.”

Noting the affects such attacks have on member service, Gill added, “It reminds us all of the importance of having strong controls in place to minimize exposure, and to have a comprehensive business resiliency plan that is regularly tested and updated.”

Comments

Popular posts from this blog

Why Auto Lending Is Starting To Stand Out As A Real Threat To CUs

  By Ray Birch MILWAUKEE—Auto lending is emerging as one of the biggest areas of risk for credit unions, even as the broader U.S. economy continues to perform better than many expected, according to Bill Handel, chief economist at Raddon, a Fiserv company. Delinquency trends in auto portfolios are now approaching levels last seen during the Great Financial Crisis, Handel said, driven by a combination of high vehicle prices, elevated interest rates and increasing financial pressure on lower-income consumers. “There’s probably still a lot of risk in the auto portfolios,” Handel said. “Our numbers in terms of delinquency behavior in the United States are now rivaling what they were during the Great Financial Crisis.” Economy Holding Up Better Than Expected Despite those pockets of risk, Handel said the broader economy remains surprisingly resilient. “If you look at the U.S. economy, it’s actually performing quite well—probably better than most people would have anticipated,” he said. ...

When Cooperation Turns To Competition: A Turning Point For The Firefighter Credit Union Movement

  By Grant Sheehan For decades, firefighter credit unions have stood as a model of what cooperative finance is meant to be—institutions built not to compete ruthlessly, but to serve a shared mission: supporting the financial well-being of those who risk their lives in service to others. That’s what makes the recent actions of Firefighter First Credit Union so concerning. Firefighter First FCU was not just another participant; it was a founding member of the National Council of Firefighter Credit Unions (NCOFCU). It helped shape the very principles of collaboration, mutual respect, and non-encroachment that have long defined our community. Those principles weren’t accidental; they were intentional safeguards to ensure that firefighter-focused credit unions could grow together, not at each other’s expense. But something has changed. Firefighter First FCU’s decision to pursue a nationwide charter marks a clear shift in direction—from cooperation to direct competition. This isn’t simpl...

Small Credit Unions Don’t Lack Representation—They Lack Board Education

  By Grant Sheehan Let’s be clear— representation  for small credit unions is not something new that suddenly needs to be invented. For more than 150 years in Europe and 115 years in the U.S., many of us—along with numerous trade groups representing postal workers, schools, hospitals, the military, first responders, electricians, welders, auto workers, and many other sponsor employee groups—have been actively representing and supporting small credit unions. The mission has always been the same: protect these institutions and ensure they have a voice. The real challenge facing small credit unions has never been a lack of organizations claiming to represent them. The challenge has been engagement and education. Many small credit unions operate with extremely limited resources. Their boards are made up of volunteers who already have full-time careers. Even when scholarships, training opportunities, and conferences are offered, the realities of travel costs, staffing shortages, op...

With Graham Signaling New Budget Bill, Credit Unions Brace For Tax Debate

By Ray Birch WASHINGTON— Senate Budget Committee Chairman Lindsey Graham’s comments Wednesday that Republicans will “expeditiously move toward creating a second budget reconciliation bill” are giving new shape to what had been a speculative discussion in Washington—and prompting renewed attention within the credit union industry to whether the movement’s federal tax exemption could again surface as lawmakers look for possible offsets. In a post on X, Graham said that after consulting with President Trump, his team and Senate Majority Leader John Thune, the Senate Budget Committee will move quickly on a second reconciliation package focused on “adequate funding to secure our homeland” and support for the military. The remarks are notable because they offer one of the clearest indications yet that a second fast-track budget measure—previously discussed but far from certain—may now be gaining traction. CUToday.info on Wednesday reached out to House Budget Committee Chairman Jodey Arringto...

Sunday Reading - How were the National Parks started?

  America's 'Best Idea'       How were the National Parks started? America's National Park System includes roughly 85 million acres of US territory, equal to the size of Germany, set aside by federal law for preservation. There are 63 areas officially designated as national parks—including the Grand Canyon, the Great Smoky Mountains, and Acadia—and more than 400 additional smaller units ( see map ). In 1872, Yellowstone was established   as the first national park dedicated to public enjoyment and recreation, though its foundation also  displaced several Native American tribes . By 1916, the growing system required the creation of the National Park Service to preserve its lands for future generations. Eventually, hunting and logging were banned in the parks, though regulated extractive activity is still permitted in nati...

Setting & Meeting Your 2018 GOALS - Dan Berger

A new year provides a fresh start and a clean slate and is often the time when resolutions and goals are established. If you are in the process of setting new goals – as I am – know that with an open mindset, achievement of all your goals is possible. "Goals provide clarity," writes Mareo McCracken, revenue leader of Movemedical. He explains that goal setting is about "combining the fortitude to achieve with clear thinking while making sense of your purpose and defining your ability to deliver value to others." However, goal setting and achieving also requires faith – or believing and hoping in something you can't see yet or that doesn't quite exist. For many of us, the No. 1 reason we don't achieve our goals is that we lack belief in ourselves and our abilities. I encourage you to read an article by Inc.com contributor Benjamin Hardy  that details the importance of having this kind of faith in yourself and delivers some tips on how to achie...

Lifesaving Companion Dog Takes On New Role With Injured Firefighter « CBS New York

Lifesaving Companion Dog Takes On New Role With Injured Firefighter « CBS New York : "NEW YORK (CBSNewYork) — A badly injured New York firefighter received a companion dog whose already saved people’s lives from fire. As CBS2’s Dave Carlin reported, disabled firefighter Tom Prin beamed as he was officially presented with his new canine companion Halona inside of a packed ceremony in Suffolk County. The former firefighter was one of 15 people receiving their canine companions. Prin was chosen because of what he’s been through — after fracturing his neck and back while responding to a Brooklyn fire. “When I was going from the third to fourth floor, the steps gave out and I fell through the fire escape,” he said. Prin has endured five spinal surgeries, but the Holtsville man will now be comforted by Halona who has quite the lifesaving resume herself." Click HERE to read full story and see video 'via Blog this'

Tower Climb NYC Registration Now Open!

     

How to Prepare for a Recession

  By Ray Birch IRVINE, Calif.—There’s little chance the Federal Reserve will steer the U.S. away from a recession in the next 12-18 months, says one economist, who adds delinquencies among the nation’s lenders could become an issue in the near future. Elliot Eisenberg, chief economist for economic consultancy GraphsandLaughs, said during a recent Origence webcast he does not think the recession will be deep. But he also urged credit unions to revisit loan loss reserves built during the pandemic and to shore those up again. What the growth of inflation will come down to, explained Eisenberg, is whether the Federal Reserve, as it adjusts rates upward to curb inflation, will be able to engineer a “soft landing” for the econo...