Skip to main content

What You Can Do About Ransomware Threat

By Ray Birch

RANCHO CUCAMONGA, Calif.—In the wake of a ransomware attack that shut down 60 credit unions, cyber security experts are warning many CUs are just one compromised key supplier away from being shut down, too. It’s a growing threat they say can have numerous  downstream effects on many organizations.

No institution is immune, and the best line of defense remains educating employees on how to avoid making mistakes that place a credit union, CUSO or vendor right into the hands of criminals.

“Co-op Solutions views ransomware attacks as an industry-wide threat that will continue for the foreseeable future with two main threat areas of concern,” said Christopher Williams, deputy chief information security officer at Co-op.

Feature Ransomware

The two areas of concern, according to Williams, are Ransomware-as-a-Service (RaaS) models and cyber supply chain threats.

A Proliferating Model

“With the RaaS model, an attacker doesn’t need to develop their own ransomware capability to turn a system compromise into a ransomware attack. This model has proliferated the cybercrime world. The model can quickly incorporate new tactics, techniques and procedures (TTPs) to be used by a wide range of threat actors,” he said. “The second threat area is the cyber supply chain. Attacks against key suppliers have a ripple effect across the supplier’s client-base. Many companies are one compromised key supplier away from a business crippling service impact.”

How to Respond

wlliams

Christopher Williams

Given that growing threat, what should credit unions be doing now?

“Credit unions should continue to educate their employees on the risk of ransomware attacks and the methods used to gain initial unauthorized access,” Williams advised. “Phishing remains a top attack vector, and social engineering of the service or help desk to compromise user credentials is on the rise.”

Credit unions also need to have robust backup capability—restoring to a clean and non-infected copy of system data, Williams added.

“That can help with the recovery of a ransomware attack,” he said. “In addition, they should become active members of the local area U.S. Secret Service Electronic Crimes Task Forces (ECTF) or Financial Crimes Task Forces (FCTF), which can provide advice in preventing attacks and support during suspected or actual attacks. In addition, monitor threat intelligence type sources for indications of attacks against their organizations or their vendors and new TTPs being used by attackers.

“Finally, practice the incident response to a ransomware attack. Drilling the panic and unknowns out of the process will help increase the chance of a successful recovery if an actual attack occurs,” he said.

The Good News? CUs Not Alone

Jim Stickley, CEO of Stickley on Security, said credit unions are one of many industries being affected by ransomware.

“I am not certain that ransomware is specific (to any organization), and credit unions and fintechs are just part of the much bigger picture of the state of ransomware in general,” said Stickley, who is also CEO of Troy, Mich.-based Mahalo Technologies. “Most people have this idea that cybercriminals are targeting a specific business type. While it’s true that healthcare and education are targeted directly and we also see banks and credit unions get targeted, when it comes to more general business, such as fintechs, we have not seen that level of direct attacks. Instead, what you see is employees who fall victim to phishing attacks or malicious websites.”

‘Average’ People, Not an Average Website

Stickley said when those incidents are investigated, what’s all-to-often discovered is that it was a phishing email that had been sent to hundreds of thousands of organizations that is the culprit, often in in the guise of te malicious websites that have been promoted though malvertising to “average” people. 

stickleyJim

Jim Stickley

“In these cases it’s just the low-hanging fruit. If an employee clicks the link, opens the attachment or browses to malicious sites, they open the door to the criminals. The criminals really don’t care if that organization is fintech, credit union or other business segment,” said Stickley, adding adding he does not believe the recent attack that hit DP vendor Fedcomp and than affected 60 credit unions had any company or credit union as a specific target.

“For criminals, there is little need to put a direct focus on fintech at this time since just about every business entity has similar value and so they will continue to cast a very wide net and whoever gets caught up will be their next victim,” he said.

Advice Shared

For credit unions looking to take some practical steps to defend themselves from ransomware, TruStage is sharing some strategies.

“Responding to the immediate threat of a ransomware attack or any cyber incident in a timely manner is critical to minimize data loss, contain the threat and restore operations,” Chris Gill, TruStage senior manager, risk and compliance solutions, told CUToday.info. “This is true even when that threat originates with a credit union’s third-party service provider or partner. Security incidents that do not originate at a credit union can still have a large impact on credit unions’ operations and reputation.”

Noting the affects such attacks have on member service, Gill added, “It reminds us all of the importance of having strong controls in place to minimize exposure, and to have a comprehensive business resiliency plan that is regularly tested and updated.”

Comments

Popular posts from this blog

NCUA Board Approves 11 Final Rules for Deregulation Project

Alexandria, VA (August 5, 2026) ― The National Credit Union Administration (NCUA) today finalized eleven rules that were proposed for changes through the Deregulation Project. This is the first round of final rules from the ongoing Deregulation Project which is an initiative to review NCUA’s regulations and ensure they are focused on credit unions’ safety, soundness, and resilience. The final rules include: This is an external link to a website belonging to another federal agency, private organization, or commercial entity. Surety and Guarantor Requirements – 12 CFR 701.20(c)(3) and 701.20(d) (Opens new window) This is an external link to a website belonging to another federal agency, private organization, or commercial entity. Limits on Loan to Other Credit Unions – 12 CFR 701.25(b) (Opens new window) This is an external link to a website belonging to another federal agency, private organization, or commercial entity. Service to Underserved Areas – IRPS 08-2 (Opens new window) This is...

Making the Most of the Final Five Years Before Retirement

  NATIONAL COUNCIL OF FIRST RESPONDER CREDIT UNIONS RETIREMENT READINESS Making the Most of the Final Five Years Before Retirement A practical planning guide for first responders, credit union volunteers, employees, and their families Five years before retirement is an important checkpoint. It is the time to confirm what you have saved, understand the income you can expect, and decide whether your retirement plans match the life you want to lead.   1. Review Your Retirement Savings Start by taking a fresh look at your retirement accounts, personal savings, investments, and other assets. A retirement calculator can help estimate whether you are on track and show how additional saving during the next five years may strengthen your plan.   2. Identify Every Source of Retirement Income List the income you may receive in retirement, including pensions, Social Security, retirement-plan withdrawals, invest...

Senate, 51-47, has confirmed John Crews to the NCUA board

WASHINGTON—The U.S. Senate, 51-47, has confirmed John Crews to the NCUA board, clearing the way for him to succeed Kyle Hauptman and return the agency to a single-member board following the Trump Administration's removal of Democratic board members Todd Harper and Tanya Otsuka earlier this year. Maintaining the foundational stability of the credit union system Supporting efficient, risk-based regulation that accounts for institutional size and operational differences Preparing for technological advancement while safeguarding member assets Encouraging the growth of new credit unions to serve underbanked and military communities Preserving an open, accessible, and collaborative dialogue between the NCUA and the credit union movement Crews, who most recently served in the Treasury Department, has said his priorities include reducing regulatory burden for smaller credit unions, encouraging innovation and supporting the chartering of new credit unions, while maintaining the safety and s...

What’s Ahead for U.S. Economy? Here’s What One Former Fed Chair is Saying

 WASHINGTON–Former Federal Reserve Chairman Ben Bernanke, who headed the central bank during the 2008 financial crisis, is now warning that the United States is headed for a situation similar to that of the 1970s, when Americans were losing their jobs but still facing higher prices at the grocery store and at the pump. Ben Bernanke “Even under the benign scenario, we should have a slowing economy,” Bernanke told the New York Times in an interview in conjunction with his new book, “ 21st Century Monetary Policy: The Federal Reserve From the Great Inflation to Covid-19 ,” which is scheduled to publish today. “So, there should be a period in the next year...

Fed Governors Signal Smaller Rate Increases Coming

WASHINGTON–There is a growing chorus among Federal Reserve governors that the central bank will be slowing it pace of rate increases when the Federal Open Markets Committee meets next on Feb. 1. Christopher Waller Among those who have signaled the days of 50 - and 75-basis point increases are over is Federal Reserve Governor Christopher Waller, who said he believes it’s time to slow the pace of increases—but not eliminate them. If the forecast proves true, it will mark the end of the rapid increases that took place during 2022 as the Fed sought to tamp down high inflation. Central bankers are now “entering a new phase that is focused more on how high-inter...

Sunday Reading - We Hold These Truths to Be Self-Evident

We Hold These Truths to Be Self-Evident .  The Declaration of Independence is the founding document that formally announced the American Colonies' break from British rule. Adopted on July 4, 1776, it laid the philosophical and moral foundation for American self-governance, asserting that individuals possess inherent rights and that governments must be accountable to the people. While it didn't create a government or legal framework, the Declaration marked the birth of the United States as a sovereign nation. >  Hear why the Continental Congress decided to declare independence, how the text took shape...

NCOFCU 2016 Annual Awards Dinner

This year in Denver, CO, the National Council of FirefighterCredit Union Inc (NCOFCU) announced the winners of their, Lifetime Achievement Award and Volunteer of the Year Award. They also awarded an Out Going Charter Director Award and a thank you to the Denver Fire Dept. Credit Union for hosting the conference.    Lifetime Achievement Award Wallace Garland CEO Richmond Virginia Fire Police Credit Union   In recognition of his constant Dedication and passion for the credit union movement throughout his career and for his unending involvement and outstanding contributions to NCOFCU  Volunteer of the Year Award Erv Williams Director Spokane Firefighters Credit Union The National Council of Firefighters Credit Unions would like to recognizance Erv Williams  as NCOFCU's volunteer of the year. The time and personal commitment of  Erv has been exemplary at all levels, and needs to be acknowledged. Out Going Charter Board M...

New CEO Named at SF Fire CU

  In San Francisco, – SF Fire Credit Union has appointed Robert Kassab as its president and chief executive Officer. Kassab, who has served as the $1.6-billion credit union’s CFO and most recently as Interim CEO, will lead the organization as it builds on 75 years of community service and pursues an ambitious strategy for growth and member impact, the credit union said in a statement. Robert Kassab “SF Fire Credit Union has a 75-year legacy of doing right by its members, and I take that responsibility seriously,” Kassab stated. Kassab joined SF Fire Credit Union in 2022 as CFO, where he played a central role in strengthening the institution’s financial foundation and positioning the credit union for long-term growth. His appointment as CEO follows a period of interim leadership, during which he worked closely with the board to develop a strategic vision for the credit union’s future, according to SF Fire. An Institution That ‘Deserves Them Back’ “SF Fire Credit Union was built on ...

New FRCUA Manuals Alert!

New & Updated Manuals Now in the First Responder Credit Union Academy! NCUA "What you Need to Know." Building a Budget Policies & Procedures CEO Strategic Planning Checklist Board Strategic Priorities Directors'  Strategic Planning Checklist We’re always improving the First Responder Credit Union Academy to give you the tools you need to succeed. Our manuals are regularly updated with the latest insights, best practices, and industry guidance — so you can stay informed, confident, and ready to serve your members. Check out the latest updates and keep your skills sharp:  https://www.ncofcu.org/first-responder-credit-union-academy  ================================================= Remember, you're not alone with  NCOFCU.org Join/Upgrade Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board  

NCUA"s new video module provides best practices for merging

The three-part video module provided by NCUA, available online   here , examines current trends in mergers, when a credit union board should consider a merger and how to negotiate a merger agreement that best serves the credit union’s interests. Every credit union should discuss the possibilities of a future merger in their strategic planning.