Skip to main content

What You Can Do About Ransomware Threat

By Ray Birch

RANCHO CUCAMONGA, Calif.—In the wake of a ransomware attack that shut down 60 credit unions, cyber security experts are warning many CUs are just one compromised key supplier away from being shut down, too. It’s a growing threat they say can have numerous  downstream effects on many organizations.

No institution is immune, and the best line of defense remains educating employees on how to avoid making mistakes that place a credit union, CUSO or vendor right into the hands of criminals.

“Co-op Solutions views ransomware attacks as an industry-wide threat that will continue for the foreseeable future with two main threat areas of concern,” said Christopher Williams, deputy chief information security officer at Co-op.

Feature Ransomware

The two areas of concern, according to Williams, are Ransomware-as-a-Service (RaaS) models and cyber supply chain threats.

A Proliferating Model

“With the RaaS model, an attacker doesn’t need to develop their own ransomware capability to turn a system compromise into a ransomware attack. This model has proliferated the cybercrime world. The model can quickly incorporate new tactics, techniques and procedures (TTPs) to be used by a wide range of threat actors,” he said. “The second threat area is the cyber supply chain. Attacks against key suppliers have a ripple effect across the supplier’s client-base. Many companies are one compromised key supplier away from a business crippling service impact.”

How to Respond

wlliams

Christopher Williams

Given that growing threat, what should credit unions be doing now?

“Credit unions should continue to educate their employees on the risk of ransomware attacks and the methods used to gain initial unauthorized access,” Williams advised. “Phishing remains a top attack vector, and social engineering of the service or help desk to compromise user credentials is on the rise.”

Credit unions also need to have robust backup capability—restoring to a clean and non-infected copy of system data, Williams added.

“That can help with the recovery of a ransomware attack,” he said. “In addition, they should become active members of the local area U.S. Secret Service Electronic Crimes Task Forces (ECTF) or Financial Crimes Task Forces (FCTF), which can provide advice in preventing attacks and support during suspected or actual attacks. In addition, monitor threat intelligence type sources for indications of attacks against their organizations or their vendors and new TTPs being used by attackers.

“Finally, practice the incident response to a ransomware attack. Drilling the panic and unknowns out of the process will help increase the chance of a successful recovery if an actual attack occurs,” he said.

The Good News? CUs Not Alone

Jim Stickley, CEO of Stickley on Security, said credit unions are one of many industries being affected by ransomware.

“I am not certain that ransomware is specific (to any organization), and credit unions and fintechs are just part of the much bigger picture of the state of ransomware in general,” said Stickley, who is also CEO of Troy, Mich.-based Mahalo Technologies. “Most people have this idea that cybercriminals are targeting a specific business type. While it’s true that healthcare and education are targeted directly and we also see banks and credit unions get targeted, when it comes to more general business, such as fintechs, we have not seen that level of direct attacks. Instead, what you see is employees who fall victim to phishing attacks or malicious websites.”

‘Average’ People, Not an Average Website

Stickley said when those incidents are investigated, what’s all-to-often discovered is that it was a phishing email that had been sent to hundreds of thousands of organizations that is the culprit, often in in the guise of te malicious websites that have been promoted though malvertising to “average” people. 

stickleyJim

Jim Stickley

“In these cases it’s just the low-hanging fruit. If an employee clicks the link, opens the attachment or browses to malicious sites, they open the door to the criminals. The criminals really don’t care if that organization is fintech, credit union or other business segment,” said Stickley, adding adding he does not believe the recent attack that hit DP vendor Fedcomp and than affected 60 credit unions had any company or credit union as a specific target.

“For criminals, there is little need to put a direct focus on fintech at this time since just about every business entity has similar value and so they will continue to cast a very wide net and whoever gets caught up will be their next victim,” he said.

Advice Shared

For credit unions looking to take some practical steps to defend themselves from ransomware, TruStage is sharing some strategies.

“Responding to the immediate threat of a ransomware attack or any cyber incident in a timely manner is critical to minimize data loss, contain the threat and restore operations,” Chris Gill, TruStage senior manager, risk and compliance solutions, told CUToday.info. “This is true even when that threat originates with a credit union’s third-party service provider or partner. Security incidents that do not originate at a credit union can still have a large impact on credit unions’ operations and reputation.”

Noting the affects such attacks have on member service, Gill added, “It reminds us all of the importance of having strong controls in place to minimize exposure, and to have a comprehensive business resiliency plan that is regularly tested and updated.”

Comments

Popular posts from this blog

Trump Administration Declares CFPB Funding Illegal, Bureau’s Cash To Run Out By Early 2026

WASHINGTON—Credit-unions face a potential regulatory vacuum as the Trump Administration formally has determined the CFPB’s current self-funding mechanism unlawful—a move that could put the agency on a path to closure in early 2026 unless Congress steps in. For credit-union leaders, who rely on the Bureau’s oversight of consumer-finance markets and enforcement of unfair practices, the decision signals a major disruption to the regulatory environment CUs navigate daily. In a court filing released late Monday, the Administration declared that the CFPB is now legally barred from seeking additional funds from the Federal Reserve System—the agency’s usual funding source under the Dodd‑Frank Wall Street Reform and Consumer Protection Act, POLITICO reported. That means the Bureau’s remaining resources will likely carry it only through the end of the year, after which it “anticipates exhausting its currently available funds in early 2026.” CUToday.info has tracked this story, noting in  Oct...

Sheehans Consulting LLC - "We only have one goal in mind!"

We have one goal in mind: “What is best for you? We achieve strategic initiatives, develop products, optimize profitability and productivity through best practices, and make our firm a strong asset for professional services.  With over 30 years of experience in public administration, credit union, and association management, I have developed a solid track record in leadership and development.  Please visit us at https://www.sheehansconsultingllc.com/ to learn more about what we can do for you.   _________________________________________ Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board

NCUA Reports Continued Credit Union Loan Growth in First Quarter of 2016

"ALEXANDRIA, Va. (June 3, 2016) – Credit unions continued to increase their lending, with loans outstanding increasing 10.7 percent in the year ending in the first quarter of 2016, the National Credit Union Administration reported today.  “The credit union system again experienced solid performance during the first quarter of 2016,” NCUA Board Chairman Rick Metsger said. “Overall, new and used auto lending was especially strong, and the system gained one million members. With an influx of deposits, federally insured shares at credit unions also neared the $1 trillion mark coming in at $991.7 billion.  “As credit union lending has increased, long-term investments have declined and reduced the system’s interest rate risk. However, delinquency and charge-off rates are slightly higher than a year ago, and member-business loan delinquencies are rising even more. Credit unions making such loans should take note and ensure that they perform proper due diligence to mitigate the r...

Now Available - "Financial Literacy" From NCOFCU

https://www.ncofcu.org/financial-literacy The National Council of Firefighter Credit Unions (NCOFCU) is dedicated to enhancing financial literacy among our members, members, particularly targeting the Millennial and Gen Z demographics. We are excited to share our engaging financial education video series, designed to address their key concerns regarding earning, saving, and spending money wisely. Here are several critical financial lessons that can significantly impact your personal finance management and long-term financial health. Discover how staying informed and educated about financial products and market trends can empower you to make smarter financial decisions. https://www.youtube.com/playlist?list=PLT3lzRTXnHw4LjHuOIk31eTDxaQ7J7B0f   _________________________________________ Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board

Fed Governor Warns ‘Global Stablecoin Glut’ Could Reshape Monetary Policy

  NEW YORK—Federal Reserve Governor Stephen Miran believes the rapid rise of stablecoins could become a major force shaping U.S. monetary policy. Once seen as a niche digital tool for crypto traders, stablecoins have evolved into a global conduit for dollar-denominated transactions, enabling users worldwide to store value and move capital more efficiently. Their growing prominence, Miran noted during his speech at the BCVC Summit 2025 at the Harvard Club, reflects continued demand for dollars—and with the GENIUS Act now providing a clear regulatory framework for U.S.-issued stablecoins, the sector is poised for broader adoption across payment systems. Stephen Miran Stablecoins’ link to the U.S. dollar is reinforcing the currency’s global dominance while simultaneously creating new implications for monetary policy. Miran argued that stablecoins are already increasing demand for U.S. Treasury bills and other dollar-based assets, especially from investors outside the United States. Th...

Best Places to Retire

  List: Best Places to Retire Midland, Michigan , was ranked the best place to retire , according to a ranking of 850 cities by U.S. News . The top locations had the best mix of affordability, quality of life, health care access, and other benefits. The top five were rounded out by Weirton, West Virginia , Homosassa Springs, Florida , The Woodlands, Texas , and Spring, Texas . Midland scored top marks on walkability , culture , retail establishments , and restaurants . The town is just a short drive from beaches at the edge of Lake Huron . The top 25 included nine cities in Florida and six in Texas. See the full list here . _________________________________________ Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board

NCUA Letter to Credit Unions: Interagency Statement on LIBOR Transition

Dear Boards of Directors and Chief Executive Officers: As a follow-up to Letter to Credit Unions 21-CU-03, LIBOR Transition , this letter provides additional reminders related to LIBOR’s discontinuance. Five federal financial institution regulatory agencies, in conjunction with the state bank and state credit union regulators, are jointly issuing the enclosed statement to emphasize the expectation that supervised institutions with LIBOR exposure will continue to progress toward an orderly transition away from LIBOR. [1] The NCUA encourages all federally insured credit unions to transition away from using U.S. dollar LIBOR as a reference rate as soon as possible, but no later than December 31, 2021, and to ensure existing contracts have robust fallback language that includes a clearly defined alternative reference rate. Please contact your NCUA Regional Office or state supervisory authority if you have any questions about this important topic. Read the Letter to Credit Unions   Sav...

House Vote Ends Longest Shutdown In U.S. History

WASHINGTON—The House late Wednesday approved a sweeping funding measure to end the longest federal government shutdown in U.S. history, clearing the way for federal agencies to reopen within hours and for hundreds of thousands of workers and service members to receive long-delayed pay. The vote was 222-209, with just six Democrats breaking with their leadership, POLITOCO said. President Trump is expected to sign the measure before night’s end, allowing federal operations to resume Thursday morning. The chamber’s vote—coming after days of intense negotiations and following the Senate’s 60–40 passage—sent the bipartisan agreement to President Donald Trump for his signature, effectively ending a shutdown that stretched well past six weeks and rattled everything from military readiness to basic government services. The package includes a continuing resolution funding the government through Jan. 30. The measure also includes a three-bill “minibus” of full-year funding for the Department...

Current Geopolitical Events Increase Likelihood of Imminent Cyberattacks on Financial Institutions

Current Geopolitical Events Increase Likelihood of Imminent Cyberattacks on Financial Institutions Financial Institutions, Large and Small, Included in Potential Targets to U.S. Critical Infrastructure The U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) has recently issued two alerts addressing risks from Russian State-Sponsored cyber threats and highlighting recent malicious cyber incidents suffered by public and private entities in Ukraine . Given current geopolitical events, the NCUA, along with CISA, the Federal Bureau of Investigation, and the National Security Agency encourage credit unions of all sizes and their cybersecurity teams nationwide to adopt a heightened state of awareness and to conduct proactive threat hunting. In addition, COVID-related supply chain disruptions may require management to reevaluate previously held assumptions for business continuity and disaster recovery pla...

Zero - Cost - Zero - Risk

  https://synergycu.org/ _______________________________________________ Check out some of NCOFCU's additional features: First Responder Credit Union Academy Podcasts YouTube Mini's Blog Job Board