Skip to main content

What You Can Do About Ransomware Threat

By Ray Birch

RANCHO CUCAMONGA, Calif.—In the wake of a ransomware attack that shut down 60 credit unions, cyber security experts are warning many CUs are just one compromised key supplier away from being shut down, too. It’s a growing threat they say can have numerous  downstream effects on many organizations.

No institution is immune, and the best line of defense remains educating employees on how to avoid making mistakes that place a credit union, CUSO or vendor right into the hands of criminals.

“Co-op Solutions views ransomware attacks as an industry-wide threat that will continue for the foreseeable future with two main threat areas of concern,” said Christopher Williams, deputy chief information security officer at Co-op.

Feature Ransomware

The two areas of concern, according to Williams, are Ransomware-as-a-Service (RaaS) models and cyber supply chain threats.

A Proliferating Model

“With the RaaS model, an attacker doesn’t need to develop their own ransomware capability to turn a system compromise into a ransomware attack. This model has proliferated the cybercrime world. The model can quickly incorporate new tactics, techniques and procedures (TTPs) to be used by a wide range of threat actors,” he said. “The second threat area is the cyber supply chain. Attacks against key suppliers have a ripple effect across the supplier’s client-base. Many companies are one compromised key supplier away from a business crippling service impact.”

How to Respond

wlliams

Christopher Williams

Given that growing threat, what should credit unions be doing now?

“Credit unions should continue to educate their employees on the risk of ransomware attacks and the methods used to gain initial unauthorized access,” Williams advised. “Phishing remains a top attack vector, and social engineering of the service or help desk to compromise user credentials is on the rise.”

Credit unions also need to have robust backup capability—restoring to a clean and non-infected copy of system data, Williams added.

“That can help with the recovery of a ransomware attack,” he said. “In addition, they should become active members of the local area U.S. Secret Service Electronic Crimes Task Forces (ECTF) or Financial Crimes Task Forces (FCTF), which can provide advice in preventing attacks and support during suspected or actual attacks. In addition, monitor threat intelligence type sources for indications of attacks against their organizations or their vendors and new TTPs being used by attackers.

“Finally, practice the incident response to a ransomware attack. Drilling the panic and unknowns out of the process will help increase the chance of a successful recovery if an actual attack occurs,” he said.

The Good News? CUs Not Alone

Jim Stickley, CEO of Stickley on Security, said credit unions are one of many industries being affected by ransomware.

“I am not certain that ransomware is specific (to any organization), and credit unions and fintechs are just part of the much bigger picture of the state of ransomware in general,” said Stickley, who is also CEO of Troy, Mich.-based Mahalo Technologies. “Most people have this idea that cybercriminals are targeting a specific business type. While it’s true that healthcare and education are targeted directly and we also see banks and credit unions get targeted, when it comes to more general business, such as fintechs, we have not seen that level of direct attacks. Instead, what you see is employees who fall victim to phishing attacks or malicious websites.”

‘Average’ People, Not an Average Website

Stickley said when those incidents are investigated, what’s all-to-often discovered is that it was a phishing email that had been sent to hundreds of thousands of organizations that is the culprit, often in in the guise of te malicious websites that have been promoted though malvertising to “average” people. 

stickleyJim

Jim Stickley

“In these cases it’s just the low-hanging fruit. If an employee clicks the link, opens the attachment or browses to malicious sites, they open the door to the criminals. The criminals really don’t care if that organization is fintech, credit union or other business segment,” said Stickley, adding adding he does not believe the recent attack that hit DP vendor Fedcomp and than affected 60 credit unions had any company or credit union as a specific target.

“For criminals, there is little need to put a direct focus on fintech at this time since just about every business entity has similar value and so they will continue to cast a very wide net and whoever gets caught up will be their next victim,” he said.

Advice Shared

For credit unions looking to take some practical steps to defend themselves from ransomware, TruStage is sharing some strategies.

“Responding to the immediate threat of a ransomware attack or any cyber incident in a timely manner is critical to minimize data loss, contain the threat and restore operations,” Chris Gill, TruStage senior manager, risk and compliance solutions, told CUToday.info. “This is true even when that threat originates with a credit union’s third-party service provider or partner. Security incidents that do not originate at a credit union can still have a large impact on credit unions’ operations and reputation.”

Noting the affects such attacks have on member service, Gill added, “It reminds us all of the importance of having strong controls in place to minimize exposure, and to have a comprehensive business resiliency plan that is regularly tested and updated.”

Comments

Popular posts from this blog

Cutting Through The Stablecoin Noise—What Credit Unions Actually Need To Know Now

By Ray Birch DOVER, Del.—By any measure, stablecoins have quickly become one of the most talked-about—and least understood—topics in credit union boardrooms. The pressure to “do something” is building, fueled by headlines, fintech momentum and a growing fear of being left behind. But according to InvestiFi CEO Kian Sarreshteh, that urgency may be misplaced. “There’s a lot of FOMO right now,” Sarreshteh said. “If I don’t adopt a stablecoin solution this year, I’m going to be left behind. I would argue pretty strongly that’s very far from the truth.” Instead of rushing to sign up for a Stablecoin pilot, Sarreshteh said credit unions should begin with a more fundamental question: what problem are you actually trying to solve? While stablecoins are often discussed as a potential challenger to traditional payment rails dominated by Visa and Mastercard, he believes that kind of mass-market disruption remains years away—especially in the U.S., where consumers already have fast, convenient opt...

Senate Banking To Vote Thursday On Landmark Digital Assets Bill

“NCOFCU appreciates the Senate Banking Committee’s continued work during next week’s markup hearing to establish a clear and responsible regulatory framework for digital assets,” said the National Council of Fire Fighter Credit Unions (NCOFCU) leadership. “As lawmakers consider this legislation, it is essential that first responder credit unions are recognized as a vital part of the financial services ecosystem and are not overlooked in the evolving digital asset landscape. Credit unions serving police, fire, EMS, and other emergency personnel must have equitable access to innovation, regulatory clarity, and the tools necessary to continue supporting the financial readiness and resilience of America’s first responders.” Grant Sheehan CEO WASHINGTON—The Senate Banking Committee will vote on the long-awaited CLARITY Act this Thursday, Committee Chairman Tim Scott (R-SC) announced Friday. Tim Scott The announcement marks a potentially major step forward for legislation that would establis...

Meeting Portals - Why Choose MyBoardPacket.com

MyBoardPacket is known as the simplest, most secure, and affordable online board packet solution. A low monthly fee, with no setup fee, no annual contracts, free customer support and unlimited users! We use MyBoardPacket.com here at NCOFCU, and we love it! Exclusive discount of 25% for NCOFCU Members! Additional discounts are granted for small asset size credit unions! Why choose MyBoardPacket over other meeting portals? The Facts: MyBoardPacket was the first secure board portal on the market, starting in 2001. So easy to use that no training is required! However, for your peace of mind, you have unlimited support and training with your very own Trainer, which any Admin can schedule whenever needed. Unlimited users , committees, and meetings from anywhere! On MyBoardPacket everyone is on the same page . Month-to-month subscription – our customers are with MyBoardPacket because they love it, not because they are locked into a lengthy contract! MyBoar...

Just Out! - NCUA Stablecoin Plan Opens Door To Credit Union-Backed Digital Dollar Issuers

ALEXANDRIA, Va.—A sweeping new NCUA proposal to implement the GENIUS Act could open the door for credit union-backed stablecoin issuance, but only through separately licensed subsidiaries operating under an extensive new federal regulatory framework that limits risks to the Share Insurance Fund. The 269-page supplemental proposed rule issued Friday lays out how “permitted payment stablecoin issuers” affiliated with federally insured credit unions would be supervised, examined and regulated by the NCUA, while also establishing rules covering reserves, liquidity, custody, operational risk, cybersecurity, anti-money laundering compliance and disclosure standards. The proposal supplements an earlier February 2026 proposal by the agency focused primarily on licensing and investments in stablecoin issuers. Federally insured credit unions themselves would still be prohibited from directly issuing payment stablecoins under the GENIUS Act. Instead, issuance would have to occur through a separa...

The Most Overlooked Growth Opportunity in First Responder Credit Unions

Credit unions spend enormous amounts of time, energy, and marketing dollars trying to acquire new members. But many institutions — especially sponsor-based first responder credit unions — are sitting on one of the most valuable growth opportunities already inside their existing membership base. The joint owner population. Every day, firefighters, police officers, EMTs, dispatchers, and other first responders join credit unions through sponsor relationships. During account opening, spouses or partners are often added as joint owners for convenience. They help manage the household finances. They use the debit card. They log into online banking. They interact with the credit union regularly. Yet in many cases, they never actually become full member-owners of the cooperative. They are connected to the institution — but not fully part of it. And that creates a major strategic opportunity. Why Joint Owner Conversion Matters For sponsor-based credit unions, converting joint owners into full m...

NCUA - How Many NCUA Staff are Leaving, & What Are They Taking With Them? Here are 3 Viewpoints

ALEXANDRIA, Va.–NCUA may have already reached its target of reducing staff by 20% as the Trump administration pressures regulatory agencies to reduce headcount, although the agency has not confirmed what several people said they are hearing. Thos same individuals have also expressed their concerns that a lot of “institutional memory” may be headed out the door. During a podcast hosted by Mark Treichel, who during his 33-year career worked his way up from examiner to executive director, John McKechnie, an advocate for credit unions on Capitol Hill who spent five years at NCUA as director of public and congressional affairs, and Geoff Bacino, who now leads an association management firm and who served on the NCUA board, shared what they have heard from inside NCUA regarding the staff reductions. Mark Treichel Updates & Board Meetings The NCUA board was to hear an update on that issue during its April board meeting, but after board members Todd Harper and Tanya Otsuka were fired by Pr...

Hood: Credit unions are safe and sound

Hood’s term on the NCUA Board will expire in August.  NCUA Board Member Rodney Hood appeared via live stream with Brad Barnes, Air Academy Credit Union, and Amy McGraw, Tropical Financial Credit Union. The regulator lauds strong membership, asset, and loan growth. Despite recent headwinds, including high-profile bank failures, the credit union movement is still safe and sound, says Rodney Hood, NCUA board member, and immediate past chairman. “We’re not seeing the contagion like at other financial institutions,” says Hood, who addressed the 2023 CUNA Finance Council Conference Monday via live stream. The Silicon Valley Bank (SVB) crisis was one of confidence, he says. Ninety percent of SVB’s deposits were uninsured. In comparison, more than 91% of credit union deposits are insured. “We don’t have those entanglements,” Hood says. “That bodes well for our future.”  He lauded America’s 4,800 credit unions for growing membership to 135 million, assets to $2.2 trill...

CEOs of CUNA, NAFCU Offer First Public Remarks Since Announcing Merger Plan; Numerous Issues Discussed

COLORADO SPRINGS, Colo.–The CEOs of CUNA and NAFCU made their first joint appearance  since the two trade groups announced plans to merge, addressing reasons for the proposed merger and what those who may oppose the merger should do, and further speaking to the concerns of smaller CUs and what will happen with conferences, as well as stressing the combination is not being driven by problems at either group. During a 45-minute Q&A at the Defense Credit Union Council (DCUC) annual meeting, CUNA CEO Jim Nussle and NAFCU CEO Dan Berger answered questions posed by DCUC CEO Tony Hernandez, as well as from CUToday.info and members of the audience. As CUToday.info reported here , the two trade groups are proposing to merge and create a new organization called America’s Credit Unions that will be led by Nussle—who was appearing at the DCUC meeting on the 89 th anniversary of CUNA’s creation--with Berger departing NAFCU at year-end. At one point Berger received a standing ...

Credit Unions Look For Answers After NCUA Shake-Up

FAQ on Recent Firing of NCUA Board Members ,   click here. WASHINGTON—Do Todd Harper and Tanya Otsuka have legal standing to contest their removal from the NCUA board by President Donald Trump? Has any past president taken similar action? Can NCUA continue functioning without a quorum on its board? Is this the first step toward consolidating federal banking regulators? In light of President Trump’s decision to remove Democratic NCUA board members Harper and Otsuka, many in the credit union community have expressed concerns and raised important questions. In response, America’s Credit Unions has prepared a detailed Q&A document addressing the implications of the White House’s actions announced on Wednesday. Below are key takeaways from the document ACU has shared with its members: President Trump may now nominate either one or two new board members to fill these vacant positions. At least one must be from a different political party, as statutorily required by the FCU Act. Or, l...

2 Historical Moments: CUNA Mutual Officially Changes Name Today, As Union Also Calls Strike

MADISON, Wis.–One of the most iconic names in credit unions and credit union history in the U.S. will officially change today when CUNA Mutual Group begins operating under the TruStage brand across the enterprise. All enterprise, business-to-business and consumer brands are now unified under the single brand name of TruStage, which the company has been using for some of its products for a number of years. The new brand is being introduced at the same time approximately 450 employees represented by Office & Professional Employees Local 39 have gone on strike. It is the first strike in the company and the union's history. As CUToday.info has been reporting, the company and the union have been at an impasse since February of 2022, when t...