Skip to main content

What You Can Do About Ransomware Threat

By Ray Birch

RANCHO CUCAMONGA, Calif.—In the wake of a ransomware attack that shut down 60 credit unions, cyber security experts are warning many CUs are just one compromised key supplier away from being shut down, too. It’s a growing threat they say can have numerous  downstream effects on many organizations.

No institution is immune, and the best line of defense remains educating employees on how to avoid making mistakes that place a credit union, CUSO or vendor right into the hands of criminals.

“Co-op Solutions views ransomware attacks as an industry-wide threat that will continue for the foreseeable future with two main threat areas of concern,” said Christopher Williams, deputy chief information security officer at Co-op.

Feature Ransomware

The two areas of concern, according to Williams, are Ransomware-as-a-Service (RaaS) models and cyber supply chain threats.

A Proliferating Model

“With the RaaS model, an attacker doesn’t need to develop their own ransomware capability to turn a system compromise into a ransomware attack. This model has proliferated the cybercrime world. The model can quickly incorporate new tactics, techniques and procedures (TTPs) to be used by a wide range of threat actors,” he said. “The second threat area is the cyber supply chain. Attacks against key suppliers have a ripple effect across the supplier’s client-base. Many companies are one compromised key supplier away from a business crippling service impact.”

How to Respond

wlliams

Christopher Williams

Given that growing threat, what should credit unions be doing now?

“Credit unions should continue to educate their employees on the risk of ransomware attacks and the methods used to gain initial unauthorized access,” Williams advised. “Phishing remains a top attack vector, and social engineering of the service or help desk to compromise user credentials is on the rise.”

Credit unions also need to have robust backup capability—restoring to a clean and non-infected copy of system data, Williams added.

“That can help with the recovery of a ransomware attack,” he said. “In addition, they should become active members of the local area U.S. Secret Service Electronic Crimes Task Forces (ECTF) or Financial Crimes Task Forces (FCTF), which can provide advice in preventing attacks and support during suspected or actual attacks. In addition, monitor threat intelligence type sources for indications of attacks against their organizations or their vendors and new TTPs being used by attackers.

“Finally, practice the incident response to a ransomware attack. Drilling the panic and unknowns out of the process will help increase the chance of a successful recovery if an actual attack occurs,” he said.

The Good News? CUs Not Alone

Jim Stickley, CEO of Stickley on Security, said credit unions are one of many industries being affected by ransomware.

“I am not certain that ransomware is specific (to any organization), and credit unions and fintechs are just part of the much bigger picture of the state of ransomware in general,” said Stickley, who is also CEO of Troy, Mich.-based Mahalo Technologies. “Most people have this idea that cybercriminals are targeting a specific business type. While it’s true that healthcare and education are targeted directly and we also see banks and credit unions get targeted, when it comes to more general business, such as fintechs, we have not seen that level of direct attacks. Instead, what you see is employees who fall victim to phishing attacks or malicious websites.”

‘Average’ People, Not an Average Website

Stickley said when those incidents are investigated, what’s all-to-often discovered is that it was a phishing email that had been sent to hundreds of thousands of organizations that is the culprit, often in in the guise of te malicious websites that have been promoted though malvertising to “average” people. 

stickleyJim

Jim Stickley

“In these cases it’s just the low-hanging fruit. If an employee clicks the link, opens the attachment or browses to malicious sites, they open the door to the criminals. The criminals really don’t care if that organization is fintech, credit union or other business segment,” said Stickley, adding adding he does not believe the recent attack that hit DP vendor Fedcomp and than affected 60 credit unions had any company or credit union as a specific target.

“For criminals, there is little need to put a direct focus on fintech at this time since just about every business entity has similar value and so they will continue to cast a very wide net and whoever gets caught up will be their next victim,” he said.

Advice Shared

For credit unions looking to take some practical steps to defend themselves from ransomware, TruStage is sharing some strategies.

“Responding to the immediate threat of a ransomware attack or any cyber incident in a timely manner is critical to minimize data loss, contain the threat and restore operations,” Chris Gill, TruStage senior manager, risk and compliance solutions, told CUToday.info. “This is true even when that threat originates with a credit union’s third-party service provider or partner. Security incidents that do not originate at a credit union can still have a large impact on credit unions’ operations and reputation.”

Noting the affects such attacks have on member service, Gill added, “It reminds us all of the importance of having strong controls in place to minimize exposure, and to have a comprehensive business resiliency plan that is regularly tested and updated.”

Comments

Popular posts from this blog

Honoring Our Member Credit Unions Ranked Among the Top 100 in 2025

Celebrating Excellence: Honoring Our Member Credit Unions Ranked Among the Top 100 in 2025   Best-performing US credit unions of 2025 At NCOFCU, we take immense pride in the strength, resilience, and impact of our member credit unions. Today, we are thrilled to recognize and celebrate several of our members who have earned a place among the Top 100 Best Performing Credit Unions of 2025 —a testament to their unwavering commitment to service, financial stewardship, and community leadership. This achievement is not just about rankings—it reflects the daily dedication to members, the trust built within communities, and the innovation that continues to drive our movement forward. 🌟 Our Honored Members We proudly congratulate the following institutions for their outstanding performance: #7 – Long Beach Firemen's Credit Union A remarkable top-10 finish that highlights exceptional operational excellence and member value. Long Beach Firemen’s CU continues to set a high bar for perform...

Fire Police City County FCU rebrands to reflect company growth

FORT WAYNE, Ind. (WANE) – A federal credit union with a long history in the Fort Wayne area is changing its name to something that the company said Tuesday reflects its ability to serve a larger sector. Fire Police City County Federal Credit Union, founded in 1933, will go by Summit Choice Credit Union starting in April. Members and locals will start to notice new signage and aesthetic changes at each branch throughout the month. The rebranding does not affect the credit union’s structure, ownership, or member accounts, according to the news release. Summit Choice Credit Union remains a member-owned financial cooperative, governed by the same principles and operated by the same team.  Its website  reminds members that new cards are being issued due to the rebranding. The credit union was originally formed for the families of local firefighters. Today, it serves employees of more than 350 local businesses around greater Fort Wayne. “Adopting the name Summit Choice Credi...

The United States at 250: How the Country Has Changed in the Past 50 Years

  In July, the United States will celebrate its 250th anniversary. The country’s last major milestone was 50 years ago, at its bicentennial on July 4, 1976. U.S. society has changed profoundly since then. Over the past five decades, the U.S. population has  aged significantly,  with the percentage of people 65 and older nearly doubling. The country has also become  more racially and ethnically diverse,  as growing shares of people identify as Asian or Hispanic. And following more than 70 million immigrant arrivals, the percentage of  foreign-born people  in the population has more than tripled.  Americans are also  less likely to be married  than ever before. Women – who now have far more options outside of the home than they did in 1976 – have contributed to a  boom in higher education  and helped  expand the workforce.  And even though many Americans are financially better off than they were 50 years ago,  econ...

Reading Up On Recessions

  Reading Up On Recessions       Background Stemming from the Latin word “recessus” (meaning “a retreat”), recessions are  sustained periods  of declining activity in a country’s economy. During a recession, unemployment rises while economic output falls across a large swath of industries. Recessions are inevitable in modern economies, with one occurring about every six to seven years ( What causes recessions ?).   One common definition of a recession is when a country logs two consecutive quarters of shrinking gross domestic product, but in practice, ...

Why Avoiding "I" in Marketing Presentations Matters

  Grant Sheehan, CCUE | CCUP | CEO NCOFCU  You know how things just stick with you? Well, many years ago, my marketing professor started off his class with the following, and it has never left me.  The Power of Perspective: Why Avoiding "I" in Marketing Presentations Matters In the world of marketing, effective communication is paramount. One valuable piece of advice that often comes from experienced instructors and industry veterans is the importance of avoiding the use of the word “I” in presentations and reports. At first glance, this may seem counterintuitive; after all, many individuals feel that personal anecdotes and experiences can enhance a message. However, upon deeper reflection, the reasoning behind this approach reveals itself as essential for achieving impactful communication. Building Objectivity When marketing professionals present their findings or insights, it’s important to establish credibility. Utilizing data, surveys, and feedback from cu...

Sunday Reading - Landmine Rat Honored

  Landmine Rat Honored   Cambodia unveiled the world’s first statue honoring a landmine-detecting rat (w/photo) Friday. Magawa the rat lived to 8 years old and identified more than 100 landmines and other explosives from 2016 to 2021.  There are more than 100 African pouched rats deployed in landmine detection operations across the world. To identify mines, the rats are trained to sniff out explosive compounds like trinitrotoluene, or TNT. (The rats are not heavy enough to trigger detonation.) In Cambodia, up to 6 million landmines remain undiscovered, most planted during three decades of conflict, from the Vietnam War era through Cambodia's civil war . Since 1979, roughly 20,000 people have been killed in Cambodia, and roughly 40,000 wounded as a result of the mines. Magawa cleared more than ...

Sunday Reading - The gold standard, explained

  Gold Standard       The gold standard, explained A gold standard is a system where a country’s currency is pegged to, and can be converted into, a fixed amount of gold. It’s typically meant to create a sense of security in the country’s currency: When a government uses a gold standard , its currency can be exchanged for an equivalent amount of gold—although regulations around redemption vary by country.   After the Civil War, in 1873, America adopted the gold standard for the first time. At the time, if gold was priced at $100 an ounce, each dollar  rep...

Open Banking Pushes Leading Credit Unions Ahead In Race For Member Loyalty

  https://youtu.be/pUIV8hwSDCE NEW YORK—Credit unions that embrace open banking aren’t just keeping pace with competitors—they’re pulling ahead, new data show. A new report finds that innovation in digital tools and personalized experiences is emerging as the decisive factor separating credit unions that win lasting member loyalty from those at risk of losing ground. “ The 2025 Credit Union Innovation Readiness Index: Closing Gaps, Winning Members ,” a June report produced in collaboration between  Velera  and PYMNTS Intelligence, underscores innovation as a defining factor for credit union success. iStock-Korakrich Suntornnites “Facing shifting expectations from both consumers and small to medium-sized businesses (SMBs) toward digital convenience and tailored experiences, credit unions must modernize not just to compete with traditional banks, but to remain relevant to their members. The report, based surveys of 500 credit union executives, 15,000 U.S. consumers, and nea...

Sunday Reading - What is the Dow Jones?

    What is the Dow Jones? Created in 1896, the Dow Jones Industrial Average is one of the world’s oldest and most widely recognized stock indexes—a measure tracking the stock performance of a selected group of companies ( see most recent data ). Originally designed to track America’s leading industrial firms, the Dow has evolved into a cultural and financial shorthand for the health of the US economy. As of 2025, it measures 30 major companies —like McDonald's, Boeing, and Nike—across sectors such as technology, healthcare, finance, and consumer goods.  Unlike most modern indexes, which are weighted by the total value of a company’s shares, the DJIA uses a price-weighted formula —meaning stocks with higher share prices exert more influence, regardless of company size. The DJIA has been updated 59 times since its creation to reflect changes in the US economy ( see ch...

Where are your children banking?

  Grant Sheehan CCUE | CCUP | CEO, NCOFCU The B reach  Between Purpose and Experience Just recently, I came across a story that has stayed with me. It wasn’t dramatic in the traditional sense. There was no scandal, no crisis, no headline-grabbing failure. In fact, it was something much quieter than that. It was simply the story of an eighteen-year-old leaving his credit union. On the surface, that might not sound remarkable. Young people move their money frequently. They open new accounts, experiment with apps, follow trends, and often make financial decisions influenced by the digital tools at their disposal. But this story was different. This young man had been a credit union member since he was a few weeks old, as many credit unions do. His mother has spent her career working inside the credit union movement as an executive. For eighteen years, his financial life was connected to a credit union. If anyone might be expected to remain a lifelong member, it wou...