Skip to main content

What You Can Do About Ransomware Threat

By Ray Birch

RANCHO CUCAMONGA, Calif.—In the wake of a ransomware attack that shut down 60 credit unions, cyber security experts are warning many CUs are just one compromised key supplier away from being shut down, too. It’s a growing threat they say can have numerous  downstream effects on many organizations.

No institution is immune, and the best line of defense remains educating employees on how to avoid making mistakes that place a credit union, CUSO or vendor right into the hands of criminals.

“Co-op Solutions views ransomware attacks as an industry-wide threat that will continue for the foreseeable future with two main threat areas of concern,” said Christopher Williams, deputy chief information security officer at Co-op.

Feature Ransomware

The two areas of concern, according to Williams, are Ransomware-as-a-Service (RaaS) models and cyber supply chain threats.

A Proliferating Model

“With the RaaS model, an attacker doesn’t need to develop their own ransomware capability to turn a system compromise into a ransomware attack. This model has proliferated the cybercrime world. The model can quickly incorporate new tactics, techniques and procedures (TTPs) to be used by a wide range of threat actors,” he said. “The second threat area is the cyber supply chain. Attacks against key suppliers have a ripple effect across the supplier’s client-base. Many companies are one compromised key supplier away from a business crippling service impact.”

How to Respond

wlliams

Christopher Williams

Given that growing threat, what should credit unions be doing now?

“Credit unions should continue to educate their employees on the risk of ransomware attacks and the methods used to gain initial unauthorized access,” Williams advised. “Phishing remains a top attack vector, and social engineering of the service or help desk to compromise user credentials is on the rise.”

Credit unions also need to have robust backup capability—restoring to a clean and non-infected copy of system data, Williams added.

“That can help with the recovery of a ransomware attack,” he said. “In addition, they should become active members of the local area U.S. Secret Service Electronic Crimes Task Forces (ECTF) or Financial Crimes Task Forces (FCTF), which can provide advice in preventing attacks and support during suspected or actual attacks. In addition, monitor threat intelligence type sources for indications of attacks against their organizations or their vendors and new TTPs being used by attackers.

“Finally, practice the incident response to a ransomware attack. Drilling the panic and unknowns out of the process will help increase the chance of a successful recovery if an actual attack occurs,” he said.

The Good News? CUs Not Alone

Jim Stickley, CEO of Stickley on Security, said credit unions are one of many industries being affected by ransomware.

“I am not certain that ransomware is specific (to any organization), and credit unions and fintechs are just part of the much bigger picture of the state of ransomware in general,” said Stickley, who is also CEO of Troy, Mich.-based Mahalo Technologies. “Most people have this idea that cybercriminals are targeting a specific business type. While it’s true that healthcare and education are targeted directly and we also see banks and credit unions get targeted, when it comes to more general business, such as fintechs, we have not seen that level of direct attacks. Instead, what you see is employees who fall victim to phishing attacks or malicious websites.”

‘Average’ People, Not an Average Website

Stickley said when those incidents are investigated, what’s all-to-often discovered is that it was a phishing email that had been sent to hundreds of thousands of organizations that is the culprit, often in in the guise of te malicious websites that have been promoted though malvertising to “average” people. 

stickleyJim

Jim Stickley

“In these cases it’s just the low-hanging fruit. If an employee clicks the link, opens the attachment or browses to malicious sites, they open the door to the criminals. The criminals really don’t care if that organization is fintech, credit union or other business segment,” said Stickley, adding adding he does not believe the recent attack that hit DP vendor Fedcomp and than affected 60 credit unions had any company or credit union as a specific target.

“For criminals, there is little need to put a direct focus on fintech at this time since just about every business entity has similar value and so they will continue to cast a very wide net and whoever gets caught up will be their next victim,” he said.

Advice Shared

For credit unions looking to take some practical steps to defend themselves from ransomware, TruStage is sharing some strategies.

“Responding to the immediate threat of a ransomware attack or any cyber incident in a timely manner is critical to minimize data loss, contain the threat and restore operations,” Chris Gill, TruStage senior manager, risk and compliance solutions, told CUToday.info. “This is true even when that threat originates with a credit union’s third-party service provider or partner. Security incidents that do not originate at a credit union can still have a large impact on credit unions’ operations and reputation.”

Noting the affects such attacks have on member service, Gill added, “It reminds us all of the importance of having strong controls in place to minimize exposure, and to have a comprehensive business resiliency plan that is regularly tested and updated.”

Comments

Popular posts from this blog

World's Happiest Country

  World's Happiest Country   Finland was named the world’s happiest country for the ninth consecutive year, the latest World Happiness Report revealed. Nordic countries—including Denmark, Iceland, Norway, and Sweden—also ranked in the top 10.  Analysts attribute Finland’s joy factor to its wealth, social safety network, and high life expectancy, among factors. Afghanistan maintained its place as the world’s unhappiest country. The results were based on answers from roughly 100,000 people in 140 countries and territories. Respondents were asked to rank their life satisfaction on a scale of 0 to 10. Finnish respondents gave an average life satisfaction score of 7.7; Afghans answered 1.4. The US, in 23rd place, reported an average score of 6.8. Explore rankings here . The report's authors cautioned this year that social media use is driving population-level drops in reported well-being among adolescents. Young English...

Regulators Launch Broad Rewrite Of Bank Capital Rules, Eye Lower Requirements

WASHINGTON— Federal banking regulators on Thursday formally launched what could become the biggest rewrite of U.S. bank capital rules in years, unveiling a package of proposals aimed at easing and recalibrating capital requirements across the industry—moves officials say should reduce aggregate required capital for banks of all sizes and free up more capacity for lending. The Federal Reserve and FDIC both advanced the proposals at board meetings Thursday, while the OCC joined the interagency package, Law360 reported. At the center of the package is a long-awaited rewrite of the U.S. “Basel III endgame” proposal for the largest banks, along with a broader companion proposal to make risk-based capital rules more risk-sensitive for smaller and midsize banks as well. Bloomberg reported the changes are designed to relax capital treatment for large lenders, while Law360 said regulators described the package as a comprehensive overhaul intended to finish the delayed Basel implementation and r...

Average 30-Year Fixed-Rate Mortgage At 6.22%

MCLEAN, Va.--The 30-year fixed-rate mortgage inched up this past week, averaging 6.22%, Freddie Mac reported. "The 30-year fixed-rate mortgage edged up this week to 6.22% but remains nearly half a percentage point lower than the same time last year," said Sam Khater, Freddie Mac's chief economist. "Potential homebuyers are poised for a more affordable spring homebuying season than last with the market experiencing improvements in purchase applications and pending home sales.” The 30-year FRM averaged 6.22% as of March 19, up from last week when it averaged 6.11%. A year ago at this time, the 30-year FRM averaged 6.67%. The 15-year FRM averaged 5.54%, up from last week when it averaged 5.50%. A year ago at this time, the 15-year FRM averaged 5.83%. ================================================= Remember, you're not alone with  NCOFCU.org Join/Upgrade Check out some of NCOFCU's additional features: Annual Conference First Responder Credit Union Academy Finan...

Sunday Reading - March Madness, explained

  The Big Dance   March Madness, explained "March Madness" is the well-known name for the NCAA's annual Division I men's and women's basketball tournaments, which determine national champions through a 68-team , single-elimination format. Automatic bids go to 31 conference winners, while 37 at-large selections fill the field. The high-stakes structure—where smaller "Cinderella" schools can upset powerhouses—drives huge viewership and revenue; TV and marketing rights account for roughly two-thirds of the NCAA's $1.4B income in fiscal 2024. The National Inv...

FRB decided to maintain the target range for the federal funds rate at 3‑1/2 to 3‑3/4 percent

  Federal Reserve issues FOMC statement For release at 2:00 p.m. EDT Share Available indicators suggest that economic activity has been expanding at a solid pace. Job gains have remained low, and the unemployment rate has been little changed in recent months. Inflation remains somewhat elevated. The Committee seeks to achieve maximum employment and inflation at the rate of 2 percent over the longer run. Uncertainty about the economic outlook remains elevated. The implications of developments in the Middle East for the U.S. economy are uncertain. The Committee is attentive to the risks to both sides of its dual mandate. In support of its goals, the Committee decided to maintain the target range for the federal funds rate at 3‑1/2 to 3‑3/4 percent. In considering the extent and timing of additional adjustments to the target range for the federal funds rate, the Committee will carefully assess incoming data, the evolving outlook, and the balance of risks. The Committee is strongly com...

James Hunter, Executive Director of Credit Union Development for New Orleans Firemen’s CU, knows too well how expensive it is to be poor.

  NEW ORLEANS FIREMEN’S FCU 􀀁 METAIRIE, L   A passion for empowerment James Hunter knows too well how expensive it is to be poor. It’s what he sees every day as mortgage director and executive director of credit union development for $182 million asset New Orleans Firemen’s Federal Credit Union, Metairie, La., and executive director of The Faith Fund, a nonprofit partnership that seeks to provide a financial hand-up to the undeserved. It’s what inspires him to come to work every day and drives his passion of empowering people and setting them on the path to financial security. “Too many people are too far away from the starting line,” Hunter says. “Payday loans are a big business in Louisiana. Exorbitant fees and interest from payday loans drain more than a quarter of a billion dollars a year. Baton Rouge supports one of the top three pay-day loan markets in the U.S.” The Faith Fund was formed to counteract that. It’s a unique cooperative relationship between like-minded busi...

Sunday Reading - How were the National Parks started?

  America's 'Best Idea'       How were the National Parks started? America's National Park System includes roughly 85 million acres of US territory, equal to the size of Germany, set aside by federal law for preservation. There are 63 areas officially designated as national parks—including the Grand Canyon, the Great Smoky Mountains, and Acadia—and more than 400 additional smaller units ( see map ). In 1872, Yellowstone was established   as the first national park dedicated to public enjoyment and recreation, though its foundation also  displaced several Native American tribes . By 1916, the growing system required the creation of the National Park Service to preserve its lands for future generations. Eventually, hunting and logging were banned in the parks, though regulated extractive activity is still permitted in nati...

A Perfect Example - What Makes Credit Unions Different from Banks!

When the government shutdown hit in October and paychecks stopped, thousands of federal employees were left wondering how to make ends meet. Credit unions across the country stepped up—but Keesler Federal Credit Union went above and beyond. No loans, no hassle—just your paycheck Instead of making members apply for emergency loans, Keesler Federal launched its Paycheck Relief Program. Revolutionary in its simplicity, it worked like this: if you were a federal employee with direct deposit at Keesler Federal, your paycheck kept coming—interest-free, fee-free, and stress-free. Each qualified member could receive up to $6,000 per pay period for as long as 90 days. No hoops, no headaches. From October 1 until the shutdown ended, Keesler Federal advanced more than 5,000 paychecks totaling $6.5 million to 1,710 members. For non-members, they even offered zero-interest loans up to $6,500 with a year to pay it back. This proactive approach meant that before the first missed paycheck, Keesler Fed...

NCUA Board Member Rodney E. Hood Remarks before CUNA’s 2021 Governmental Affairs Conference

    Read Press Release Previewing what may become a major regulatory effort, the two Republican members of the NCUA board on Wednesday said they want to make it easier for organizations to start credit unions. “The NCUA had one new charter last year,” NCUA Board Member Rodney Hood said at CUNA’s annual Governmental Affairs Conference, which is being held virtually this year. “Only two are planned for this year. These data are, quite frankly, unacceptable. The agency can make it incredibly difficult to get a new charter. We aren’t saying chartering a credit union should be easy, but it shouldn’t feel impossible for many organizing groups.” Hood said that fellow Board Member Kyle Hauptman has been focusing on the issue since joining the board and that he supports that effort. “There has got to be an easier path for de novo credit unions,” Hauptman told those attending GAC. “I’m from Maine, and I was pleased to hear about a new credit union chartered in my home state just last ...