The TruStage Cybersecurity Incident: A Practical Guide for Credit Unions

A vendor reports a cyberattack. Services are disrupted, members have questions, and the investigation is still underway. Your credit union needs a clear process for assessing the impact, protecting members, and determining whom to notify, even before all the facts are available.

The TruStage incident provides a timely reminder to review that process. The summary below reflects incident updates through September 18, 2026, followed by practical steps to strengthen your credit union’s response. 

What We Know About the TruStage Incident

TruStage identified a cybersecurity attack on July 11, 2026, and publicly disclosed the incident on July 15 (TruStage recovery update, TruStage incident statement). Its updates and related reporting describe the following:

  • Reported likely cause: TruStage said a workforce member may have inadvertently downloaded a malicious file while attempting to install a legitimate software tool, describing a preliminary investigative conclusion rather than a final finding (CU Daily).

  • Containment and recovery: TruStage reported that the incident had been contained, engaged cybersecurity firm Mandiant, and rebuilt portions of its infrastructure rather than simply restarting affected systems (TruStage recovery update).

  • Continuing disruption: As of the September 18 updates, claims submission, processing, payouts, policy servicing, and disbursements remained partially available, with some manual processes and longer processing times (TruStage recovery dashboard).

Important questions remained unresolved:

  • Potential data compromise: The investigation into whether member or employee information was affected remained underway; as of September 17, TruStage expected approximately two more months to complete it, without identifying confirmed affected individuals or data categories in that update (CrossState Credit Union Association).

  • Member notifications: TruStage said it would notify an affected credit union before notifying its members and coordinate the notification process if the investigation determines that member information was impacted (CrossState Credit Union Association).

  • Ransomware and attribution: The official public updates reviewed did not establish whether ransomware was involved or identify an attacker (TruStage incident statement, TruStage recovery dashboard).

Know When the Reporting Clock Starts

Federally insured credit unions must notify the NCUA of a reportable cyber incident as soon as possible, but no later than 72 hours after reasonably believing one has occurred; for qualifying third-party incidents, the deadline runs from that reasonable belief or the third party’s notification, whichever is earlier (12 CFR 748.1(c)). The initial report is an early alert, not a completed investigation, so a vendor’s ongoing investigation does not postpone an otherwise applicable reporting deadline (NCUA reporting guide).

Not every vendor incident automatically triggers a report: the incident must be substantial and meet the rule’s criteria involving loss of system confidentiality, integrity, or availability; cyberattack-related disruption; or disruption or sensitive-data exposure caused by a qualifying third-party or supply-chain compromise (12 CFR 748.1(c)). Assess the impact on your credit union’s systems, information, operations, and members, and document the basis for your reporting decision. 

Make Reporting Easy to Execute

Keep primary and backup contacts, reporting instructions, and an incident log accessible outside your normal network. Assign someone to track the deadline, record what was known at each decision point, and coordinate follow-up.

The NCUA accepts reports through its online reporting system, by voicemail at 1.833.292.3728, or through its Secure Email Message Center to cybercu@ncua.gov (NCUA reporting guide). Be prepared to provide the credit union’s name and charter number, the reporter’s name and title, a callback number, the relevant date and time, and a general description based on what is known; do not include sensitive personal information, indicators of compromise, specific vulnerabilities, or email attachments in the initial notification (NCUA reporting guide). 

Protect Members Based on the Actual Exposure

NCUA guidance calls for a risk-based response, including containment, evidence preservation, and monitoring, freezing, or closing affected accounts as appropriate (Appendix B to Part 748). Rather than defaulting to replacing every potentially exposed member number, consider what the number allows someone to do and which controls would meaningfully reduce the risk:

  • Internal identifier: Determine whether changing the number would provide meaningful protection.

  • Transaction account number: Evaluate replacement if unauthorized activity has occurred or other controls cannot adequately address the exposure.

  • Login or authentication identifier: Address compromised credentials and authentication directly; changing a member number alone may not resolve the risk.

If numbers change, plan for direct deposits, automatic payments, checks, and linked accounts. Confirm how the old number will be restricted and explain any necessary steps to affected members.

Check Other Notification Duties

The 72-hour report is not the only notification consideration. Appendix B separately addresses notice to the NCUA regional director and, for state-chartered credit unions, the applicable state supervisory authority as soon as possible after becoming aware of unauthorized access to or use of sensitive member information (Appendix B to Part 748).

Affected members should be notified as soon as possible when a reasonable investigation determines that misuse has occurred or is reasonably possible, subject to a qualifying written law-enforcement request to delay notification (Appendix B to Part 748). A service provider may assist with notifications, but the credit union remains responsible for notifying its members and regulator (Appendix B to Part 748). 

Use a separate checklist to evaluate applicable state breach laws, law-enforcement and Suspicious Activity Report obligations, and insurance or contractual notice conditions. Keep those assessments separate from the NCUA’s 72-hour reporting analysis. 

Take One Practical Step Now

If a serious vendor notice arrived tonight, would the person receiving it know what to do? Confirm your contacts, update your reporting checklist, and test one realistic scenario before an actual incident tests your plan. Crimson Oak Strategies can help you review your incident-response procedures and reporting checklist. Contact us at info@crimsonoakstrategies.com to discuss your credit union’s needs.

Next
Next

Vendor Management is Business Management