Principle Security Principle Security.

Credit union security · Vendor incident

The TruStage incident is now your credit union's problem to document.

A calm, factual response guide for credit unions. What is confirmed, what is not, and the steps your examiner will expect you to have taken, whatever the final scope turns out to be.

Free checklist

Get the response checklist

Free · NCUA Part 748 aligned · sent to your inbox immediately

We'll email the checklist and occasional credit union security briefings. No spam, unsubscribe anytime. See our privacy policy.

Situation status

What is known, and what no one can responsibly claim yet

Updated August 3, 2026. First published July 22, 2026.

✓ Confirmed

Publicly established

  • On July 14, TruStage (formerly CUNA Mutual Group) took parts of its network offline to contain a cybersecurity incident.
  • On July 15, TruStage disclosed the incident and engaged outside cybersecurity experts.
  • Member-facing services were disrupted for weeks: claims, GAP and payment-protection servicing, retirement accounts.
  • On July 17, the first class action was filed (Bessemer System FCU v. TruStage).
  • Phased restoration is underway; TruStage is targeting mid-August for basic servicing, including billing and claims.
⚠ Not yet confirmed

Unestablished as of today

  • Whether any member or credit union data was accessed or exfiltrated.
  • How many individuals are affected.
  • Whether ransomware was involved. TruStage calls scope conclusions premature.

To be clear: a TruStage outage does not touch your credit union's own deposits, cards, ATMs, or online banking. This is your vendor's incident, which makes it your vendor-management obligation.

Why we are not shouting "breach"

As of today the scope is unconfirmed and no data exposure has been established. Treating an unconfirmed incident as a confirmed breach is how credit unions misinform their members and lose examiner credibility. We will sharpen this guidance the moment TruStage confirms facts, and not before.

What this triggers

Even unconfirmed, this is a Part 748 event

A cybersecurity incident at a core vendor is exactly the event that NCUA Part 748 vendor management and incident response expectations are written for. Whether or not data is ultimately confirmed exposed, your examiner will expect to see that you identified your exposure, assessed member impact, and documented your response.

That work does not wait for TruStage's final report. It starts today, and a clean record of it becomes evidence of a functioning third-party risk program at your next Information Security Examination.

Jul 15
Incident disclosed

TruStage publicly confirmed the cybersecurity incident.

72 hrs
NCUA reporting window

The clock a reportable cyber incident starts for your CU.

Part 748
The rule in play

Vendor management and incident response, examiner-tested.

Your response checklist

Ten steps to take now, in order

Prefer the working document? Grab the printable checklist: five pages with per-step exam evidence, a TruStage exposure map, the seven vendor questions, member-comms starter language, a board briefing outline, and a response log.

  1. 01

    Confirm your exposure

    Inventory every TruStage product, data feed, single sign-on, and integration your credit union uses, including whether member lists were ever shared for marketing programs. You cannot assess risk you have not mapped.

  2. 02

    Assign an owner, preserve every notice

    Designate one person to hold all TruStage communications and maintain a dated response timeline from the first notice onward.

  3. 03

    Assess member impact and prepare accurate comms

    Identify which members use affected products. Draft messaging that is factual and does not overstate a scope no one has confirmed.

  4. 04

    Run your NCUA 72-hour analysis

    Evaluate whether this rises to a reportable cyber incident for your credit union, and document the determination either way, even when the answer is not reportable.

  5. 05

    Pull your TruStage vendor file

    Review the contract's incident-notification clause, SLAs, right to audit, indemnification, and cyber-insurance provisions. Know what TruStage owes you.

  6. 06

    Put your questions to TruStage in writing

    Scope of your data, forensics status, IOCs, restoration commitments, notification responsibility, member protection, updated assurance. File every answer; verbal reassurance is not evidence.

  7. 07

    Tighten interim controls

    Rotate shared credentials or API keys tied to TruStage. Warn staff and members about phishing that impersonates TruStage or your credit union during the confusion.

  8. 08

    Prepare for a data-confirmation scenario

    If TruStage later confirms data exposure, be ready for GLBA and state member-notification obligations. Draft that playbook now, while it is calm.

  9. 09

    Document everything for your exam

    A clean record of this response is direct evidence of a working third-party risk and incident program for your next ISE.

  10. 10

    Debrief and improve

    Use this event to update your vendor-risk program and incident response plan for the next vendor incident, because there will be one.

Want a second set of eyes before your examiner asks?

We help credit unions work through vendor incidents like this one, and build the programs that make the next one routine. Bring us your TruStage exposure and we'll walk your team through the response.