Credit union security · Vendor incident
The TruStage incident is now your credit union's problem to document.
A calm, factual response guide for credit unions. What is confirmed, what is not, and the steps your examiner will expect you to have taken, whatever the final scope turns out to be.
Situation status
What is known, and what no one can responsibly claim yet
Updated August 3, 2026. First published July 22, 2026.
Publicly established
- On July 14, TruStage (formerly CUNA Mutual Group) took parts of its network offline to contain a cybersecurity incident.
- On July 15, TruStage disclosed the incident and engaged outside cybersecurity experts.
- Member-facing services were disrupted for weeks: claims, GAP and payment-protection servicing, retirement accounts.
- On July 17, the first class action was filed (Bessemer System FCU v. TruStage).
- Phased restoration is underway; TruStage is targeting mid-August for basic servicing, including billing and claims.
Unestablished as of today
- Whether any member or credit union data was accessed or exfiltrated.
- How many individuals are affected.
- Whether ransomware was involved. TruStage calls scope conclusions premature.
To be clear: a TruStage outage does not touch your credit union's own deposits, cards, ATMs, or online banking. This is your vendor's incident, which makes it your vendor-management obligation.
Why we are not shouting "breach"
As of today the scope is unconfirmed and no data exposure has been established. Treating an unconfirmed incident as a confirmed breach is how credit unions misinform their members and lose examiner credibility. We will sharpen this guidance the moment TruStage confirms facts, and not before.
What this triggers
Even unconfirmed, this is a Part 748 event
A cybersecurity incident at a core vendor is exactly the event that NCUA Part 748 vendor management and incident response expectations are written for. Whether or not data is ultimately confirmed exposed, your examiner will expect to see that you identified your exposure, assessed member impact, and documented your response.
That work does not wait for TruStage's final report. It starts today, and a clean record of it becomes evidence of a functioning third-party risk program at your next Information Security Examination.
TruStage publicly confirmed the cybersecurity incident.
The clock a reportable cyber incident starts for your CU.
Vendor management and incident response, examiner-tested.
Your response checklist
Ten steps to take now, in order
Prefer the working document? Grab the printable checklist: five pages with per-step exam evidence, a TruStage exposure map, the seven vendor questions, member-comms starter language, a board briefing outline, and a response log.
- 01
Confirm your exposure
Inventory every TruStage product, data feed, single sign-on, and integration your credit union uses, including whether member lists were ever shared for marketing programs. You cannot assess risk you have not mapped.
- 02
Assign an owner, preserve every notice
Designate one person to hold all TruStage communications and maintain a dated response timeline from the first notice onward.
- 03
Assess member impact and prepare accurate comms
Identify which members use affected products. Draft messaging that is factual and does not overstate a scope no one has confirmed.
- 04
Run your NCUA 72-hour analysis
Evaluate whether this rises to a reportable cyber incident for your credit union, and document the determination either way, even when the answer is not reportable.
- 05
Pull your TruStage vendor file
Review the contract's incident-notification clause, SLAs, right to audit, indemnification, and cyber-insurance provisions. Know what TruStage owes you.
- 06
Put your questions to TruStage in writing
Scope of your data, forensics status, IOCs, restoration commitments, notification responsibility, member protection, updated assurance. File every answer; verbal reassurance is not evidence.
- 07
Tighten interim controls
Rotate shared credentials or API keys tied to TruStage. Warn staff and members about phishing that impersonates TruStage or your credit union during the confusion.
- 08
Prepare for a data-confirmation scenario
If TruStage later confirms data exposure, be ready for GLBA and state member-notification obligations. Draft that playbook now, while it is calm.
- 09
Document everything for your exam
A clean record of this response is direct evidence of a working third-party risk and incident program for your next ISE.
- 10
Debrief and improve
Use this event to update your vendor-risk program and incident response plan for the next vendor incident, because there will be one.
Strengthen in advance
Don't wait for the scope to harden your program
The TruStage incident is a preview, not an exception. These are the programs that make the next vendor event routine, and turn your response into examiner-ready evidence instead of a scramble.
Vendor & third-party risk program
Build the oversight that turns the next vendor incident into a routine, documented response instead of a fire drill.
Learn moreIncident response & the 72-hour rule
A tested IR plan and NCUA reporting workflow, so the clock never catches you flat-footed.
Learn moreNCUA ISE & exam readiness
Walk into your Information Security Examination with evidence in hand, not a scramble.
Learn moreSecurity risk assessment (FAIR)
Cyber risk expressed in dollars, so your board funds the right controls before the loss, not after.
Learn morePart 748 security program
A member-information security program built to stand up to examiner scrutiny.
Learn moreVirtual CISO leadership
Senior security leadership that owns the program between the exams and the incidents.
Learn moreWant a second set of eyes before your examiner asks?
We help credit unions work through vendor incidents like this one, and build the programs that make the next one routine. Bring us your TruStage exposure and we'll walk your team through the response.
Explore