CSIDB logo
Incident

TruStage

Incident posture

Attack window
Jul 2026
Location
United States of America
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-26 19:29

Linked entities

Victim
TruStage
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Undetermined
Discovered
Jul 2026
Disclosed
Jul 2026
Resolved
Pending

Summary

TruStage detected unusual network activity and shut down its systems after an employee inadvertently downloaded a malicious file while attempting to install a legitimate tool. The company has been working with external cybersecurity experts to restore services in a controlled, prioritized manner, bringing back basic servicing, call centers, claims processing and billing for many customers while maintaining policy continuity for missed payments. Although most key business processes are nearing operational restoration, a thorough data review to determine whether member or employee information was accessed is expected to take several months, during which affected credit unions will be notified first if any compromise is found. Numerous lawsuits have been filed by consumers and credit unions alleging disruptions stemming from the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On July 11, 2026, TruStage detected unusual network activity and immediately shut down its systems to contain the incident. The company later stated that the attack likely began when an employee inadvertently downloaded a malicious file while attempting to install a legitimate software tool. Following the shutdown, TruStage engaged external cybersecurity experts, including Mandiant, law enforcement and regulators to investigate and begin recovery. By July 21, TruStage reported that it had started restoring systems in a controlled, prioritized manner, emphasizing that it would not sacrifice quality, security or reliability for speed. The retirement call center was already operating, while life and annuity call centers were scheduled to reopen on August 14, with basic servicing expected to be operational for the majority of its businesses by mid‑August. During the recovery, TruStage resumed paying preplanning and funeral claims, GAP claims, debt protection and credit insurance benefits, and prioritized life and accidental death and dismemberment claims that were pending when the outage began. Billing was restored for a large segment of customers, and the company announced that policies would remain active for consumers who missed payments during the disruption. Temporary manual workarounds were implemented to support some claims processes and to assist credit union partners issuing GAP waivers, while bond and business protection coverage renewals continued to be supported. TruStage noted that its cloud‑based Compliance Solutions products were not affected by the incident. The company also established a streamlined reporting process with the NCUA for credit unions that determine the incident is reportable.

As of August 12, TruStage reported that it was nearing its mid‑August target for restoring most key business processes, although customers might initially experience higher call volumes and longer handling times. The firm said it was working with Mandiant and data analysis firm Epiq Global to determine what information, if any, had been accessed during the attack, a process expected to take another two to three months. TruStage’s President and CEO Terrance Williams stated that if credit union member or employee data were found to be compromised, affected credit unions would be notified first and the company would assist with required notifications and regulatory reporting. Legal records showed that on July 17, the $47.2 million Bessemer System Federal Credit Union filed a proposed class action against TruStage in the U.S. District Court for the Western District of Wisconsin, six days after the cyberattack. Numerous consumers subsequently filed cases in the same court, with lawsuits initiated by Marylou Peixoto and Johna Nivens on July 20 and 21, followed by cases involving Linda Kroutter, Kenneth Delin, Mozzell Brown and others. Additional suits were filed through July 29, including those by Andrea Belley, Hannah Blackmon, Nina Lyle‑Douville, Jeffrey Turner, Ruthie Coleman and Tammy Collette, bringing the total number of filed cases to fourteen as of the August 12 update. The lawsuits generally alleged that consumers and credit unions suffered disruptions stemming from the cyberattack. Throughout the incident, TruStage maintained that it was too early to draw conclusions about whether any data had been accessed, emphasizing its commitment to sharing information when possible while respecting ongoing investigation and legal considerations. The company continued to work with external experts, law enforcement and regulators as the investigation and recovery effort progressed. TruStage’s recovery efforts remained ongoing, with the organization focused on restoring services, assessing potential data exposure and addressing the legal claims arising from the incident.

Sources

Sources available to members: 2 sources.

CSIDB