Cyber Incident Victim: TruStage
Date:
Jul 2026
Location:
United States of America
Summary
TruStage reported a cyber incident after detecting unusual network activity and shutting down systems to contain the threat. Investigators believe the breach originated when an employee inadvertently downloaded a malicious file while attempting to install a legitimate software tool. The company has begun restoring systems in a controlled, prioritized manner, with most credit insurance and debt protection products operational and temporary manual workarounds supporting claims processes, GAP waiver issuance, and bond and business protection coverage renewals, while its cloud‑based Compliance Solutions remained unaffected. The company is working with external cybersecurity experts, law enforcement, and regulators, and has set up a streamlined reporting process with the NCUA for credit unions that may need to report the incident, noting it is still too early to determine whether any data was accessed.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 0 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On July 11, 2026, TruStage detected unusual activity on its network and immediately shut down systems to contain the incident. Later, the company disclosed that investigators believe the attack began after an employee inadvertently downloaded a malicious file while attempting to install a legitimate software tool. The incident was disclosed earlier in the month, and TruStage began working with external cybersecurity experts, law enforcement, and regulators to investigate. President and CEO Terrance Williams communicated the update in a video message, noting that both the investigation and recovery work were ongoing.

TruStage has entered the next phase of recovery and is restoring systems in a controlled, prioritized manner over the coming days and weeks. The company reported that most credit insurance and debt protection products are now operational, while temporary manual workarounds support some claims processes. Workarounds have also been implemented for credit union partners issuing GAP waivers, and bond and business protection coverage renewals continue to be supported. TruStage noted that its cloud-based Compliance Solutions products were not affected by the incident. The company has established a streamlined reporting process with the NCUA for credit unions that determine the incident is reportable.
Williams cautioned that it is still too early to determine whether any data was accessed during the attack. He stated that it is premature to draw conclusions about data access and that the company will share information when it can. Williams added that certain details cannot be disclosed because of the ongoing investigation and potential legal, regulatory, and security considerations. The recovery effort remains ongoing as TruStage continues to work with its external partners to restore full service.
