Additional Details of CU’s Suit Against TruStage Over System Shutdown are Revealed in Filing

GREENVILLE, Penn. — As the CU Daily was first to report, a Pennsylvania credit union has filed suit over the ongoing system shutdown at TruStage, alleging the company failed to implement and maintain adequate, industry-standard cybersecurity safeguards. 

Now, a review of the filing by the CU Daily reveals additional details in what is being alleged over the event, which TruStage disclosed on July 15, 2026.

Alleging that one of the credit union industry’s leading providers of cybersecurity and financial protection services failed to adequately secure its own systems, Bessemer System Federal Credit Union has filed a proposed nationwide class-action lawsuit against TruStage Financial Group following the company’s recent cybersecurity incident.

Charles Nerko of NERKO PLLC, an attorney to the credit union and the proposed class, the lawsuit, brought on behalf of a proposed nationwide class of credit unions and individuals affected by the breach, seeks damages, recovery of payments made for allegedly deficient services, reimbursement of breach-related expenses, and declaratory and equitable relief.

TruStage Responds

In response to a query from the CU Daily, TruStage issued a statement saying, “TruStage is approaching this incident responsibly and transparently, with a focus on continuing to support business partners, customers and other stakeholders while response efforts continue. As a matter of policy, TruStage does not comment on pending litigation.”

The Allegations

The lawsuit, filed in the U.S. District Court for the Western District of Wisconsin, seeks class-action status on behalf of credit unions and their members nationwide that allegedly were affected by the incident. The complaint accuses TruStage of negligence and alleges the company failed to implement commercially reasonable cybersecurity safeguards despite marketing itself as a trusted provider of cybersecurity, risk management and insurance products for credit unions.
The allegations have not been proven in court, and TruStage had not filed a response to the complaint as of Friday.

‘Entrusted With Confidential Information’

According to the lawsuit, Bessemer System FCU entrusted TruStage with confidential information belonging to both the credit union and its members while purchasing a variety of products and services from the Madison, Wis.-based company. The complaint notes that TruStage markets cybersecurity protection through its Business Protection Solutions Suite, along with lending protection products such as Guaranteed Asset Protection (GAP), employee benefit investment platforms and other financial services.

The complaint argues that this makes the alleged security failures particularly significant because TruStage “provides Cybersecurity Protection to credit unions across the country” while representing that it maintains safeguards designed to protect customer information.

Bessemer FCU alleges TruStage represented in its privacy policy that it maintained physical, technological and administrative safeguards to protect customer information and, in security materials provided to credit unions, stated that it regularly backed up production data, monitored systems for errors and conducted annual recovery testing to ensure critical business processes could be restored in a timely manner. The lawsuit alleges those representations influenced credit unions’ decisions to enter into and maintain long-term business relationships with the company.

Network Shutdown

The lawsuit stems from TruStage’s July 15 announcement that it was responding to a cybersecurity incident after unauthorized parties allegedly accessed its systems. According to the complaint, the company shut down portions of its network to contain the incident, resulting in disruptions that affected customer access to certain systems and support channels, Guaranteed Asset Protection claims, Mechanical Repair Coverage claims and Payment Protection products.

The complaint further alleges customers experienced difficulty accessing account information, completing online transactions and submitting requests. It also states that some credit unions temporarily lost access to employee retirement accounts, including 401(k) plans, and that “normal business operations with TruStage have come to a halt.”

Bessemer FCU contends TruStage knew or should have known its security controls were inadequate given the increasing threat posed by attacks targeting third-party service providers. The lawsuit alleges the company failed to implement industry-standard cybersecurity safeguards, allowing threat actors to gain unauthorized access to its network.

Costs Incurred
According to the complaint, credit unions affected by the incident have incurred costs associated with investigating suspicious activity, monitoring member accounts, mitigating fraud risks, protecting members against potential identity theft and responding to the operational disruption caused by the incident. It further alleges credit unions continued paying for services they believed met contractual and regulatory security requirements because they relied on TruStage’s representations regarding its cybersecurity practices.

The lawsuit also cites industry research indicating third-party vendors have become an increasingly common source of cybersecurity incidents. It references studies stating approximately 30% of reported data breaches involve third-party providers and notes research estimating the average global cost of a data breach at nearly $4.9 million, with third-party breaches often proving more costly because they disrupt multiple organizations simultaneously.

The Potential Class

The proposed class would include “all credit unions (including credit union members) in the United States who provided Confidential Information to TruStage and were impacted by the Data Breach,” according to the complaint. The suit was filed under the federal Class Action Fairness Act, which the complaint says applies because the proposed class exceeds $5 million in controversy.
The complaint asserts a single count of negligence and seeks unspecified damages, reimbursement for breach-related losses, indemnification or contribution, attorneys’ fees, litigation costs, interest and other relief the court considers appropriate.

Facebook
Twitter
LinkedIn

6 Responses

  1. Not to mention the anxiety and duress that long time account holders that 401K participants are going through during this time.

  2. This is so stressful and they should be accountable for us.we trusted them now we don’t know if we ok are not.they should have to tell us what’s included in this breach.and make it right with us

  3. This has been an absolute sh*t show since July 13th while working with the annuity side of TruStage. We have members who have not gotten their monthly deposits (who depend on this money), members who have requested withdrawals from their annuities and those have not processed.
    I had to Google what the heck was going on since I couldn’t login or get in touch with anyone on the phone – the only explanation given was “technical difficulties.” Not to be able to reach a company for a whole week when dealing with people’s money is absolutely absurd.

  4. I am absolutely outraged that this is continuing on. I will be pressing my company HR managers to provide a new 401K provider…having my retirement account “suspended” for an unspecified time period is unacceptable. And there is zero transparency with these clowns…and by the way, their own agent told me phone that they had been frozen since the attach on Saturday the 11th…not Monday the 13th as reported.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.