TruStage Offers New Update on Cybersecurity Incident; Still Unknown if Member Data Exposed; More Than a Dozen Lawsuits Now Filed

MADISON, Wis. — In a new update, TruStage said it is making “steady advancements” in restoring servics following a cyberattack that has knoocked out services for more than a month but that it will likely be two-to-three months before it knows whether any credit union/member data has been compromised–an issue at the heart of more than a dozen lawsuits the company now faces.

In a new statement, TruStage President and CEO Terrance Williams said the company is making “steady advancements in restoring our technology environment and expanding operational capabilities, while also taking the opportunity to strengthen the technology foundation that will support members, customers, and credit union partners.”

Terrance Williams

In response to the question Williams confirmed many in credit unions have been asking–and which is also the basis for the litigation the company is facing–whether any credit union/member data has been compromised, Williams said, “We know you want answers quickly, and we do too. We’re executing as quickly as we can with the help of Mandiant, our cybersecurity experts, and Epiq Global, a leading data analysis firm,” Williams said. “Because of how complicated this process is, it will likely be 2 to 3 months from now before we have those answers. I understand that timeline may be frustrating, but it is consistent with what happens in these kinds of cases. The time required to get this right will allow us to share accurate information and give you the answers you need. 

“If we determine that your member data or your employee data has been impacted, we are committed to telling you first,” Williams said. “And we will do what we can do to make any notification and regulatory reporting that might be required as easy on you as we can.

As the CU Daily reported here, TruStage said it detected unusual activity on its network on July 11 and immediately shut down its systems to investigate. It has confirmed its systems were breached after “a member of our workforce may have inadvertently downloaded a malicious file while trying to install a legitimate tool.”

The company has not issued any statement regarding whether ransomware is involved.

‘Clean Environment’ Established

Williams said Mandiant, which TruStage has retained  as its “cybersecurity partner,” has confirmed that the company has established a clean, isolated environment that is separate from any systems that were impacted, potentially impacted, or remain under investigation.

“Know that teams are actively working to restore systems and processes in phases using a mix of secure, restored capabilities and interim solutions,” Williams said. “Each of those is tested and validated before coming online.”

Williams said the full restoration across all company systems will take more time than anyone would like, but that TruStage is “using this opportunity to enhance our environment, and our ability to serve you and your members. Our goal is not simply to return to normal, but to emerge even stronger and more secure.”

Priorities and Progress 

In the update, Williams said TruStage remains on track to having most of its key processes operational by mid-August, and further noted:

  • Basic Servicing: “We expect to have basic servicing up and running for the majority of our businesses, including the reopening of our customer contact centers, by our mid-August target.”
  • Call Centers: “Some businesses, such as our retirement call center, are open now, while our life and annuity call centers will open Friday, Aug. 14. Keep in mind, the experience may have hiccups due to higher volumes and longer handling times initially. While not all customer service needs can be addressed at this time, we are committed to enhancing our experiences and capabilities in the weeks ahead.”
  • Claims Payments: “We have started to pay claims across our business, including preplanning/funeral claims, GAP claims and debt protection/credit insurance benefits. For Life and AD&D claims, we are working to restore core processing capabilities, and we will focus first on paying claims that were pending at the time of the outage before moving to claims received post-outage. We will work through this backlog as quickly as possible, but that will take some time.”
  • Retirement and Annuity Plans: Williams said annuity and retirement plan assets have not affected by the cybersecurity attack and that the majority of defined contribution participants, other than those using certain legacy platforms, can now request withdrawals and loans, if allowed under their plan, and request updates on their account balances over the phone.”
  • Billing Activities: “We have resumed billing activities to avoid billing disruptions for a large segment of our consumers and are working on options for consumers who missed a payment. Be assured that those policies will remain active as we work through this process.”

TruStage has published an updated list of FAQs on the outage here

Legal Fallout Grows

Meanwhile, the legal fallout from the cybersecurity incident that forced TruStage to shut down portions of its systems has grown substantially, with a review of federal court records finding at least a dozen lawsuits have been filed against the company in Madison as of Aug. 12.

The cases have been filed in U.S. District Court for the Western District of Wisconsin, where Madison-based TruStage is headquartered. The litigation began just two days after TruStage publicly disclosed the cybersecurity incident July 15, as the CU Daily was first to report here.

A review of federal docket records shows the lawsuits include one brought by a credit union and at least 11 filed by individuals, generally seeking class-action status. Some of the individual cases also name credit unions as defendants.

To date, TruStage has not stated whether any member data has been compromised or exposed. In a statement to the CU Daily the company said it does not comment on litigation.

Information on the public-facing portion of TruStage’s website.

The Cases

The cases identified in the court records are:

  • Bessemer System Federal Credit Union v. TruStage Financial Group Inc., Case No. 3:26-cv-00644, filed July 17.
  • Marylou Peixoto v. TruStage Financial Group Inc. et al., Case No. 3:26-cv-00658, filed July 20. Align Credit Union is also named as a defendant.
  • Johna Nivens v. TruStage Financial Group Inc. et al., Case No. 3:26-cv-00659, filed July 21. First Financial Federal Credit Union is also named as a defendant.
  • Linda Kroutter v. TruStage Financial Group Inc., Case No. 3:26-cv-00661, filed July 21.
  • Kenneth S. Delin v. TruStage Financial Group Inc., Case No. 3:26-cv-00665, filed July 22.
  • Jennifer Brazier v. TruStage Financial Group Inc., Case No. 3:26-cv-00670, filed July 23.
  • Mozzell Brown v. TruStage Financial Group Inc., Case No. 3:26-cv-00672, filed July 23.
  • Jeffrey Turner v. TruStage Financial Group Inc., Case No. 3:26-cv-00680, filed July 27.
  • Nina Lyle-Douville v. TruStage Financial Group Inc., Case No. 3:26-cv-00681, filed July 27.
  • Hannah Blackmon v. TruStage Financial Group Inc., Case No. 3:26-cv-00683, filed July 27.
  • Randall Landers v. TruStage Financial Group Inc. et al., Case No. 3:26-cv-00688, filed July 27. First Financial Federal Credit Union is also named as a defendant.
  • Tammy Collette v. TruStage Financial Group Inc., Case No. 3:26-cv-00698, filed July 29.

Additional Details

Federal docket listings confirm, for example, that the Turner, Lyle-Douville, Blackmon and Landers cases were all filed July 27. The records show Landers named both TruStage and First Financial Federal Credit Union as defendants.

The most recent case identified in the review is Collette’s, filed July 29. Court records classify that action as an “other contract” case and identify breach of contract as the cause of action.

Credit Union Was First to Sue

As the CU Daily was first to report, the first lawsuit came from Bessemer System Federal Credit Union in Pennsylvania, which filed a proposed class action July 17, only two days after TruStage publicly acknowledged the cybersecurity incident.

The complaint seeks to represent Bessemer and other similarly situated credit unions allegedly affected by the shutdown. Court records show the complaint included a jury demand and was assigned to U.S. Magistrate Judge Anita Marie Boor.

Unlike the consumer cases that followed, Bessemer’s lawsuit focuses on alleged harm to credit unions that depend on TruStage products and systems.

About the Attack

The litigation stems from the cyberattack TruStage said it identified in July. The company said July 15 it had “recently identified a cybersecurity incident affecting its environment” and immediately activated incident-response and recovery protocols. TruStage said it brought in outside cybersecurity experts to assist with containment, remediation and recovery.

The incident led TruStage to shut down portions of its network, disrupting services used by credit unions and their members, including some Guaranteed Asset Protection, Mechanical Repair Coverage and Payment Protection services.

TruStage President and CEO Terrance Williams has appeared in two videos offering updates on the shutdown, most recently here.

Consumer Cases Quickly Followed

The first individual case identified in the docket review was filed July 20 by Marylou Peixoto. That lawsuit names both TruStage and Align Credit Union as defendants.

Nivens and Kroutter filed separate cases the following day. Federal court records list both as personal-injury actions, while Nivens also names First Financial Federal Credit Union as a defendant.

The pace of filings accelerated from there, with cases filed by Delin on July 22; Brazier and Brown on July 23; and Turner, Lyle-Douville, Blackmon and Landers on July 27. Collette followed July 29.

The litigation represents allegations by the plaintiffs and does not constitute findings that TruStage or any credit union named as a defendant violated the law or is liable for damages..

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.