MADISON, Wis. — TruStage President and CEO Terrance Williams says one of the biggest lessons from the devastating cyberattack that has disrupted the company for nearly two months is that financial institutions cannot rely solely on their own cybersecurity assessments, while stressing that TruStage remains financially strong and is developing a fund that would provide grants to members who suffered hardship as a direct result of the incident.
Williams, speaking during a 45-minute fireside chat with BCU President and CEO Mike Valentine, said the company is also learning that information technology administrators have become prime targets for increasingly sophisticated cybercriminals and that organizations should never assume their systems are beyond attackers’ reach.

Williams said TruStage intends to share extensively what it has learned from the mid-July attack, including through CEO roundtables he expects to conduct around the country beginning in the first or second quarter of 2027.
At the same time, Williams sought to reassure credit unions about the financial consequences of the attack.
“Our balance sheet is stronger than ever,” Williams said. “We are incredibly sound financially.”
The cyberattack will have a “major, major impact” operationally and will affect TruStage’s financial results in 2026 and 2027, Williams acknowledged. But he said it will not have dire financial consequences or create significant balance-sheet problems.
Williams also disclosed that TruStage is developing what it is calling a “member assistance fund” that would provide grants — not loans or insurance benefits — to people who experienced financial hardship directly attributable to the cyberattack.
“We recognize that some of the inability for us to honor that promise … has caused hardship,” Williams said.
Attack Caused Extensive Damage
Valentine, an 11-year member of TruStage’s board of directors, questioned Williams about the attack, the company’s recovery, criticism of its communications, its financial condition, the potential compromise of data and what TruStage is doing to assist credit unions and their members.
Williams described the cyberattack as devastating not only to TruStage but, indirectly, to the credit union movement.
The attackers damaged major portions of TruStage’s operating environment and compromised many of the backups the company would ordinarily have relied upon to recover from such an incident, he said.
That has forced TruStage to rebuild portions of its technology infrastructure rather than simply restore systems from backups. The company decided to rebuild in the cloud, which Williams said was both the industry-standard response to an attack of this magnitude and a way to make TruStage more resilient and secure in the future.
“Our goal is to recover the organization and get us back to where we were before the attack and get us into a better position even from a long-term standpoint,” Williams said.
Williams acknowledged the recovery has placed a significant burden on credit unions, which have had to use manual processes and workarounds while also responding to members unable to access normal TruStage services.
He said TruStage has failed during the incident to meet the standard it sets for itself as a partner to credit unions.
“I regret the fact that we haven’t lived up to what I’ll call system partner status over the last several weeks,” Williams said.
Lesson No. 1: Get Outside Validation
Asked by Valentine what TruStage has learned, Williams said one of his strongest recommendations to credit union CEOs is to obtain independent, third-party validation of cybersecurity systems.
It is no longer enough, he said, for organizations to depend upon assurances from their own technology and security teams.
The sophistication of cybercriminals has grown exponentially, Williams said, with advances in artificial intelligence providing attackers with increasingly powerful tools.
Williams also repeated a detail TruStage previously disclosed about the origins of the attack: It began after an IT employee downloaded legitimate software used for the employee’s job that had been embedded with malware.
The incident underscores why IT employees with administrative privileges are particularly attractive targets, he said. Gaining access through an administrator can provide attackers with far greater access to an organization’s network.
Williams advised credit unions to harden security protocols and password protections around IT administrators and other employees with elevated system privileges.
“Never assume your systems are such that you are untouchable,” Williams said.
Attacks Haven’t Stopped
The attempted attacks against TruStage have not ended. Williams said the company has faced an “onslaught” of additional attacks since publicly disclosing the original incident.
In one case, he said, a TruStage executive received a call on his mobile phone that appeared on the device to be coming from TruStage. It was instead a threat actor attempting to persuade the executive to download software purportedly needed for security purposes. The executive recognized the call as fraudulent, hung up and reported it to TruStage’s IT staff.

“The number of attacks are just vicious, ferocious, and they are coming at the speed of light,” Williams said.
Williams said he cannot promise TruStage will never again be attacked. In fact, he said, he can “almost guarantee the opposite.”
The objective instead is to build an organization capable of withstanding another attack without experiencing a recovery process similar to the current one.
Among the changes are greater resiliency, third-party security verification and development of applications in a more modular manner so systems can be restored or replaced more easily.
“I still feel very confident that we’ll get through this and we’ll be stronger than ever in the long run,” Williams said.
No Single Date for Full Recovery
Williams said TruStage cannot yet provide a date when all systems will be fully restored because the complexity and age of its technology varies considerably across business lines.
He said the company expects significant progress in Credit Union Protection and lending capabilities over the next two weeks and during the following 30- to 60-day period.
Life insurance will take longer because of the complexity and dependencies associated with those systems, he said. TruStage is relying more heavily on continuity plans in areas where full restoration will take longer. the CEO explained. .
Williams said some of the company’s systems were nearing or had exceeded their expected useful lives, making it necessary to rebuild them differently rather than simply turn them back on.
Simply restoring the old environment also could have posed a security risk, he said, because attackers who penetrate a network may leave behind tools or other means of regaining access.
Rebuilding in the cloud takes more time, Williams said, but should leave TruStage with greater security and resiliency.
Member Assistance Fund Being Developed
Williams devoted part of the discussion to the impact on individual members who have been unable to receive normal service, particularly those attempting to file and receive insurance claims.

TruStage essentially sells a promise, he said — that when a member experiences a time of need, the company will fulfill its obligation by providing financial benefits.
“We’ve fallen down in that regard,” Williams said.
Claims systems are now operating and TruStage is accepting and paying claims, he said, but the inability to do so normally during portions of the outage troubles him.
Williams said TruStage intends to “err on the side of the member and on the side of the partner” as it addresses problems caused by the attack.
The company has established flexible payment arrangements as billing systems are restored, extended grace periods for premiums and is working to provide refunds to people who attempted to cancel policies while systems were unavailable.
TruStage is also developing the member assistance fund for people who can demonstrate financial hardship directly related to the cyberattack. The assistance would be a grant rather than a loan and would be separate from any payment owed under an insurance policy.
Williams said details are still being developed, including how the program would operate and how grants would be distributed.
BenefitsForYou Digital Access Targeted
Williams also addressed questions about restoration of BenefitsForYou, saying it is among the two or three issues he hears about most frequently from credit union CEOs.
The underlying systems are among the more complex TruStage platforms to restore, he said.
In the meantime, continuity procedures allow people to call to obtain balances and conduct transactions. Williams acknowledged that requiring members to call is not an ideal solution.
TruStage is working to create a digital option that would allow users to go online to check balances, conduct transactions and move money.
Williams said the company’s current goal is to have that digital capability available toward the end of September or in early October, although he cautioned that recovery timelines remain fluid.

Data Investigation Could Take Months
Another major unanswered question is whether credit union member data was compromised and, if so, how much.
As the CU Daily has reported previously, Williams said TruStage has hired outside industry experts to lead that portion of the investigation. The company expects to have more definitive information in roughly the next two months or longer, he said.
Williams acknowledged that is a lengthy period for credit unions to wait but said TruStage does not want to provide conclusions based on assumptions in an investigation of this magnitude.
Once TruStage determines whether member data belonging to a particular credit union was compromised, that credit union will hear from TruStage first, Williams pledged.
Credit unions also will be given notice well before TruStage makes any notification to affected members, he said.
The company is developing a process under which a credit union could opt into a coordinated notification program. TruStage would provide the institution with details about what happened and what member information was affected and could then handle member notifications on the credit union’s behalf.
TruStage is also working with regulators as it develops that process, Williams said.
Williams Responds to Communications Criticism
Valentine also raised criticism that Williams has not been visible enough at credit union meetings since the attack and that TruStage’s communications have sometimes been inadequate.
Williams said he accepts that criticism and that the company has changed its communications strategy based on feedback from credit unions.
He said TruStage made an early decision to publicly acknowledge that it had experienced a cyberattack rather than simply tell the marketplace its systems were unavailable.
The company is now sending operational updates from Chief Administrative Officer Greg Holman at least weekly, providing details on capabilities that have been restored, what credit unions should expect next and what workarounds remain necessary.
Williams said he and other executives are also communicating with the market, and he personally speaks with credit union CEOs almost daily.
His absence from some industry events, he said, reflects his decision to make restoration of TruStage’s systems his primary focus.
Williams said the company is also attempting to balance transparency with regulatory and legal risks.
Within 48 hours of TruStage publicly acknowledging the attack, the company was hit with its first lawsuit, he said.
TruStage therefore must weigh what it can disclose while investigations and litigation continue, Williams said, adding that its communications strategy will continue to evolve based on feedback from credit unions.
Plans to Share ‘Good, Bad and Ugly’
Williams said one of the longer-term outcomes of the incident will be a push to share what TruStage learned with the broader credit union community.
He said he envisions beginning a series of CEO roundtables around the first or second quarter of 2027 in different parts of the country.
Those discussions would examine the “good, the bad, the ugly” of TruStage’s experience and identify steps credit unions should be considering now rather than waiting until they suffer their own attack.
The most important message, Williams said, is that the threat environment has changed dramatically and organizations must prepare not only to prevent attacks but also to recover when defenses fail.
TruStage’s own recovery strategy is being built around that premise.
Williams said the attack has caused significant problems for TruStage employees, credit unions and the members the company serves, and he repeatedly acknowledged the burden created by manual processes and unavailable systems.
But he said the rebuilding effort, combined with TruStage’s financial strength, should ultimately leave the company in a stronger position.
The goal, he said, is not merely to restore what existed before the attack, it is to build a safer and more resilient TruStage for the next one.
The full video of the discussion can be viewed here.




