MADISON, Wis. — TruStage President and CEO Terrance Williams said that the cyberattack that has disrupted the company for nearly six weeks now affected not just its primary technology environment but portions of the backup infrastructure it had expected to use for recovery, forcing it to rebuild significant parts of its technology environment in the cloud.
TruStage was hit by the cyberattack in mid-July and has said it was most likely the result of an employee downloading a malicious file. It had earlier announced plans to have most systems restored by mid-August, and some member-facing services have been restored. It has also introduced a Recovery Status Dashboard.
In an Aug. 27 update to credit union CEOs, Williams acknowledged frustration over the pace of the recovery and said TruStage is continuing to restore systems through a phased process.

The company has also brought in PwC to assist with the recovery, named Kirsten Garen interim chief information officer and said an investigation into potentially affected data could take another two to three months.
“I know this incident has created challenges and frustrations for your teams, your employees and the members we collectively serve,” Williams told credit union leaders.
Attack Also Affected Backup Infrastructure
Williams directly addressed questions from credit unions about why restoration has taken so long.
Before the attack, TruStage was modernizing legacy infrastructure and maintained multiple backup systems and business continuity plans, he said. But the severity of the cyberattack complicated those preparations.
“The extreme nature of this attack impacted our primary operating environment and elements of the backup infrastructure we had expected to rely on,” Williams said.
As a result, TruStage accelerated longer-term modernization plans and developed an alternative recovery strategy that required rebuilding and restoring significant portions of its technology environment in the cloud.
Williams said the company does not intend simply to recreate the technology environment that existed before the attack.
“This incident reinforced the need for additional layers of resilience and independence in how critical capabilities are designed, protected, and recovered,” he said.
Services Gradually Returning
Williams said TruStage continues to restore operations, although some processes remain limited or slower than normal.
Among the areas where the company said it is making progress are:
- Expanding customer service capabilities
- Restoring transaction and servicing functions
- Resuming claims and payment operations across several businesses
- Increasing the ways customers can obtain support
TruStage is using a phased approach to restoring functionality, Williams said.
Chief Administrative Officer Greg Holman is expected to provide a more detailed progress report Aug. 31. TruStage also plans to hold a town hall for credit union CEOs in the coming weeks.

PwC Added, Interim CIO Named
TruStage has expanded the outside expertise involved in its recovery.
Mandiant and Epiq Global continue to assist the company, with Mandiant supporting technical restoration and Epiq working on the data investigation, Williams said.
TruStage has now also engaged PwC’s cybersecurity consulting team to provide additional expertise, coordination and operational support for the enterprise-wide recovery.
The company has appointed Garen interim CIO to lead the technology recovery and help develop its longer-term resiliency strategy. Williams said Garen has experience leading cyber incident response and technology transformation efforts.
Pat Lawicki, who had served as TruStage’s CIO since 2024, will remain with the company in a consulting capacity to provide institutional knowledge and continuity during the recovery, Williams said.
Data Review Could Take 2-3 Months
Questions remain about whether the attack compromised data belonging to credit unions, their members, employees or others.
Williams said the investigation being conducted with Mandiant and Epiq remains underway and is expected to require another two to three months before TruStage can reach definitive conclusions.
“While we all want answers as quickly as possible, it is critical that we communicate verified facts rather than assumptions,” Williams said.
He said TruStage would communicate directly with affected credit unions if the investigation determines that member, employee or other data was affected. The company also plans to assist credit unions with any resulting notification or regulatory reporting requirements.
Williams said he will communicate directly with credit union CEOs when significant developments require additional context, while TruStage continues providing regular operational and service-restoration updates.
“Our focus remains clear: restoring services safely, strengthening our environment, and earning confidence through our actions,” Williams said.



