TruStage Offers New Update on Cybersecurity Incident; Still Unknown if Member Data Exposed; More Than a Dozen Lawsuits Now Filed

MADISON, Wis. — In a new update, TruStage said it is making “steady advancements” in restoring servics following a cyberattack that has knoocked out services for more than a month but that it will likely be two-to-three months before it knows whether any credit union/member data has been compromised–an issue at the heart of more than a dozen lawsuits the company now faces.

In a new statement, TruStage President and CEO Terrance Williams said the company is making “steady advancements in restoring our technology environment and expanding operational capabilities, while also taking the opportunity to strengthen the technology foundation that will support members, customers, and credit union partners.”

Terrance Williams

In response to the question Williams confirmed many in credit unions have been asking–and which is also the basis for the litigation the company is facing–whether any credit union/member data has been compromised, Williams said, “We know you want answers quickly, and we do too. We’re executing as quickly as we can with the help of Mandiant, our cybersecurity experts, and Epiq Global, a leading data analysis firm,” Williams said. “Because of how complicated this process is, it will likely be 2 to 3 months from now before we have those answers. I understand that timeline may be frustrating, but it is consistent with what happens in these kinds of cases. The time required to get this right will allow us to share accurate information and give you the answers you need. 

“If we determine that your member data or your employee data has been impacted, we are committed to telling you first,” Williams said. “And we will do what we can do to make any notification and regulatory reporting that might be required as easy on you as we can.

As the CU Daily reported here, TruStage said it detected unusual activity on its network on July 11 and immediately shut down its systems to investigate. It has confirmed its systems were breached after “a member of our workforce may have inadvertently downloaded a malicious file while trying to install a legitimate tool.”

The company has not issued any statement regarding whether ransomware is involved.

‘Clean Environment’ Established

Williams said Mandiant, which TruStage has retained  as its “cybersecurity partner,” has confirmed that the company has established a clean, isolated environment that is separate from any systems that were impacted, potentially impacted, or remain under investigation.

“Know that teams are actively working to restore systems and processes in phases using a mix of secure, restored capabilities and interim solutions,” Williams said. “Each of those is tested and validated before coming online.”

Williams said the full restoration across all company systems will take more time than anyone would like, but that TruStage is “using this opportunity to enhance our environment, and our ability to serve you and your members. Our goal is not simply to return to normal, but to emerge even stronger and more secure.”

Priorities and Progress 

In the update, Williams said TruStage remains on track to having most of its key processes operational by mid-August, and further noted:

  • Basic Servicing: “We expect to have basic servicing up and running for the majority of our businesses, including the reopening of our customer contact centers, by our mid-August target.”
  • Call Centers: “Some businesses, such as our retirement call center, are open now, while our life and annuity call centers will open Friday, Aug. 14. Keep in mind, the experience may have hiccups due to higher volumes and longer handling times initially. While not all customer service needs can be addressed at this time, we are committed to enhancing our experiences and capabilities in the weeks ahead.”
  • Claims Payments: “We have started to pay claims across our business, including preplanning/funeral claims, GAP claims and debt protection/credit insurance benefits. For Life and AD&D claims, we are working to restore core processing capabilities, and we will focus first on paying claims that were pending at the time of the outage before moving to claims received post-outage. We will work through this backlog as quickly as possible, but that will take some time.”
  • Retirement and Annuity Plans: Williams said annuity and retirement plan assets have not affected by the cybersecurity attack and that the majority of defined contribution participants, other than those using certain legacy platforms, can now request withdrawals and loans, if allowed under their plan, and request updates on their account balances over the phone.”
  • Billing Activities: “We have resumed billing activities to avoid billing disruptions for a large segment of our consumers and are working on options for consumers who missed a payment. Be assured that those policies will remain active as we work through this process.”

TruStage has published an updated list of FAQs on the outage here

Legal Fallout Grows

Meanwhile, the legal fallout from the cybersecurity incident that forced TruStage to shut down portions of its systems has grown substantially, with a review of federal court records finding at least a dozen lawsuits have been filed against the company in Madison as of Aug. 12.

The cases have been filed in U.S. District Court for the Western District of Wisconsin, where Madison-based TruStage is headquartered. The litigation began just two days after TruStage publicly disclosed the cybersecurity incident July 15, as the CU Daily was first to report here.

A review of federal docket records shows the lawsuits include one brought by a credit union and at least 11 filed by individuals, generally seeking class-action status. Some of the individual cases also name credit unions as defendants.

To date, TruStage has not stated whether any member data has been compromised or exposed. In a statement to the CU Daily the company said it does not comment on litigation.

Information on the public-facing portion of TruStage’s website.

The Cases

The cases identified in the court records are:

  • Bessemer System Federal Credit Union v. TruStage Financial Group Inc., Case No. 3:26-cv-00644, filed July 17.
  • Marylou Peixoto v. TruStage Financial Group Inc. et al., Case No. 3:26-cv-00658, filed July 20. Align Credit Union is also named as a defendant.
  • Johna Nivens v. TruStage Financial Group Inc. et al., Case No. 3:26-cv-00659, filed July 21. First Financial Federal Credit Union is also named as a defendant.
  • Linda Kroutter v. TruStage Financial Group Inc., Case No. 3:26-cv-00661, filed July 21.
  • Kenneth S. Delin v. TruStage Financial Group Inc., Case No. 3:26-cv-00665, filed July 22.
  • Jennifer Brazier v. TruStage Financial Group Inc., Case No. 3:26-cv-00670, filed July 23.
  • Mozzell Brown v. TruStage Financial Group Inc., Case No. 3:26-cv-00672, filed July 23.
  • Jeffrey Turner v. TruStage Financial Group Inc., Case No. 3:26-cv-00680, filed July 27.
  • Nina Lyle-Douville v. TruStage Financial Group Inc., Case No. 3:26-cv-00681, filed July 27.
  • Hannah Blackmon v. TruStage Financial Group Inc., Case No. 3:26-cv-00683, filed July 27.
  • Randall Landers v. TruStage Financial Group Inc. et al., Case No. 3:26-cv-00688, filed July 27. First Financial Federal Credit Union is also named as a defendant.
  • Tammy Collette v. TruStage Financial Group Inc., Case No. 3:26-cv-00698, filed July 29.

Additional Details

Federal docket listings confirm, for example, that the Turner, Lyle-Douville, Blackmon and Landers cases were all filed July 27. The records show Landers named both TruStage and First Financial Federal Credit Union as defendants.

The most recent case identified in the review is Collette’s, filed July 29. Court records classify that action as an “other contract” case and identify breach of contract as the cause of action.

Credit Union Was First to Sue

As the CU Daily was first to report, the first lawsuit came from Bessemer System Federal Credit Union in Pennsylvania, which filed a proposed class action July 17, only two days after TruStage publicly acknowledged the cybersecurity incident.

The complaint seeks to represent Bessemer and other similarly situated credit unions allegedly affected by the shutdown. Court records show the complaint included a jury demand and was assigned to U.S. Magistrate Judge Anita Marie Boor.

Unlike the consumer cases that followed, Bessemer’s lawsuit focuses on alleged harm to credit unions that depend on TruStage products and systems.

About the Attack

The litigation stems from the cyberattack TruStage said it identified in July. The company said July 15 it had “recently identified a cybersecurity incident affecting its environment” and immediately activated incident-response and recovery protocols. TruStage said it brought in outside cybersecurity experts to assist with containment, remediation and recovery.

The incident led TruStage to shut down portions of its network, disrupting services used by credit unions and their members, including some Guaranteed Asset Protection, Mechanical Repair Coverage and Payment Protection services.

TruStage President and CEO Terrance Williams has appeared in two videos offering updates on the shutdown, most recently here.

Consumer Cases Quickly Followed

The first individual case identified in the docket review was filed July 20 by Marylou Peixoto. That lawsuit names both TruStage and Align Credit Union as defendants.

Nivens and Kroutter filed separate cases the following day. Federal court records list both as personal-injury actions, while Nivens also names First Financial Federal Credit Union as a defendant.

The pace of filings accelerated from there, with cases filed by Delin on July 22; Brazier and Brown on July 23; and Turner, Lyle-Douville, Blackmon and Landers on July 27. Collette followed July 29.

The litigation represents allegations by the plaintiffs and does not constitute findings that TruStage or any credit union named as a defendant violated the law or is liable for damages..

Facebook
Twitter
LinkedIn

18 Responses

  1. Still unable to make contact with via telephone or email – which results in no information regarding my account forthcoming. TruStage needs to correspond directly with everyone who has a policy with them. It is basic business courtesy.

  2. They still have not notified us of a problem. We found out on our own. Still no communication at all. We have credit life and disability on two loans. I am totally disabled and my wife is terminally ill. This company is extremely hard to work with, and now this lack of security, and backups is hurting milllions of people. People want answers, and sadly I doubt we will ever get them. 80 years in business and not accredited with the Better Business Bureau. Credit Unions apperenty didn’t vet theses people well.

  3. In response to the above comment – this in unethical – the company has to be held accountable for this breach. Perhaps in the form of a class action lawsuit.

  4. my anniversary was july 25, was supposed to get 13% added to acct. Tried to access acct july 27 to see new balance, thats how i found out. Finally directed to trustage.com/outage, only option it showed was partial or full surrender on form. Tried to email Trustage, agent named laura got email , said all systems shut down but could fill out forms thru assuresign and they would process my surrender. Think about it, said all systems down, but they could do a surrender but could noy tell me the dollar amount.So i filled it out and a check arrived on 8/11, dated 8/3, had toll free number to call, it forwarded to India and someone who had heavy accent saying all systems down, cant access account. The check was $23,000 short, kept calling and emailing and on 8/19 ,a call from DAWN, wanting to know why i was questioning $ amount. I explained just as i wrote, she said they added the 13% i was due, then deducted 3% penalty for early surrender, $16000 was for a MVA, market value adjustment. I told her that i had called on July 29th and no one would answer phone nor emails to explain the formula of the MVA, if someone had told me it was going to take 10% of my annuity ,i would have not done the surrender. She said it was in my contract, i said i agree, but to do the math you have to have the dollar amount, i was told ALL SYSTEMS WERE DOWN and it was going to be a slow process to get everything back on line. So that brings me down to the question, On July 29th, all systems were suppose to be down, but 5 days later they took account balance from July 25 2025, market up 17% , i was indexed at 13& gain. They took value of acct. added 13% mius 3% penalty, minus $16,000 MVA ,all while i was being told all systems shutdown and cannot give you an account dollar amount. Makes me wondr even more on 8/14/26, i got an email to access trustage.com/outage and they had added to surrender form a line to click on to see amount. Is that convient ? These are things that i hate about annuties with no guarentee. If they have 3 million subscribers and say 25% surrendered their contract, some with a lot more money than mine, then think about how many millions they made claiming ALL SYSTEMS DOWN. The whole thing seems suspicious ,and its one of those things that make you go hhhhhmmm.

  5. I see where my monthly auto payments to TruStage have resumed. Hopefully, this means the issue, though not totally resolved, is moving in the right direction for customers.

  6. My 401K is with Trustage and represents 45% of my net worth. Have called daily since August 4, 2026 and they have never answered. Each time I have left a message and have never received a call back. August 24, 2026 remained on hold for over 2 hours before giving up. Today I’m up to 1 hour 45 minutes and I’m planning on remaining on the line until they answer. I have never received any notice from them regarding the attack. The only reason I know about it is on August 4, 2026 I called to perform a direct rollover to Charles Schwab. If I had only done this in June!

      1. As of today September 5th 2026 they still have not taken premiums from my credit union account. There should have one for July and one for August in

  7. I retired at the end of June with a promise of a pension payout package in two weeks. Then total silence at TruStage. They are have since assured me the funds in the pension are safe but that their actuaries can’t do any manual calculations with no timeline to resolution. NOT an acceptable answer. I am on a fixed income loosing $1,700 in monthly interest income Base on if I had my lump sum invested at a 5 % annual return. Unbelievable is a word that comes to mind. And they best not say “it was an act of God” to skirt liability. Cyber attacks are man made.

  8. The fact that Trustage has not contacted customers is very worrisome. I’m wondering if all the money I’ve paid in premiums for term life insurance over the years has been a total waste.

  9. There is no way that TruStage should need months to tell if information of credit union customers has been accessed in this cyber attack. My guess is that it has been, because it took days after they noticed a problem to shut down. At todays speeds a lot of data can be accessed in just one day.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.