By Jeff Bassill

On July 15, 2026, TruStage disclosed that it had identified a cybersecurity incident affecting its environment and had proactively taken portions of its network offline while it investigated. The company said it activated its incident response and recovery protocols and brought in outside cybersecurity experts to help contain and remediate the issue.
The practical effects showed up fast for credit unions. Services tied to GAP insurance, mechanical repair coverage, and payment protection products were disrupted, and some credit unions reported members locked out of account access, including 401(k) plans, while systems were down. TruStage serves the overwhelming majority of U.S. credit unions and has described itself as protecting roughly 42 million consumer relationships, so when its network goes down, the impact doesn’t stay contained to one vendor’s IT department.
On July 17, 2026, Bessemer System Federal Credit Union, a Pennsylvania institution, filed a proposed class action against TruStage in the U.S. District Court for the Western District of Wisconsin, alleging the company failed to maintain adequate, industry-standard cybersecurity safeguards despite its own privacy policy and security materials promising administrative, physical, and technical protections. As of the most recent reporting, TruStage has not disclosed whether member data was accessed, and the investigation remains ongoing.
TruStage is Not Just Another Vendor
For many credit unions, TruStage is deeply embedded in member-facing insurance, protection, lending support, and related service channels. When an organization of that scale experiences a cybersecurity-related outage, the operational burden does not stay neatly contained within the vendor relationship.
Credit unions are the institutions fielding member questions, documenting workarounds, managing claim delays, preserving timelines, and evaluating whether any regulatory reporting obligations may be triggered. That is a real operational issue, not simply a vendor communications matter.
That is why the response from America’s Credit Unions matters. The primary national trade association for credit unions does not need to speculate, assign blame, or interfere with an active investigation. But it can acknowledge the disruption, provide practical guidance, and help credit unions communicate clearly with members.
ACU Should Be Part of the Response
TruStage has long been a significant presence in the credit union movement. Its relationships with credit unions, leagues, conferences, advocacy efforts, and system partners are extensive. That is precisely why silence from America’s Credit Unions is so noticeable. Close system relationships should make coordinated communication more important, not less.
Silence can create its own risk
I understand why America’s Credit Unions would be cautious during a cybersecurity investigation involving a major system partner. No one wants the association to get ahead of verified facts or create unnecessary legal exposure. But there is a difference between avoiding speculation and leaving credit unions to manage uncertainty without meaningful industry-level support.
The Operational Reality
Front-line staff and compliance teams are dealing with the immediate consequences: member questions, interrupted claims processes, manual tracking, vendor updates, phishing concerns, and potential incident-response documentation. These are exactly the moments when America’s Credit Unions should help credit unions translate limited vendor updates into practical next steps.
The credit union movement often talks about collaboration, shared responsibility, and member advocacy. Those principles are most important when the situation is uncomfortable. Acknowledging the operational impact of the TruStage outage would not be disloyal to a system partner; it would be America’s Credit Unions fulfilling its role in support of the credit unions and members affected by it.
What This Means, Regardless of How Investigation Ends
Whatever the eventual findings, this event is a live case study in third-party vendor risk, and it’s worth using it now, while it’s fresh, rather than waiting for a tabletop exercise months from now:
- Pull your TruStage (or equivalent core-adjacent vendor) contract and confirm your notification triggers. Do you know what obligates them to notify you, and on what timeline, if member data is confirmed affected?
- Check whether your Incident Response Plan actually accounts for a vendor-side incident, not just an internal breach. Many IR plans are written assuming the credit union itself is the point of compromise.
- Document as you go. If members are calling about delayed claims or locked accounts, that’s exactly the kind of operational impact that belongs in your own incident file, regardless of fault.
- Revisit your vendor due diligence cadence. A vendor’s security representations are only as good as the last time you verified them.
To make the first step easier, I’ve put together a generic Incident Response documentation form, pre-populated with the publicly available facts of the TruStage event so far and clearly marked fields for your institution to complete the rest. You can download the template here.
Jeff Bassill has 45 years of experience in financial institutions and currently serves as Chief Financial & Risk Officer at Kings Federal Credit Union, a role he moved into after retiring as the credit union’s President & CEO in 2022. He is also the founder of CU Risk Advisors, focused on Risk Management, Regulatory Compliance, and Indirect Lending.
The views expressed in this opinion are my own and do not represent the official position of Kings Federal Credit Union. This post reflects publicly reported information available as of the date above. It is not legal advice, and institutions should consult counsel regarding their specific notification and regulatory obligations.





7 Responses
America’s Credit Unions should have no role in this in this process or response. This is between TruStage and their customers. If in any way their response and communication is insufficient, that’s on them. ACU doesn’t add value here, and getting in the middle of things like this is not their role or purpose. “Acknowledging the operational impact” does nothing to help anyone. TruStage isn’t going to work harder to fix this or do anything different if ACU weighs in and acts like they matter in this issue. Kudos to them for understanding what their their role is and isn’t.
TruStage’s customers are dues paying members of ACU and consumers that they claim to protect, not some uninvolved third party population. Considering the state leagues have already been acknowledging operational impact for their members, it’s not a leap to think that the national trade association should offer assistance to its members.
TruStage isn’t just a close system relationship they’ve put real money behind ACU’s advocacy campaigns. Maybe that’s totally irrelevant to the silence here. However, if it is relevant, “understanding what their role is and isn’t” starts to sound like yet another convenient excuse for ACU to take our money, take our vendors money and look the other way.
CU’s pay for protection? ACU is complicit if they are silent? Is that how it works? Sure, they take our money, but we don’t pay for them to manage our vendors. You don’t go tattle to mom when your brother socks you in the arm. ACU can add no value to this. How does their public acknowledgement of this help anyone? How does creating a web link and reposting the same exact info from TruStage help a credit union?
It’s good to see Bessemer take action. Credit unions should be focused on helping their members, holding TruStage accountable, and then owning their own vendor management and governance breakdowns for doing business with a vendor that left itself this exposed and didn’t have independent enough systems for unrelated businesses and product lines.
all these opinions are just gibberish to me. what i do know is i cannot access my 401k info. and the tru stage updates are useless. when are we going to get some realistic info and a date when services are going to be restored.
Well your 401k has nothing do to with ACu, which is the topic of this post. Take it up with your credit union or Trustage.
This outage is unacceptable, and as soon as I am able, I am canceling my TruStage policies.
understand there is a lot of work necessary to get everything done the right way. but i do not understand why tru stage has not posted new date or anticipated date when system will be operable. the tru stage updates are void of any meaningful information.