TruStage Shares Updated FAQs on Cybersecurity Incident, System Outage

MADISON, Wis. — TruStage has published an updated list of FAQs related to the July 11 cybersecurity incident that has shut down many of its systems.

In the new FAQs, TruStage confirms what its CEO, Terrance Williams, said in a video last week, that the company believes the security breach is the result of an employee inadvertently downloaded a malicious file while attempting to install a legitimate utility tool.

The company emphasized that its investigation remains ongoing and that it has not yet determined the full scope of the incident, including whether customer or credit union data was accessed or exfiltrated.

According to TruStage, the company detected unusual activity on its network July 11 and immediately activated its incident response and business continuity plans. The company said it notified law enforcement and engaged cybersecurity firm Mandiant to assist with investigating, containing and remediating the incident.

As part of its response, TruStage proactively took certain systems offline as a precaution.

The company said that, based on its investigation to date, it has not observed any additional threat actor activity since July 11, when the incident was detected and containment efforts began.

No Common Vulnerabilities and Exposures

While the investigation continues, TruStage said it has not identified any known Common Vulnerabilities and Exposures (CVEs) associated with the compromise.

The company also said it has not observed the threat actor interacting with files shared through third-party systems, portals, virtual private networks, APIs or other environments connected to TruStage. However, it cautioned that investigators are continuing to determine whether customer or partner data was accessed, exposed or stolen.

TruStage said it is not yet able to provide written assurances to individual credit unions regarding whether their data was affected because the forensic investigation remains incomplete.

Some Questions Remain Unanswered

The company declined to answer several questions, including when the threat actor first gained access to its network, how long the attacker remained in its systems, the specific type of cyberattack involved and whether any threat actor has claimed responsibility. TruStage said releasing those details would be premature or inappropriate while the investigation is underway.

To assist partners with their own security monitoring, TruStage said it has released several indicators of compromise, including two IP addresses and several domains associated with the investigation. The company noted that the underlying “b-cdn.net” domain itself is not considered malicious.

TruStage said it has notified applicable regulatory authorities and will continue to do so as required. It also confirmed it has informed the National Credit Union Administration of the incident. The company said credit unions that determine the incident is reportable should contact the NCUA directly and identify their notification as relating to the TruStage cybersecurity event.

Other Key Updates

Among the key updates provided by TruStage:

  • The incident was first detected on July 11 after unusual network activity was identified.
  • Investigators believe the attack may have originated from an employee inadvertently downloading a malicious file while installing a legitimate utility application.
  • Mandiant is leading the forensic investigation and remediation efforts alongside TruStage.
  • The company said it has not observed additional threat actor activity since July 11.
  • The investigation has not yet determined whether customer, partner or credit union data was accessed or exfiltrated.
  • TruStage said it has not identified any known CVEs connected to the incident.
  • The company said it has not observed attackers moving into connected third-party systems or environments.

TruStage said it will continue providing updates to its credit union partners as additional facts become available through the ongoing forensic investigation.

Litigation Filed

As the CU Daily has reported, one credit union has already filed a lawsuit against TruStage over the security incident, while one class action law firm has indicated it is seeking plaintiffs for potential litigation against both individual credit unions and TruStage. 

The FAQs can be found here

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.