Featured artwork for the TorchLight article about the TruStage cyberattack and credit union and healthcare third-party risk

14 Lawsuits, One Unanswered Question: What the TruStage Cyberattack Means for Credit Unions

By July 29, fourteen proposed class action lawsuits tied to the TruStage cyberattack had reached federal court in Wisconsin. As of September 15, one important question remains unanswered: Was credit union member data accessed or taken?

September 15, 2026 Author: Zach Carothers Reviewed By: Benjamin Ross 7 min read Credit Unions Cybersecurity & Third-Party Risk

Executive Summary

TruStage identified the cyberattack on July 11 and disclosed it publicly on July 15. The company has relationships with more than 93% of U.S. credit unions and protects approximately 42 million consumer relationships, although that does not mean 93% use TruStage as a core processor.

For each credit union, it’s crucial to know whether the incident disrupted its operations, affected sensitive information, or otherwise meets the NCUA definition of a reportable cyber incident.

NCUA’s 72-hour reporting requirement can apply before a forensic investigation is complete. Member notification is a separate determination based on the facts, likelihood of misuse, and applicable federal and state requirements.

The lesson we find ourselves repeating over and over in 2026: third-party cyber risk is operational risk.

What does the TruStage incident mean for your credit union?

That depends on how your institution uses TruStage.

Leadership should be able to answer:

Which TruStage services do we use?
What member or employee data does TruStage maintain for us?
Which services were disrupted?
Who could potentially be affected?
What reporting or notification requirements apply?
What has TruStage told us about the investigation?

Those questions are part of effective third-party oversight, not just incident response. TorchLight’s recent guide to vendor risk management for credit unions goes deeper into what credit unions should be documenting and monitoring before a vendor incident occurs.

The NCUA clock and the forensic clock are different

Federally insured credit unions must notify the NCUA as soon as possible, and no later than 72 hours after reasonably believing a reportable cyber incident has occurred.

That can include third-party incidents. If a provider tells a credit union that sensitive data or business operations were compromised or disrupted, the reporting obligation may begin before the provider even completes the forensic work.

But NCUA does not expect a finished investigation within 72 hours.

The initial notice is meant to be high-level: what happened, when it was identified, which services were affected, whether sensitive information may be involved, and what the operational impact appears to be.

A credit union should not assume, “We cannot report until TruStage determines whether data was stolen.” Management must decide whether its own circumstances meet the reporting threshold based on what is known now.

Member notification is a separate issue

Regulatory reporting and member notification do not necessarily occur at the same time.

NCUA guidance calls for prompt investigation when sensitive member information may have been accessed. State breach-notification laws may create additional obligations, so compliance and legal counsel should evaluate the specific circumstances.

Operational communication is different. If members are experiencing disruption, the credit union can communicate what is known without speculating about data theft:

TruStage experienced a cybersecurity incident. Certain services were affected. The investigation into potential data impact remains underway. Your credit union is monitoring the situation and will communicate directly if additional action becomes necessary.

That is transparency without getting ahead of the evidence.

The recovery strategy should matter to your board

TruStage has established a clean, isolated technology environment while rebuilding and restoring systems with assistance from cybersecurity specialists. The company says the attack was broad enough that parts of its infrastructure are being rebuilt rather than simply turned back on.

How long can critical operations continue while systems are contained, validated, rebuilt, or recovered?

Incident response and business continuity plans should define recovery priorities, acceptable downtime, manual workarounds, communication methods, decision authority, and the conditions required before systems return to production.

Those same principles should extend into the day-to-day management of infrastructure. TorchLight’s Managed IT Services are built around proactive monitoring, patching, verified backups, recovery planning, vendor coordination, and documentation for regulated organizations.

Outsourcing a service does not outsource responsibility for managing the risk.

Two recent vulnerabilities reinforce the point

The TruStage incident also highlights why security teams cannot manage risk by waiting for perfect information or relying on one severity number.

Cisco CVE-2026-20212

Cisco CVE-2026-20212 affects certain Nexus 9000 Series switches. Cisco rates the vulnerability 9.8 Critical because an unauthenticated remote attacker could execute code with root privileges on affected devices. Cisco released fixes and had not reported active exploitation when the advisory was published.

Palo Alto Networks CVE-2026-0310

The PAN-OS buffer overflow can allow an unauthenticated network attacker to execute arbitrary code with root privileges on affected PA-Series hardware firewalls. Palo Alto prominently lists the vulnerability as 7.2 High, while the same advisory publishes a 9.2 CVSS Base score and gives the vulnerability its highest remediation urgency. Tenable independently lists a 9.2 CVSS v4 Base score and a 9.8 CVSS v3 score.

That discrepancy is not evidence that Palo Alto is manipulating CVSS. Its 7.2 figure is a threat-adjusted CVSS-BT score that incorporates the current lack of reported exploitation.

It does, however, reinforce something we recently covered in 421 Vulnerabilities: It Only Took One : the headline CVSS number should not make the risk decision for you.

Ask instead: Is the technology exposed? What access could an attacker gain? Are attackers exploiting it? What systems depend on it? How quickly can we remove the risk?

That is also why vulnerability management works best as part of a broader managed security operation that connects detection, prioritization, containment, remediation, and executive reporting instead of treating vulnerabilities as a list of numbers.

What your credit union can do now

01

Determine whether your incident is reportable.

Document when you became aware of the incident, what was affected, and why management determined it did or did not meet NCUA’s reporting threshold.

02

Map your TruStage exposure.

Identify the products you use, data exchanged, systems involved, and members or employees potentially within scope.

03

Preserve the vendor record.

Keep notifications, status reports, forensic updates, service-impact documentation, and escalation history together.

04

Prepare member communications now.

Maintain separate templates for operational disruption and confirmed data exposure, with clear approval responsibilities.

05

Test the harder scenario with the board.

Ask: What happens if one of our most important vendors goes offline for 30, 60, or 90 days and cannot immediately tell us whether our data was taken? If your current playbook can’t answer that, it needs work.

Your vendor can become your incident

The TruStage incident shows why third-party risk is more than a compliance exercise.

A credit union can secure its endpoints, identities, email, and network and still face operational disruption, regulatory questions, member communication challenges, and legal exposure because of a service provider.

The vendor connection is also a real attack path. In our analysis of how ransomware enters a credit union network , compromised vendors and managed devices are among the entry points credit unions need to plan for alongside stolen credentials, phishing, and exposed infrastructure.

That does not mean avoiding third parties.

It means knowing which vendors are critical, what information they hold, how quickly they must notify you, what happens if they become unavailable, what evidence they owe you after an incident, and how your institution keeps operating without them.

That is the difference between maintaining a vendor list and managing third-party risk.

Is your incident response plan built for a vendor failure?

TorchLight works with credit unions on cybersecurity, incident readiness, third-party risk, compliance, business continuity, and board-level technology governance.

Our approach connects managed IT and security operations with fractional vCIO and vCISO guidance, so incident response is tied to the systems, vendors, documentation, and people responsible for carrying it out.

If the TruStage incident has your board asking whether the current playbook would hold up during a prolonged third-party outage, that is a useful question to answer before the next incident.

Resources