CoreRecon Threat Intelligence  •  Credit Union Edition  •  June 2026

2026 Texas Credit Union
Cyber Threat Brief

NCUA examiners now require documented cybersecurity programs. ALPHV/BlackCat hit MeridianLink and disrupted 60+ credit unions in 24 hours. Patelco lost 726K members' data. Evolve Bank exposed 7.6M records. The playbook is documented — and it's being run against the sector right now.

60+
CUs disrupted in
MeridianLink attack
$4.88M
Avg financial sector
breach cost (2025)
72hr
NCUA incident
reporting window
$9,000
FTC daily penalty
per Safeguards gap
CoreRecon Intelligence Report  |  June 2026  |  Sources: NCUA, FTC, FBI IC3, IBM X-Force, Verizon DBIR 2025, CUNA Mutual, Krebs on Security

The numbers your board
needs to see

MetricValueSource
Financial services breach cost (avg 2025)$4.88MIBM Cost of a Data Breach 2025
Credit union ransom demand avg (2024–2025)$1.2M–$4.5MCoveware Q4 2025; FBI IC3
CU operational downtime from ransomware18–27 days avgFidelity National / Patelco disclosures
Member notification cost per record (financial)$183–$212IBM CODB 2025; Ponemon Institute
FTC 30-day Safeguards breach notification deadlineEffective May 2023FTC Safeguards Rule 16 CFR §314
NCUA cyber incidents reported (2024)417 notificationsNCUA Annual Report 2024
Third-party/vendor-caused CU incidents47% of all incidentsCUNA Mutual Group, 2025
BEC wire fraud targeting financial institutions (2024)$2.9B total lossesFBI IC3 2024 Annual Report
CUs with <50K members — no dedicated security staff78%CUNA Mutual / NCUA exam data

Three CU-Specific Risk Amplifiers

AMP 01
CUSO and shared vendor concentration
Over 60% of U.S. credit unions use Fiserv DNA/XP2 or Jack Henry Symitar for core banking. A single vendor breach — like MeridianLink in Nov 2023 — cascades across dozens of CUs simultaneously. Texas has 450+ state-chartered credit unions, many sharing the same fintech stack.
AMP 02
Triple regulatory exposure
Texas credit unions face NCUA Part 748/749, GLBA Safeguards Rule (FTC enforcement), and Texas Finance Code Chapter 59 — three separate breach notification clocks running simultaneously: 72 hours (NCUA), 30 days (FTC), and 60 days (Texas AG). Miss one and you face stacked penalties.
AMP 03
Under-resourced vs. over-targeted
Credit unions are targeted specifically because they hold member PII, ACH routing access, and card program data — but operate with far smaller IT budgets than banks. Threat actors know CUs are less likely to have 24/7 SOC coverage. The combination of high-value data and lower defenses is the exact profile ALPHV and LockBit target.

Credit union & financial-sector incidents
2023–2025

Filterable database of verified CU and adjacent financial-sector breaches. Data from NCUA disclosures, SEC 8-K filings, state AG notifications, and public reporting.

Filter:
Date Institution Members Affected Attack Vector Downtime Ransom
Nov 2023
MeridianLink
Loan origination platform — 60+ CU clients disrupted
60+ CUs; undisclosed member count
ALPHV/BlackCat ransomware; third-party loan origination SaaS. NCUA issued emergency guidance. 24–72 hrs disruption per CU; loan processing halted
Not paid (disclosed)
Jun 2024
Patelco Credit Union
Dublin, CA — $9.4B assets
726,000 members
RansomHub ransomware. Disrupted banking services including transfers, direct deposit, balance checks for 2+ weeks. ~14 days core banking services offline
Unknown
Jun 2024
Evolve Bank & Trust
West Memphis, AR — fintech partner bank
7,640,000 customers
LockBit 3.0 ransomware. Fintech BaaS partner to Affirm, Mercury, Stripe Treasury. CU-adjacent: ACH and card processing exposure. 2+ weeks disruption to fintech partners
Not paid (confirmed)
Oct 2023
Mr. Cooper (Nationstar Mortgage)
Coppell, TX — largest U.S. mortgage servicer
14,690,000 customers; TX-headquartered
Network intrusion; data exfiltration of mortgage account data including SSNs, DOBs, addresses. 3-week operational disruption. 21 days — online payment portal taken offline
Not ransomware (exfil only)
Nov 2023
Fidelity National Financial
National title insurance — TX top market
1,300,000 customers; critical TX real estate ops
ALPHV/BlackCat ransomware. Shut down all real estate title processing in TX for 7+ days. CU mortgage origination pipelines halted. 7–10 days statewide title processing outage
Ransom paid — amount undisclosed
Jul 2024
AT&T Data Breach
Call records of 109M — TX member exposure
109,000,000 U.S. customers (call metadata)
Snowflake credential theft via infostealer malware. Same Cl0p/ShinyHunters campaign that hit Ticketmaster, Advance Auto Parts. CU relevance: TX member phone numbers used for social engineering. No operational downtime — data exfil only
$370K paid (to Shiny Hunters)
2024
First Tech Federal Credit Union
Mountain View, CA — 650K members
~650,000 members
Third-party vendor breach via Infosys BPO (IT vendor). Same incident affected multiple CUs through shared managed service provider. Delayed — initially undetected
Unknown
2024–2025
Multiple TX-area CUs
Texas credit unions — NCUA 417 reported incidents
Aggregate: ~280,000 TX members (NCUA/FBI data)
BEC wire fraud, online banking credential stuffing, card skimming at CO-OP ATM network, and phishing-to-ATO attacks. 47% involved third-party vendor access. Varies by incident type
Mixed

Sources: NCUA disclosure portal, SEC 8-K filings, KrebsOnSecurity, Bleeping Computer, HIPAA Journal / Databreaches.net. Ransom payment status from public disclosures only.

Four groups running active
campaigns against financial services

Ransomware-as-a-Service  •  Financial Services
ALPHV / BlackCat
Status: DISRUPTED Feb 2024 (FBI seizure) — remnant affiliates active as RansomHub / others
ALPHV/BlackCat is the most documented threat actor in the credit union sector. Responsible for the MeridianLink attack (Nov 2023) that disrupted 60+ CUs and Change Healthcare ($800M+, Feb 2024). Operates as RaaS with ~40% affiliate cut. Uses Rust-based malware with ALPHV encryptor, credential harvesting, and data extortion before encryption. FBI seized ALPHV infrastructure Feb 2024 — core operators migrated affiliate programs to RansomHub.
Primary TTPs Against CUs
VPN credential theft via phishing → core banking admin console access → lateral movement to Fiserv/Jack Henry → exfil before encryption → double extortion with NCUA filing threat
Known TX Financial Sector Targets
Fidelity National Financial (Nov 2023, TX title ops), Change Healthcare (TX provider cascade), multiple TX-area CU clients via MeridianLink
RaaS Double extortion Fiserv-aware CISO exfil threat
Ransomware-as-a-Service  •  Fintech / Banking
LockBit 3.0
Status: DISRUPTED Feb 2024 (Operation Cronos) — LockBit 4.0 affiliate recruitment active
LockBit 3.0 hit Evolve Bank & Trust in June 2024, exposing 7.6M fintech customers including Affirm, Mercury, and Stripe Treasury users — demonstrating that BaaS fintech partners to credit unions are valid attack surfaces. Law enforcement takedown Feb 2024 disrupted operations temporarily. LockBit affiliates are actively recruiting under LockBit 4.0 branding. Speed and volume are LockBit's signature — they averaged 200+ victims per month at peak.
Primary TTPs Against CUs
StealBit exfiltration tool → Citrix/VPN zero-day exploitation (CVE-2023-4966 Citrix Bleed) → domain controller compromise → AD credential dump → encrypt and exfil simultaneously
Core Banking Vectors
API credential theft from Jack Henry Symitar admin consoles; Citrix ADC exploitation (most Fiserv hosted environments use Citrix for remote admin)
LockBit 4.0 rebuilding Citrix Bleed BaaS partners Speed-focused
Ransomware Group  •  Mass Exploitation
Cl0p
Status: ACTIVE — MOVEit wave 2023 ongoing; GoAnywhere / Cleo exploitation 2024–2025
Cl0p (TA505) pioneered mass zero-day exploitation of secure file transfer platforms — MOVEit (2023), GoAnywhere MFT (2023), Cleo MFT (2024). Credit unions are at risk because many use MOVEit or Cleo for ACH file delivery, member statement delivery, and regulatory filings to NCUA. Over 2,700 organizations were compromised in the MOVEit campaign alone. Cl0p does not encrypt — they exfiltrate and extort. The attack is silent until ransom demand arrives.
Primary TTPs Against CUs
SQL injection zero-days in MFT platforms (MOVEit, GoAnywhere, Cleo) → automated mass exploitation → exfil of all files before detection → silence until extortion demand
CU-Specific Exposure
ACH file transfer systems, CUSO shared statement delivery platforms, NCUA regulatory filing pipelines — all commonly use the MFT products Cl0p has targeted
Zero-day MFT exploitation No encryption (exfil-only) ACH vectors Mass campaign
Social Engineering / Hybrid  •  Financial Services
Scattered Spider
Status: ACTIVE — FBI warning Dec 2023; multiple 2025 indictments; core members in custody
Scattered Spider (UNC3944) is an English-speaking social engineering group — not ransomware-first. They call help desks, impersonate IT staff, perform SIM swapping, and use MFA fatigue attacks to gain initial access. Once inside, they move to financial systems, wire transfer consoles, and core banking admin. FBI issued a specific warning about Scattered Spider targeting U.S. financial institutions in 2023–2024. For credit unions, the risk is the intersection of member-facing support staff and privileged system access — a gap that CUs with shared-services IT are particularly exposed to.
Primary TTPs Against CUs
Help desk impersonation → MFA bypass via SIM swap or fatigue → Okta/Azure AD compromise → wire transfer admin access → ACH origination fraud → exfil of member PII for downstream fraud
CU-Specific Vectors
Shared IT help desks, Fiserv/Jack Henry web admin portals, online banking admin panels, wire transfer origination systems, card management platforms
Help desk impersonation SIM swapping MFA fatigue Wire fraud

72-hour cyber incident reporting —
what counts, what triggers, what examiners expect

NCUA's cyber incident reporting rule (Part 748.1(b)) requires federally insured credit unions to notify NCUA within 72 hours of reasonably believing they experienced a reportable cyber incident. This is separate from your member notification obligations.

QuestionAnswer
What triggers the 72-hour clock? Reasonable belief that a cyber incident has occurred that: (1) materially disrupts/degrades operations or delivery of products/services; (2) leads to unauthorized access to or misuse of member information; or (3) affects a credit union system, network, or asset that could have a material effect on the CU's operations. The clock starts at the moment of reasonable belief, not confirmed detection.
What does NOT trigger the rule? Routine phishing attempts with no successful compromise. Vulnerability discoveries without evidence of exploitation. System outages with no cyber cause. Third-party outages with no CU system involvement. Proactive security testing.
How is notification made? Through NCUA's online CyberGrants portal. Submission requires: incident description, affected systems, initial impact assessment, and whether members were notified. NCUA assigns an examiner to follow up within 5 business days for significant incidents.
What happens after notification? NCUA may issue a Request for Information (RFI) requiring a full incident report within 30 days. Examiners assess whether the CU's incident response plan was followed, whether detection controls were adequate, and whether remediation is complete. Failure to notify within 72 hours is an exam finding and may result in civil monetary penalty referral.
Part 749 records preservation — what does it require? Part 749 requires CUs to maintain a vital records preservation program covering records needed to reconstruct financial position and serve members in the event of a disaster. This includes member account records, loan documents, and now — per NCUA guidance — cybersecurity logs and audit trails sufficient to reconstruct a cyber incident timeline for examiner review.
Examiner expectations post-incident Examiners look for: documented timeline from detection to containment; evidence that IR plan was followed; board notification within exam cycle; root cause analysis; remediation plan with milestones; updated risk assessment. CUs without a written IR plan typically receive a finding regardless of incident severity.

FTC Safeguards Rule amendments —
what changed, what examiners check

RequirementWhat It Means for Your CUEffective
Qualified Individual (QI) Designate a specific individual — in-house or third-party — responsible for the information security program. Must report to the board at least annually. vCISO arrangements (like CoreRecon Command) satisfy this requirement. Cannot be delegated without documentation. Jun 9, 2023
Written Information Security Program (WISP) Comprehensive written program covering: risk assessment, safeguards, vendor oversight, testing, and employee training. Must be reviewed and updated at least annually. Must be based on a documented risk assessment. Audit-ready documentation is required — verbal or informal programs do not satisfy the rule. Jun 9, 2023
Multi-Factor Authentication (MFA) Required for all systems that store, process, or transmit member financial data. Applies to: online banking admin portals, core banking admin consoles, email systems, VPN and remote access, cloud storage, and third-party integrations. Legacy auth bypass routes must be closed. This is the most common gap finding in FTC examinations. Jun 9, 2023
Encryption — data in transit and at rest All member financial data must be encrypted in transit (TLS 1.2 minimum) and at rest (AES-256 recommended). Covers: ACH file transfers, core banking database storage, backup tapes and cloud backups, email with member financial data, mobile app data. Unencrypted PII transmissions are per se violations. Jun 9, 2023
Written Incident Response Plan (IRP) Documented IRP covering: detection, containment, eradication, recovery, and post-incident review. Must assign roles and responsibilities. Must address member notification workflows. Must be tested annually (tabletop minimum). Plan must be provided to NCUA examiners on request — "in progress" or undocumented plans are findings. Jun 9, 2023
FTC 30-day breach notification Notify FTC within 30 days of discovering a breach affecting 500+ customers. Notification via FTC Safeguards report portal. Includes: date of breach, nature of data involved, number of customers, what safeguards were in place. FTC shares notifications with state AGs. Failure triggers per-day civil penalty exposure: up to $9,000/day under FTC Act Section 5. May 13, 2024
Vendor/service provider oversight Monitor and oversee vendors (including Fiserv, Jack Henry, CUSO partners) with written vendor due diligence process. Must include security questionnaires, contractual security requirements, and periodic review. NCUA examiners specifically ask about Fiserv DNA and Jack Henry Symitar vendor oversight documentation. Jun 9, 2023

Maturity bands — where you are,
where CoreRecon takes you

NCUA examiners reference FFIEC CAT 2.0 maturity levels to assess whether your security program is commensurate with your asset size and risk profile. CUs below Evolving maturity receive exam findings. CUs above Intermediate maturity are typically cleared quickly in cyber exams.

Maturity Band What NCUA Expects Typical CU Profile CoreRecon Coverage
Baseline Written security policy, basic AV, annual training, password policy, basic access controls. Minimum required for any federally insured CU. Exam findings likely if not met. CUs under $50M assets, 1 IT staff, no dedicated security. Most common exam finding: no written policy or annual training records. CoreRecon Sentinel covers all Baseline controls: 24/7 EDR, policy templates, annual training tracking, access control monitoring.
Evolving Risk-based approach, threat intelligence use, MFA on critical systems, documented IR plan, vendor risk process, log management. Minimum expectation for CUs $50M–$250M. CUs $50M–$250M, part-time IT, shared core banking vendor. Gaps: MFA not on all systems, no formal IR plan, vendor reviews informal. Sentinel + Fortress: MFA deployment support, written IR plan, threat intel feed, SIEM with 90-day log retention, vendor questionnaire templates.
Intermediate Continuous monitoring, penetration testing annually, formal vendor risk management, board cybersecurity training, documented threat hunting cadence. Expected for CUs $250M–$1B. CUs $250M–$1B, dedicated IT manager, contract CISO. Gaps: pen testing ad hoc or never, no formal threat hunting, board lacks cyber literacy. Fortress: continuous monitoring, annual pen test coordination, formal vendor risk program, quarterly board reporting package, threat hunting cadence.
Advanced Threat intelligence sharing (FS-ISAC), active threat hunting, automated response playbooks, tabletop exercises twice annually, real-time anomaly detection. Expected for CUs $1B+. CUs $1B+ with dedicated security staff. Gaps: FS-ISAC participation limited, tabletops not documented, automated response not deployed. Command: FS-ISAC intelligence feed integration, automated SOAR playbooks, bi-annual tabletop facilitation, advanced behavioral analytics, NCUA exam prep package.
Innovative Predictive threat modeling, AI-assisted anomaly detection, industry-leading threat sharing, zero-trust architecture, continuous compliance automation. Aspirational — few CUs at this level. $5B+ asset CUs or CUs with significant fintech partnerships requiring elevated assurance. Rare in the TX CU sector. Command + custom engagement: zero-trust architecture roadmap, custom threat modeling, AI-assisted behavioral baselining, continuous compliance automation for NCUA exam readiness.

What your SOC should be
alerting on right now

Credit union environments have specific detection requirements that generic MSSP SOC rules miss. Fiserv DNA/XP2, Jack Henry Symitar, and CO-OP card platforms require custom detection logic that CoreRecon has built for the CU sector.

Fiserv DNA / XP2 (Portico)
Admin Console Authentication Anomaly
Alerts when Fiserv admin console login occurs from a new device fingerprint, IP outside known admin CIDR range, or at unusual hours (nights/weekends). ALPHV and LockBit specifically target Fiserv admin credentials as the path to core banking encryption.
Jack Henry Symitar (Episys)
Episys Job Scheduler Modification
Monitors for unauthorized modifications to Symitar's RepGen job scheduler — threat actors add malicious batch jobs to exfiltrate member data on a scheduled basis without triggering interactive login alerts. A common persistence technique.
BIN Attack Detection
Card Authorization Volume Spike
Monitors for anomalous volume of declined card authorization attempts within a 60-minute window against a specific BIN range. Threshold: 3× baseline authorization attempt rate. Primary indicator of automated BIN enumeration attack targeting CU card programs.
Online Banking Session Anomaly
ATO Session Takeover Pattern
Detects credential stuffing patterns: high-velocity login attempts from distributed IPs, session tokens shared across geographically improbable locations within short timeframes, user agent strings matching known ATO toolkits (SentinelBOT, SNIPR, STORM).
ACH / Wire Transfer Platform
Out-of-Pattern Wire Origination
Alerts on wire transfer originations: new beneficiary account not in 90-day history, amount >150% of historical average for originator, origination within 4 hours of admin credential change, or transfers to high-risk jurisdictions outside member's normal pattern.
CO-OP / Shared Branching Network
Shared Branch Access Anomaly
Monitors for CO-OP shared branching transactions that deviate from member baseline: large cash transactions at distant shared branches, rapid multi-branch visits within hours, ATM withdrawal patterns matching mule network activity.
Active Directory / Identity
MFA Bypass / Help Desk Reset Alert
Alerts on: MFA disabled for privileged account, password reset followed immediately by MFA token reset (Scattered Spider signature), help desk ticket opened for senior officer account with rapid self-service completion, admin group membership changes outside change window.
MOVEit / Cleo / GoAnywhere MFT
Cl0p MFT Exploitation Indicator
Monitors for indicators of Cl0p TTPs: unexpected SQL execution against MFT database, new admin user creation via API, file enumeration across all transfer directories, outbound transfer to non-whitelisted IP, web shell deployment in MFT web root.

Three tiers mapped to
CU asset size and member volume

Sentinel
$89/endpoint/month
Designed for: CUs under $250M assets · 50–200 endpoints · up to 30K members
24/7 SOC monitoring — 30-min critical incident SLA
EDR deployment on all endpoints (Fiserv/Symitar workstations)
SIEM with 90-day log retention (NCUA-compliant baseline)
BIN attack detection logic pre-configured
NCUA Part 748 written security policy template
FFIEC CAT Baseline maturity coverage
Monthly threat briefing — CU-sector focused
Fortress
$109/endpoint/month
Designed for: CUs $250M–$1B assets · 200–600 endpoints · 30K–150K members
Everything in Sentinel
Vulnerability management + 72-hr critical patch SLA
Written Incident Response Plan (GLBA + NCUA compliant)
Vendor risk program — Fiserv/Jack Henry oversight documentation
MFA deployment support + legacy auth elimination
ATO detection — credential stuffing + session anomalies
FFIEC CAT Evolving–Intermediate maturity
Annual pen test coordination
Third-party vendor agreement for NCUA due diligence package
Command
$129/endpoint/month
Designed for: CUs $1B+ assets · 600+ endpoints · 150K+ members
Everything in Fortress
vCISO — GLBA Qualified Individual satisfied
Bi-annual tabletop exercise (NCUA exam-ready documentation)
FS-ISAC intelligence integration
Automated SOAR playbooks — wire fraud, ATO, BIN attacks
Breach notification package — NCUA 72hr + FTC 30-day + TX AG
FFIEC CAT Advanced maturity coverage
Board cybersecurity report — quarterly, examiner-ready
NCUA exam preparation support — policy package + gap analysis

Every clock running against
Texas credit unions

Framework Requirement Deadline / Status Penalty
NCUA Part 748 Written information security program, board-approved. Annual review required. Cyber incident notification within 72 hours of reasonable belief. Ongoing — exam cycle Exam finding; potential civil monetary penalty referral; loss of NCUA insurance eligibility risk for repeat violations
NCUA Part 749 Vital records preservation program. Must include cybersecurity logs and audit trails sufficient for incident reconstruction. Updated 2024 guidance requires 1-year minimum log retention. 1-yr log retention: effective 2024 Exam finding; limits ability to demonstrate compliance post-incident
GLBA Safeguards Rule (FTC 16 CFR §314) Qualified Individual designated, written WISP, MFA on all covered systems, encryption in transit/at rest, written IRP, annual board report, vendor oversight program. Effective Jun 9, 2023 Up to $9,000/day per violation under FTC Act §5; FTC referral to state AG; class action litigation risk
GLBA — FTC 30-Day Notification Notify FTC within 30 days of breach affecting 500+ customers via Safeguards portal. FTC shares notification with state AGs automatically. Effective May 13, 2024 $9,000/day per violation; automatic state AG notification triggers parallel state investigation
PCI DSS v4.0.1 All future-dated requirements (originally from v4.0 marked "best practice until March 31, 2025") are now mandatory. Includes expanded MFA scope, software security requirements for custom apps, and enhanced phishing-resistant authentication for cardholder environments. MANDATORY as of Mar 31, 2025 Card brand fines: $5K–$100K/month; card processing suspension; mandatory forensic investigation at CU expense
Texas Finance Code Ch. 59 Texas-chartered CUs must notify the Texas Department of Banking and affected customers of a breach involving Texas residents' information. Notification window: 60 days from discovery. 60 days from discovery Texas AG enforcement; civil penalty up to $100 per affected TX resident per day
Texas SB 820 (amended) Entities subject to GLBA (including CUs) that experience a breach affecting Texas residents must also notify the Texas AG within 60 days. Dual notification requirement: FTC (30 days) + TX AG (60 days). 60 days — runs concurrent with Ch. 59 AG enforcement; CID investigation; injunctive relief; civil penalties
FFIEC CAT 2.0 NCUA examiners use CAT 2.0 to assess maturity. Not a hard deadline — but CUs below Evolving maturity receive findings. CUs above Intermediate are typically cleared. Board must receive CAT assessment results annually. Annual exam cycle Exam findings; remediation plans with milestones required; repeated Baseline findings escalate to civil penalty referral
Full Brief + Executive Summary  •  PDF Download

Get the Complete 2026 Texas
Credit Union Threat Brief

8-page PDF — full incident database, NCUA reporting mechanics reference, GLBA Safeguards amendment checklist, FFIEC CAT 2.0 maturity mapping, and CoreRecon CU coverage model. Formatted for board distribution.

Brief sent to your inbox.
Check your email for the full PDF. John will follow up with a complimentary security assessment offer within 24 hours.
Free Assessment  •  No Contract Required
Know Your NCUA Exam Exposure
Before the Examiner Does

CoreRecon's free security posture assessment for Texas credit unions maps your controls against NCUA Part 748, GLBA Safeguards, and FFIEC CAT 2.0. You get a written gap report, FFIEC CAT maturity score, and remediation roadmap — whether you engage us or not.

About This Report
The 2026 Texas Credit Union Cyber Threat Brief is produced by CoreRecon, a Service-Disabled Veteran-Owned Small Business (SDVOSB) based in Corpus Christi, TX. CoreRecon provides managed security services to Texas credit unions, financial institutions, and regulated entities with a 30-minute critical incident SLA and CU-sector-specific detection logic for Fiserv DNA/XP2 and Jack Henry Symitar environments.
Sources: NCUA Annual Report 2024, NCUA Part 748/749 regulatory text, FTC Safeguards Rule 16 CFR §314, FFIEC CAT 2.0 (2025 update), FBI IC3 Annual Report 2024, IBM Cost of a Data Breach 2025, Verizon DBIR 2025, Coveware Ransomware Report Q4 2025, CUNA Mutual Group Research 2025, KrebsOnSecurity, Databreaches.net, public NCUA disclosure portal, SEC Form 8-K filings.
This brief is for informational purposes. It does not constitute legal, compliance, or regulatory advice. Consult qualified counsel for specific regulatory obligations applicable to your institution.