NCUA examiners now require documented cybersecurity programs. ALPHV/BlackCat hit MeridianLink and disrupted 60+ credit unions in 24 hours. Patelco lost 726K members' data. Evolve Bank exposed 7.6M records. The playbook is documented — and it's being run against the sector right now.
| Metric | Value | Source |
|---|---|---|
| Financial services breach cost (avg 2025) | $4.88M | IBM Cost of a Data Breach 2025 |
| Credit union ransom demand avg (2024–2025) | $1.2M–$4.5M | Coveware Q4 2025; FBI IC3 |
| CU operational downtime from ransomware | 18–27 days avg | Fidelity National / Patelco disclosures |
| Member notification cost per record (financial) | $183–$212 | IBM CODB 2025; Ponemon Institute |
| FTC 30-day Safeguards breach notification deadline | Effective May 2023 | FTC Safeguards Rule 16 CFR §314 |
| NCUA cyber incidents reported (2024) | 417 notifications | NCUA Annual Report 2024 |
| Third-party/vendor-caused CU incidents | 47% of all incidents | CUNA Mutual Group, 2025 |
| BEC wire fraud targeting financial institutions (2024) | $2.9B total losses | FBI IC3 2024 Annual Report |
| CUs with <50K members — no dedicated security staff | 78% | CUNA Mutual / NCUA exam data |
Filterable database of verified CU and adjacent financial-sector breaches. Data from NCUA disclosures, SEC 8-K filings, state AG notifications, and public reporting.
| Date | Institution | Members Affected | Attack Vector | Downtime | Ransom |
|---|---|---|---|---|---|
| Nov 2023 | MeridianLink Loan origination platform — 60+ CU clients disrupted |
60+ CUs; undisclosed member count |
ALPHV/BlackCat ransomware; third-party loan origination SaaS. NCUA issued emergency guidance. | 24–72 hrs disruption per CU; loan processing halted | Not paid (disclosed) |
| Jun 2024 | Patelco Credit Union Dublin, CA — $9.4B assets |
726,000 members |
RansomHub ransomware. Disrupted banking services including transfers, direct deposit, balance checks for 2+ weeks. | ~14 days core banking services offline | Unknown |
| Jun 2024 | Evolve Bank & Trust West Memphis, AR — fintech partner bank |
7,640,000 customers |
LockBit 3.0 ransomware. Fintech BaaS partner to Affirm, Mercury, Stripe Treasury. CU-adjacent: ACH and card processing exposure. | 2+ weeks disruption to fintech partners | Not paid (confirmed) |
| Oct 2023 | Mr. Cooper (Nationstar Mortgage) Coppell, TX — largest U.S. mortgage servicer |
14,690,000 customers; TX-headquartered |
Network intrusion; data exfiltration of mortgage account data including SSNs, DOBs, addresses. 3-week operational disruption. | 21 days — online payment portal taken offline | Not ransomware (exfil only) |
| Nov 2023 | Fidelity National Financial National title insurance — TX top market |
1,300,000 customers; critical TX real estate ops |
ALPHV/BlackCat ransomware. Shut down all real estate title processing in TX for 7+ days. CU mortgage origination pipelines halted. | 7–10 days statewide title processing outage | Ransom paid — amount undisclosed |
| Jul 2024 | AT&T Data Breach Call records of 109M — TX member exposure |
109,000,000 U.S. customers (call metadata) |
Snowflake credential theft via infostealer malware. Same Cl0p/ShinyHunters campaign that hit Ticketmaster, Advance Auto Parts. CU relevance: TX member phone numbers used for social engineering. | No operational downtime — data exfil only | $370K paid (to Shiny Hunters) |
| 2024 | First Tech Federal Credit Union Mountain View, CA — 650K members |
~650,000 members |
Third-party vendor breach via Infosys BPO (IT vendor). Same incident affected multiple CUs through shared managed service provider. | Delayed — initially undetected | Unknown |
| 2024–2025 | Multiple TX-area CUs Texas credit unions — NCUA 417 reported incidents |
Aggregate: ~280,000 TX members (NCUA/FBI data) |
BEC wire fraud, online banking credential stuffing, card skimming at CO-OP ATM network, and phishing-to-ATO attacks. 47% involved third-party vendor access. | Varies by incident type | Mixed |
Sources: NCUA disclosure portal, SEC 8-K filings, KrebsOnSecurity, Bleeping Computer, HIPAA Journal / Databreaches.net. Ransom payment status from public disclosures only.
NCUA's cyber incident reporting rule (Part 748.1(b)) requires federally insured credit unions to notify NCUA within 72 hours of reasonably believing they experienced a reportable cyber incident. This is separate from your member notification obligations.
| Question | Answer |
|---|---|
| What triggers the 72-hour clock? | Reasonable belief that a cyber incident has occurred that: (1) materially disrupts/degrades operations or delivery of products/services; (2) leads to unauthorized access to or misuse of member information; or (3) affects a credit union system, network, or asset that could have a material effect on the CU's operations. The clock starts at the moment of reasonable belief, not confirmed detection. |
| What does NOT trigger the rule? | Routine phishing attempts with no successful compromise. Vulnerability discoveries without evidence of exploitation. System outages with no cyber cause. Third-party outages with no CU system involvement. Proactive security testing. |
| How is notification made? | Through NCUA's online CyberGrants portal. Submission requires: incident description, affected systems, initial impact assessment, and whether members were notified. NCUA assigns an examiner to follow up within 5 business days for significant incidents. |
| What happens after notification? | NCUA may issue a Request for Information (RFI) requiring a full incident report within 30 days. Examiners assess whether the CU's incident response plan was followed, whether detection controls were adequate, and whether remediation is complete. Failure to notify within 72 hours is an exam finding and may result in civil monetary penalty referral. |
| Part 749 records preservation — what does it require? | Part 749 requires CUs to maintain a vital records preservation program covering records needed to reconstruct financial position and serve members in the event of a disaster. This includes member account records, loan documents, and now — per NCUA guidance — cybersecurity logs and audit trails sufficient to reconstruct a cyber incident timeline for examiner review. |
| Examiner expectations post-incident | Examiners look for: documented timeline from detection to containment; evidence that IR plan was followed; board notification within exam cycle; root cause analysis; remediation plan with milestones; updated risk assessment. CUs without a written IR plan typically receive a finding regardless of incident severity. |
| Requirement | What It Means for Your CU | Effective |
|---|---|---|
| Qualified Individual (QI) | Designate a specific individual — in-house or third-party — responsible for the information security program. Must report to the board at least annually. vCISO arrangements (like CoreRecon Command) satisfy this requirement. Cannot be delegated without documentation. | Jun 9, 2023 |
| Written Information Security Program (WISP) | Comprehensive written program covering: risk assessment, safeguards, vendor oversight, testing, and employee training. Must be reviewed and updated at least annually. Must be based on a documented risk assessment. Audit-ready documentation is required — verbal or informal programs do not satisfy the rule. | Jun 9, 2023 |
| Multi-Factor Authentication (MFA) | Required for all systems that store, process, or transmit member financial data. Applies to: online banking admin portals, core banking admin consoles, email systems, VPN and remote access, cloud storage, and third-party integrations. Legacy auth bypass routes must be closed. This is the most common gap finding in FTC examinations. | Jun 9, 2023 |
| Encryption — data in transit and at rest | All member financial data must be encrypted in transit (TLS 1.2 minimum) and at rest (AES-256 recommended). Covers: ACH file transfers, core banking database storage, backup tapes and cloud backups, email with member financial data, mobile app data. Unencrypted PII transmissions are per se violations. | Jun 9, 2023 |
| Written Incident Response Plan (IRP) | Documented IRP covering: detection, containment, eradication, recovery, and post-incident review. Must assign roles and responsibilities. Must address member notification workflows. Must be tested annually (tabletop minimum). Plan must be provided to NCUA examiners on request — "in progress" or undocumented plans are findings. | Jun 9, 2023 |
| FTC 30-day breach notification | Notify FTC within 30 days of discovering a breach affecting 500+ customers. Notification via FTC Safeguards report portal. Includes: date of breach, nature of data involved, number of customers, what safeguards were in place. FTC shares notifications with state AGs. Failure triggers per-day civil penalty exposure: up to $9,000/day under FTC Act Section 5. | May 13, 2024 |
| Vendor/service provider oversight | Monitor and oversee vendors (including Fiserv, Jack Henry, CUSO partners) with written vendor due diligence process. Must include security questionnaires, contractual security requirements, and periodic review. NCUA examiners specifically ask about Fiserv DNA and Jack Henry Symitar vendor oversight documentation. | Jun 9, 2023 |
NCUA examiners reference FFIEC CAT 2.0 maturity levels to assess whether your security program is commensurate with your asset size and risk profile. CUs below Evolving maturity receive exam findings. CUs above Intermediate maturity are typically cleared quickly in cyber exams.
| Maturity Band | What NCUA Expects | Typical CU Profile | CoreRecon Coverage |
|---|---|---|---|
| Baseline | Written security policy, basic AV, annual training, password policy, basic access controls. Minimum required for any federally insured CU. Exam findings likely if not met. | CUs under $50M assets, 1 IT staff, no dedicated security. Most common exam finding: no written policy or annual training records. | CoreRecon Sentinel covers all Baseline controls: 24/7 EDR, policy templates, annual training tracking, access control monitoring. |
| Evolving | Risk-based approach, threat intelligence use, MFA on critical systems, documented IR plan, vendor risk process, log management. Minimum expectation for CUs $50M–$250M. | CUs $50M–$250M, part-time IT, shared core banking vendor. Gaps: MFA not on all systems, no formal IR plan, vendor reviews informal. | Sentinel + Fortress: MFA deployment support, written IR plan, threat intel feed, SIEM with 90-day log retention, vendor questionnaire templates. |
| Intermediate | Continuous monitoring, penetration testing annually, formal vendor risk management, board cybersecurity training, documented threat hunting cadence. Expected for CUs $250M–$1B. | CUs $250M–$1B, dedicated IT manager, contract CISO. Gaps: pen testing ad hoc or never, no formal threat hunting, board lacks cyber literacy. | Fortress: continuous monitoring, annual pen test coordination, formal vendor risk program, quarterly board reporting package, threat hunting cadence. |
| Advanced | Threat intelligence sharing (FS-ISAC), active threat hunting, automated response playbooks, tabletop exercises twice annually, real-time anomaly detection. Expected for CUs $1B+. | CUs $1B+ with dedicated security staff. Gaps: FS-ISAC participation limited, tabletops not documented, automated response not deployed. | Command: FS-ISAC intelligence feed integration, automated SOAR playbooks, bi-annual tabletop facilitation, advanced behavioral analytics, NCUA exam prep package. |
| Innovative | Predictive threat modeling, AI-assisted anomaly detection, industry-leading threat sharing, zero-trust architecture, continuous compliance automation. Aspirational — few CUs at this level. | $5B+ asset CUs or CUs with significant fintech partnerships requiring elevated assurance. Rare in the TX CU sector. | Command + custom engagement: zero-trust architecture roadmap, custom threat modeling, AI-assisted behavioral baselining, continuous compliance automation for NCUA exam readiness. |
Credit union environments have specific detection requirements that generic MSSP SOC rules miss. Fiserv DNA/XP2, Jack Henry Symitar, and CO-OP card platforms require custom detection logic that CoreRecon has built for the CU sector.
| Framework | Requirement | Deadline / Status | Penalty |
|---|---|---|---|
| NCUA Part 748 | Written information security program, board-approved. Annual review required. Cyber incident notification within 72 hours of reasonable belief. | Ongoing — exam cycle | Exam finding; potential civil monetary penalty referral; loss of NCUA insurance eligibility risk for repeat violations |
| NCUA Part 749 | Vital records preservation program. Must include cybersecurity logs and audit trails sufficient for incident reconstruction. Updated 2024 guidance requires 1-year minimum log retention. | 1-yr log retention: effective 2024 | Exam finding; limits ability to demonstrate compliance post-incident |
| GLBA Safeguards Rule (FTC 16 CFR §314) | Qualified Individual designated, written WISP, MFA on all covered systems, encryption in transit/at rest, written IRP, annual board report, vendor oversight program. | Effective Jun 9, 2023 | Up to $9,000/day per violation under FTC Act §5; FTC referral to state AG; class action litigation risk |
| GLBA — FTC 30-Day Notification | Notify FTC within 30 days of breach affecting 500+ customers via Safeguards portal. FTC shares notification with state AGs automatically. | Effective May 13, 2024 | $9,000/day per violation; automatic state AG notification triggers parallel state investigation |
| PCI DSS v4.0.1 | All future-dated requirements (originally from v4.0 marked "best practice until March 31, 2025") are now mandatory. Includes expanded MFA scope, software security requirements for custom apps, and enhanced phishing-resistant authentication for cardholder environments. | MANDATORY as of Mar 31, 2025 | Card brand fines: $5K–$100K/month; card processing suspension; mandatory forensic investigation at CU expense |
| Texas Finance Code Ch. 59 | Texas-chartered CUs must notify the Texas Department of Banking and affected customers of a breach involving Texas residents' information. Notification window: 60 days from discovery. | 60 days from discovery | Texas AG enforcement; civil penalty up to $100 per affected TX resident per day |
| Texas SB 820 (amended) | Entities subject to GLBA (including CUs) that experience a breach affecting Texas residents must also notify the Texas AG within 60 days. Dual notification requirement: FTC (30 days) + TX AG (60 days). | 60 days — runs concurrent with Ch. 59 | AG enforcement; CID investigation; injunctive relief; civil penalties |
| FFIEC CAT 2.0 | NCUA examiners use CAT 2.0 to assess maturity. Not a hard deadline — but CUs below Evolving maturity receive findings. CUs above Intermediate are typically cleared. Board must receive CAT assessment results annually. | Annual exam cycle | Exam findings; remediation plans with milestones required; repeated Baseline findings escalate to civil penalty referral |
8-page PDF — full incident database, NCUA reporting mechanics reference, GLBA Safeguards amendment checklist, FFIEC CAT 2.0 maturity mapping, and CoreRecon CU coverage model. Formatted for board distribution.
CoreRecon's free security posture assessment for Texas credit unions maps your controls against NCUA Part 748, GLBA Safeguards, and FFIEC CAT 2.0. You get a written gap report, FFIEC CAT maturity score, and remediation roadmap — whether you engage us or not.