MADISON, Wis.— TruStage expects the majority of its key operational processes to be back online by mid-August following the sweeping cyberattack that forced the company to shut down systems earlier this month, while executives say they still do not know whether credit union member data was accessed during the incident.
In a video update to credit union partners, TruStage President and CEO Terrance Williams said restoration efforts have moved into a phased recovery after the July 11 attack, with the company rebuilding portions of its technology environment rather than simply restarting systems. Williams also stressed that forensic investigators have not yet determined whether any member information was compromised, promising credit unions they would be notified before any member communications if data exposure is confirmed.
The update comes as TruStage faces mounting legal scrutiny, with multiple lawsuits now filed over the cyberattack alleging the insurer failed to adequately safeguard sensitive information. While the litigation continues to grow, Williams emphasized the company's immediate focus remains safely restoring operations and completing a complex forensic investigation.
"We anticipate the majority of our key processes will be operational by mid-August," Williams said. "While we've talked a lot about systems coming online, know they may not be fully operational or fully back to normal."
Williams described the July 11 incident as "a particularly broad attack" on the company's network and systems that required far more than simply bringing servers back online. Instead, TruStage has rebuilt portions of its infrastructure, refreshed employee laptops and implemented additional security controls before reconnecting employees to company systems.
"The goal is for us and for you to have confidence that as we bring things back online, we've made sure that they're protected, they're safe and they're stable," Williams said.
The company said it has established a clean, isolated technology environment segmented from systems that were impacted, potentially impacted or remain under investigation. Recovery is proceeding in phases to ensure systems can be restored without reintroducing malicious code or allowing threat actors back into the environment.
Williams acknowledged the recovery timeline has been frustrating for credit unions and their members but said the deliberate approach is necessary to ensure long-term stability.
"We're being deliberate and diligent to ensure that we are doing everything we can to bring systems up while protecting employees, partners, members and the organization," he said.
Williams said investigators are still working to determine whether the attackers accessed sensitive information, a question that remains at the center of the ongoing investigation. While TruStage has retained cybersecurity firm Mandiant to assist with the forensic investigation, Williams said the company still cannot determine whether data was viewed or stolen.
"The reality is these forensic investigations take time," Williams said. "It takes time to figure out whether anything was accessed and to confirm what wasn't. And if information was accessed, it takes time to confirm what kind of information it was and where that data came from."
Williams said the company understands the uncertainty is difficult for credit unions seeking answers for their members but cautioned against drawing conclusions before investigators complete their work.
"We don't know yet," Williams said. "While we don't know if credit union member data was accessed, what I can tell you is that you will be the first to know if this is the case, and we'll work in partnership with you to ensure that any notification or reporting process is as easy as possible."
In a companion email sent to credit union partners, TruStage reinforced that it would be "premature to draw conclusions about the full scope or impact of the incident." To help institutions respond to member concerns, TruStage has provided a template member letter along with talking points and frequently asked questions that credit unions can use while the investigation continues.
Operationally, the company said it has restored several critical customer-facing functions even as broader systems remain offline.
According to the email update, TruStage is now answering thousands of customer calls through a third-party contact center while also making outbound calls. The company reported progress across several business lines, including lending, wealth management and life insurance.
For lending, TruStage has begun testing a process with eight credit unions to resume recurring debt protection payments on claims approved before the outage and expects to expand that capability in the coming weeks.
Within its wealth business, interim processes are now available for annuity transactions, death claims, partial withdrawals and full surrenders. Retirement transaction recovery has also advanced into testing, with temporary capabilities planned for participant disbursements before broader functionality returns.
Life insurance operations remain more complex because the platform depends on multiple interconnected systems. TruStage said it expects to restore basic billing and claims servicing during the first half of August while continuing to rebuild additional components needed for full operations.
The latest update follows weeks of disruption that affected insurance claims processing, lending protection products, wealth management services and other offerings used by hundreds of credit unions nationwide.
