HAGERSTOWN, Md.–The CUSO at the center of an outage affecting services at more than 60 credit unions has issued a statement offering an update on what’s taking place, while NCUA has provided its own update on the CUs involved and how it has been responding, along with expressing some frustrations over its inability to get more information more quickly.
In its statement, Ongoing Operations, a unit of Trellance Cooperative Holdings, said it took immediate action following the ransomware attack on the company that occurred on Nov. 26. That attack continues to affect approximately five-dozen credit unions running the Fedcomp data processing system.
The company said that certain statements that have appeared in the media related to the attack and resulting outage have been misleading.
In its message to credit unions, Ongoing Operations stated, “Should you come across conflicting information in the press compared to what we've communicated, it's highly probable that the press coverage is either inaccurate or unrelated to your specific situation,” the company said in its statement.
Immediate Response
“Once we identified the incident, we immediately began working with our IT staff and engaged third-party forensic specialists to investigate the nature and scope of the incident. This incident is isolated to a segment of the Ongoing Operations network and does not impact Trellance products or services,” the company said. “Our team is diligently working around the clock to minimize service interruptions wherever possible and to ensure the safety of information stored on our systems. We will notify impacted individuals once we confirm the scope of the incident.”
Ongoing Operations said the investigation to determine what impact this incident may have had on information stored on its network systems is ongoing, and that it has engaged “leading experts to recommend and implement additional measures” designed to increase its data security and block further unauthorized access to our systems moving forward.
‘Substantial Time’
“The nature of this ongoing investigation takes a substantial amount of time as the process of reviewing the files to determine what information may have been involved is lengthy and complex,” Ongoing Operations said in a statement. “We have made significant progress as we continue to re-establish services for customers. We are encouraged by our progress to date and remain confident our teams will be able to resolve the issue in a safe and secure manner.”
Additional Updates
In its updated Incident Status statement, Ongoing Operations further noted:
- “We notified federal law enforcement. At this time, our investigation is currently ongoing, and we will continue to provide updates as necessary.
- “As part of our response to this incident, we are reviewing the impacted data to determine exactly what information was impacted and to whom that information belonged.
- “This incident is isolated to a segment of the Ongoing Operations network and our team is diligently working around the clock to minimize service interruptions wherever possible and to ensure the safety of information stored on the Ongoing Operations systems.
- “We have notified all impacted customers and any who have not received a notice were not affected by this incident.
- “The forensic investigation into the incident is still ongoing. We continue to make progress in re-establishing services for customers and we are notifying customers whose information was impacted. We will share more information as soon as there are updates.
- “Ongoing Operations will assist impacted credit unions with member notification and will offer complimentary credit monitoring and identity restoration services to those who are impacted.”
NCUA Response
Meanwhile, during a call with the media, NCUA officials said they are also working to respond to the incident.
According to NCUA, all of the institutions involved are below $100 million in assets, with total assets of $912 million and 93,000 represented by the 60 credit unions affected. At least one of those CUs told CUToday.info it has had to turn to manual processing in order to serve members as a result of the outage.
NCUA Chairman Todd Harper said the agency has been in touch with those CUs and is “working directly to help them get their systems and operations back online so members can access their funds.”
Harper added NCUA has been in contact with the Treasury Dept., the Cybersecurity and Infrastructure Agency (CISA), the FBI and Congress as part of its incident response.
Frustration at Agency
Harper said he and the agency itself have been frustrated in attempting to get information on the outage, and said NCUA continues to speak with the affected credit unions on a daily basis. He said at least one credit union has also expressed its own frustrations with the issue.
NCUA Cybersecurity Advisor and Coordinator Todd Finkler said the two CUSOs and individual credit unions have been good about communicating with the agency.
“But, honestly, this is almost a chain problem, so if we're asking what (technology providers) a credit union uses they know they’re using Fedcomp, but Fedcomp is using other third parties, so we get to fourth and fifth parties and that makes it really challenging to get a complete picture,” Finkler said. “I would argue that we feel like we probably have the understanding of what's going on, but nobody has a complete picture.”
How Long Can This Go On?
How long can the affected credit unions continue to operate without full access to member data?
“Credit unions are identifying workarounds, including the manual workarounds,” said Harper. “We are working with them on that overall.”
Added Finkler, “It’s been impressive to watch all parties taking a role in this. We have been working with the credit unions who have been identifying workarounds.”
Finkler credited Fedcomp for “doing a good job on a daily basis” of providing information to credit unions of member activities.
The agency said it has informed the credit unions it is prepared to step in and address any liquidity events that may occur.
Finkler said NCUA is “starting to see some credit unions come back and be operational and that’s good.”
Stressing Need for Vendor Oversight
NCUA is again using the ransomware attack to urge Congress to provide the agency with third-party oversight authority.
“It has been more than 20 years since the NCUA has had the necessary statutory authority to examine third party vendors for (events) such as this one,” said Harper. “As a result, NCUA’s ability to analyze and assess risks posed by third-party vendors to the credit union system remain limited, and when incidents and outages like this one occur the agency's lack of authority limits our ability to respond effectively and quickly, which negatively impacts credit unions and their members. In fact, NCUA’s response was delayed by several days due to the lack of direct information from the service providers.
“Even today, almost two weeks after the first incident report, the NCUA is still unable to determine the full extent of the ransomware attack and the resulting outages and disruptions to Fedcomp and Ongoing Operations, as well as other secondary systems and vendors that utilize these systems to support credit unions,” Harper continued, urging Congress to act. “The agency’s lack of vendor authority means thousands of credit unions, tens of millions of consumers and trillions of dollars in assets are exposed to serious risks. The time has come to close this growing regulatory blind spot.”
Having vendor oversight authority, Harper suggested, would allow NCUA to provide additional information to credit unions that are considering various vendors before they move to purchase certain products or services.
Congress Could Act
The chairman said he believes Congress is paying attention to the issue, noting language to provide NCUA with the authority it is seeking was nearly included in must-pass legislation at the end of 2022. He noted Rep. Bill Foster (D-IL) said he plans to reintroduce a vendor authority bill in the current Congress. While the national trade associations have opposed the expanded powers, Harper said there is support among credit unions, including by the GoWest CU Association, which has said it would support such authority.
