Credit Unions Made to Look 'Nefarious'

By Ray Birch

WASHINGTON—Law firms are moving quickly to file class-action lawsuits against financial institutions victimized by the growing number of ransomware attacks, according to one attorney, who is sharing strategies CUs should be considering before and after an attack occurs.

As CUToday.info reported, numerous lawsuits have been filed against Patelco Credit Union following a ransomware attack that knocked many of its systems offline for weeks and from which it considers to be affected.

Federal court records show at least six cases filed in the U.S. District Court in Northern California, and at least 12 filed in Alameda County Superior Court in July, according to The Independent. The report notes that some of the lawsuits are class action cases, representing more than one plaintiff.

Feature Ransomware Again

“I've seen these types of cases on the rise against credit unions, really going back a couple of years,” said Brandy Bruyere, a partner at Honigman, LLP. “However, the pace has been much more significant in the past year.”

‘Race to the Courthouse’

As CUToday.info has reported, Patelco was hit by the ransomware attack in late June, shutting down its online and mobile banking and even making it impossible for branch staff to provide balances and other services to members. Patelco was able to restore some services to its 500,000 members approximately two weeks later.

“There are different states that require reporting (of data breach incidents) to the state attorney general, which makes it fairly easy for the plaintiffs’ attorneys to see that some breach has occurred, and then turn right around and race to the courthouse,” Bruyere explained.

Bruyere said the Patelco incident is a good example of how quickly class-action lawsuits are being filed following a ransomware attack or data breach.

bruyere_brandy 006 16_rt

Brandy Bruyere

Seems ‘Nefarious’

“These plaintiffs’ attorneys know there's opportunity and they're not hesitating to file the suits,” she said. “Oftentimes, the credit union itself might not have directly had the incident occur within its walls. But what these plaintiffs’ attorneys love to do is point to the length of time between when a breach occurred and when members received their notice about the breach. And they make (the credit union’s actions) seem very nefarious, which is not necessarily true.”

Bruyere detailed what is contributing to the increased number of ransomware threats.

‘Getting More Sophisticated’

“As we know, ransomware attacks have been on the rise,” she noted. “The fraudsters that use these kinds of attacks are just getting more sophisticated. Credit unions are doing their due diligence in terms of their defense systems, training employees on what to do and what not to do, such avoiding clicking on untrusted links. They test their teams. They find out where the vulnerabilities are and retrain the people who clicked on the links during a test, for example. Credit unions are getting better and better at defending against ransomware.”

Bruyere emphasized fraudsters are just getting better at making their fake messages look legitimate, often with the use of AI. And they are getting better at hacking people’s emails inside companies and then sending out messages from a trusted address.

‘Finding More Vulnerabilities’

“These days criminals are just finding more vulnerabilities,” Bruyere said. “Credit unions are facing more of these risks.”

Bruyere pointed out ransomware attacks can affect credit unions when vendor vulnerabilities are exploited.

“So, the risks are not always direct,” she noted.

What should credit unions be doing in a period in which lawsuits related to ransomware attacks and data breaches are growing?

The first step is to closely examine vendor contracts, Bruyere said.

“Look at your vendor agreements carefully for any vendor that touches member data and make sure you’re comfortable with things like the limitation of liability in those agreements,” she recommended. “Does it say liability is limited to one year's worth of fees? Does it say we're only liable if we were grossly negligent? How is that structured in the agreement? Is the vendor going to indemnify the credit union? What are they promising to do in the event of a data breach? How quickly are they going to notify the credit union? I'm seeing a lot of clients want to be a little more aggressive on that front.”

Vendors Look to Protect Themselves

Simultaneously, Bruyere is seeing vendors wanting to limit their liability.

“Because, at the end of the day, you know a lot of these incidents might not happen because of negligence,” she said. “Cyber security is a risk-based business and everybody's just trying to stay ahead of fraudsters. It's Whac-A-Mole out there right now. Patch something, fix a vulnerability, and then the crooks just find a new way in.”

When it comes to ransomware attacks, Bruyere said credit unions must be nimble in how they approach their security systems and always focus on educating their teams on proper security practices.

“Just remain as vigilant as possible,” she said.

Differences in Lawsuits

Bruyere also pointed to potential differences in a class-action lawsuits related to a ransomware attack and those from a general data breach.

“If the ransomware attack is a direct attack on a credit union, and not through a vendor, at some point some employee likely clicked on something they should not have. Right? Somebody opened an email that said click here for a free Mastercard gift card, probably purported to be from their employer,” she said. “Then it becomes factual argument of was this negligence. Would a reasonable person have clicked on this link.”

Bruyere reminded the effects of a ransomware attack can be long-lasting and limit members’ access might to vital services—possibly making them late on bills or rent.

Important to Communicate

“Once credit unions are hit with these lawsuits, they must notify their insurer,” Bruyere explained. “That's required under those coverages. But it's also important to talk to your own counsel, not just the one assigned by your insurance company. There's different rules about who's representing whom and I do think it's important for the credit union to get what I would call independent legal counsel, at least for some initial consultation—even if they know they'll end up using their insurance for the actual litigation.”

Bruyere added that effective communication with members in the event of ransomware attack is paramount.

“How you communicate during this crisis is important,” she said.

Section: Standard
Word Count: 1329
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/Credit-Unions-Made-to-Look-Nefarious