By Ray Birch
PERU, N.Y.— It’s back to old-fashioned cash and manual data entry for one of the credit unions impacted by the ransomware attack on a vendor that has affected approximately 60 CUs.
The $52.5-million Mountain Valley FCU here has been serving members with cash to get them through what is now about one week without its data system operating. As a result, members and the credit union cannot see the amount of money that is in an account.
As CUToday.info reported, approximately 60 credit unions in the U.S. have been hit with outages due to a ransomware attack on Ongoing Operations, a unit of St. Petersburg, Fla.-based Trellance. NCUA has confirmed the attack and in a statement to the media said it is “coordinating with affected credit unions” in response.
“I've heard our data processor (FedComp) is in the process of posting items from last week,” said Mountain Valley CEO Maggie Pope, who noted the problem began early last week. “They're hoping that soon we will be able to get to our new server on our desktops. But I really don’t have an ETA on when this will be all fixed, but I am hoping it will be this week.”
Pope said the new desktop server will allow the credit union to begin inputting the data from the transactions it has conducted in the branches—all with cash.
‘The Biggest Problem’
“The biggest problem is members cannot see their money, and that bothers people,” explained Pope. “They cannot see deposits coming in and withdrawals. We're asking members to come in to get cash—but they can still use debit cards and write checks. But, basically, we're kind of doing things the old-fashioned way.”
Pope said the credit union, which is located on Lake Champlain on the border with Vermont, has told its approximately 4,600 members that Mountain Valley is “going to see you through this. Whatever they need.”
She further noted that because the CU is unable to check member balances, it has put in place withdrawal limits in line with what a member might typically withdraw
“We are not naïve,” she said. “We know our members well. They get paid every week.”
The CEO stressed Mountain Valley has been “very transparent” with members about what has happened.
Most Are Understanding, But…
“We’re reassuring them that their member information has not been compromised, and that we're not going bankrupt—which is one of the rumors I’ve heard,” she said. “We let them know we are safe and strong and that the only thing that is different with your account is that we cannot get in and see what your balances are, nor can you.
“I would say 90% of our members are very understanding, but we have had a few of who have been a little irate, which I understand. People live paycheck to paycheck and they want to know exactly what they can spend,” Pope said.
A Big Target
One cyber security expert said credit unions, such as Mountain Valley, should not be surprised by the recent ransomware attack, stating third-parties present crooks with an attractive door into financial institutions.
Brett Callow, threat analyst with Emisoft, told CUToday.info that supply chains have big targets on their backs.
“Service and solution providers are extremely attractive targets as they can enable hackers to disrupt—and potentially steal data from—multiple companies in a single attack,” he said. “Such incidents have become increasingly common and I expect that credit unions and other organizations will face an increasing number of supply chains threats in the months ahead.”
NCUA Response
On Monday NCUA told CUToday.info that it continues to work with the approximately 60 credit unions that have experienced system outages affecting member account availability.
“Although not fully operational, many of these credit unions have alternative services in place that allow members to access their funds,” NCUA stated.
The outage comes as NCUA has been repeatedly warning credit unions of the threats posed by cyberattacks, with NCUA Chairman Todd Harper and other members of the board saying the threat is the one that “keeps me up at night.” Other NCUA board members have made similar statements.
The attack also highlights an issue Harper and the other board members have also raised, which is the lack of third-party vendor oversight by NCUA. The NCUA board has repeatedly requested that authority from Congress, including in Harper’s most recent appearances before the House and Senate.
NCUA officials often note it is the only federal financial regulator lacking such authority.
