Here's What 1 Expert Says is Happening

By Ray Birch

BIRMINGHAM, Ala.—Two more credit unions have allegedly been compromised in ransomware attacks, according to respective postings on two criminal organizations’ websites.

The $83-million Jefferson CU in Hoover, Ala., and the $466-million Public Employees CU in Austin, Texas, have allegedly been attacked, but the degree to which any penetration occurred is not known.

RansomHouse claims to have successfully hacked Jefferson Credit Union, stating on its website, “Below is a list of companies that either have considered their financial gain to be above the interests of their partners/individuals who have entrusted their data to them or have chosen to conceal the fact that they have been compromised.”

Jefferson CU’s name and link to their website are on the list.

Meanwhile, the criminal organization AvosLocker allegedly has compromised PECU. The group on its website states, “We have confidential files belonging to all 29,000 members including name, address, SSN, Telephone, email, credit cards, loan applications, IRS documents…”

Hackers typically post a sample of the data they claim to have compromised. AvosLocker posts a portion of a W-2 form that appears to be from one of PECU’s employees.

A Shift in Strategy

As CUToday.info has reported, ransomware attacks have shifted from encrypting an organization’s data and demanding a ransom to unlock it, to stealing the information, posting a sample on their website, and then threatening to make all of the data public if the organization does not pay the ransom. Sometimes the criminals do both—encrypt the data and also hold it for ransom.

CUToday.info contacted both credit unions. Jefferson CU declined to comment. PECU did not respond.

Brett Callow, threat analyst with Emsisoft, told CUToday.info that currently there are about 30 active data-stealing ransomware operations.

“But keep in mind that groups retire old brands, launch new ones, teams split and start their own operations,” Callow said. “Also, many groups work on a profit-sharing or an affiliate model basis, with the groups that created the ransomware effectively renting it out and splitting proceeds with the people who use it to carry out their attacks—and the latter can cooperate with multiple groups.”

callow

Brett Callow

Callow said, essentially, the ransomware landscape constantly shifts.

“Even when a criminal brand appears to be new, its operators may well be old hands,” he said.

Likely Not a Trend

Callow said that two credit unions being attacked in a one-month period does not signal that cooperatives have become a bigger target.

“Most ransomware attacks are random and fluctuations in numbers and sectors is to be expected,” he said.

Callow reminded that most ransomware attacks succeed because of “basic security failings.”

“For example, not patching or not using multi-factor authentication,” he said. “This means most incidents are preventable and, by extension, that an organization can reduce the likelihood of becoming victims simply by getting the basics right.”

Bank Info Security recently reported that ransomware attacks have come “storming back” after experiencing their “typical end-of-the year decline.”

A Surge in Attacks

From February to March, the number of known ransomware victims surged from 185 to 283, Bank Info Security reported, citing NCC Group data.

Based on attacks that have come to light, Lockbit 2.0 was the most prolific, accounting for 96 of the 283 attacks, followed by Conti with 71 attacks, Hive with 26 attacks and BlackCat, aka Alphv, with 23 attacks, the data show.

Of the known victims, 44% are based in North America, followed by Europe at 38% and Asia at 7%.

In March, attacks involving Hive, which first appeared in June 2021 and which often targets the healthcare sector, increased markedly compared to it being tied to only nine known incidents in February, which "begs the questions as to whether we are looking at a new, dominant threat actor,” Bank Info Security stated.

As CUToday.info recently reported, the war in Ukraine could slow ransomware attacks in the U.S., according to security experts.

The Cloud Isn’t Sufficient

But even if ransomware attacks do slow, credit unions should be on guard for system attacks from Russia—a concern NCUA has addressed. Security expert Jim Stickley has also advised that as the war in Ukraine potentially threatens more data systems, financial institutions must make sure they have hard-copy backups of their data, and not just rely on the cloud as the fallback strategy.

Section: Standard
Word Count: 916
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/Here-s-What-1-Expert-Says-is-Happening