TruStage Identifies Likely Cause Of Cyberattack, Begins System Recovery

MADISON, Wis.— TruStage said it has begun restoring systems and services following the cyber incident it disclosed earlier this month, while revealing for the first time that investigators believe the attack began after an employee inadvertently downloaded a malicious file while attempting to install a legitimate software tool.

Screenshot 2026-07-21 182146

Terrance Williams

The update came in a video message from President and CEO Terrance Williams, who said the company continues working with external cybersecurity experts, law enforcement and regulators as the investigation and recovery effort continues. As previously reported by CU Today, TruStage detected unusual activity on its network on July 11 and immediately shut down systems to contain the incident.

"Based upon the current investigative status, we believe that a member of our workforce may have inadvertently downloaded a malicious file while trying to install a legitimate tool," Williams said. "Both the investigation and the recovery work are ongoing."

Williams said TruStage has now entered the next phase of recovery and is restoring systems "in a controlled, prioritized way" over the coming days and weeks. "We will be methodical. Not all systems will be available at the same time," he said, adding that the company "will not sacrifice quality, security, or reliability for speed."

The company said most credit insurance and debt protection products are now operational, while temporary manual workarounds are supporting some claims processes. Williams said TruStage has also implemented workarounds for credit union partners issuing GAP waivers, is continuing to support bond and business protection coverage renewals, and noted that its cloud-based Compliance Solutions products were not affected. He added that TruStage has established a streamlined reporting process with the NCUA for credit unions that determine the incident is reportable.

Williams cautioned that it remains too early to determine whether any data was accessed during the attack.

"At this stage, it's premature to draw conclusions about whether any data may have been accessed," he said. "We are absolutely committed to sharing what we can, when we can," while noting the company cannot disclose certain details because of the ongoing investigation and potential legal, regulatory and security considerations.

Section: Standard
Word Count: 466
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/TruStage-Identifies-Likely-Cause-Of-Cyberattack-Begins-System-Recovery