MADISON, Wis.— TruStage said the cyberattack that has disrupted its operations for more than a month has been contained and that investigators have found no evidence of continuing intrusion, but the company cautioned credit union partners it could be another two to three months before it knows whether member or employee data was compromised.
In an Aug. 12 update to partners, TruStage said Mandiant, the cybersecurity firm assisting with the investigation and recovery, has confirmed the company has established a “clean, isolated environment” separate from systems that were affected, potentially affected or remain under investigation.
An Aug. 10 Mandiant memo said TruStage’s operating environment is clean, the incident is contained and investigators have found no indication of an active intrusion or threat-actor activity since July 11, when TruStage first detected the incident and moved to contain it. Mandiant also said it has not observed the threat actor interacting with files shared with third parties or with third-party systems, portals, VPNs or APIs connected to TruStage.
The update provides considerably more clarity around the forensic investigation, although a key question remains unresolved: whether data was accessed or compromised. TruStage said it is working with Mandiant and data-analysis firm Epiq Global on that review and expects it will likely take another two to three months to determine whether credit union member or employee information was affected. TruStage told partners that if such data is determined to have been impacted, affected credit unions will be told first and the company will work to assist with any required notifications and regulatory reporting.
As previously reported by CUToday.info, TruStage President and CEO Terrance Williams said investigators believe the incident began when a member of TruStage’s workforce inadvertently downloaded a malicious file while attempting to install a legitimate software tool. Williams said at the time that TruStage had begun a phased restoration of its systems while the investigation continued. TruStage first detected unusual activity July 11 and shut down systems as part of its response.
TruStage said Wednesday it remains on track toward its previously announced goal of having most key processes operational by mid-August. The company expects basic servicing to be operating for the majority of its businesses, including reopening customer contact centers. Its retirement call center is already open, while life and annuity call centers are scheduled to reopen Friday, Aug. 14. TruStage cautioned that customers could initially encounter higher call volumes, longer handling times and limits on the services representatives can provide.
The company also said it has begun paying claims across several businesses, including preplanning/funeral claims, GAP claims and debt protection/credit insurance benefits. For life and AD&D claims, TruStage said it is restoring core processing capabilities and will first address claims that were pending when the outage began before moving to those received afterward. In its wealth business, TruStage reiterated that annuity and retirement-plan assets were not affected by the attack and said most defined-contribution participants, except those on certain legacy platforms, can now request withdrawals and loans where permitted and obtain account-balance updates by phone. Billing also has resumed for a large segment of consumers.
The incident has also generated litigation. Proposed class-action lawsuits filed in the wake of the attack now total 14, including actions brought on behalf of credit unions and consumers alleging TruStage failed to adequately safeguard information and systems. The allegations remain unproven, and TruStage’s investigation has not yet determined whether member or employee data was compromised. The company said restoration work continues daily, with systems and processes being returned in phases only after they have been tested and validated.
