Which CUs Are Most at Risk, & What to Do Now

MADISON, Wis.—The massive Equifax data breach that may have compromised sensitive financial and personal information for as many as 143 million Americans should have credit unions paying close attention to online membership and account openings—for many years.

Feature Equifax

In response, one expert has outlined a half-dozen steps CUs should be taking now to mitigate the risk.

Ken Otsuka, senior risk management consultant with CUNA Mutual Group, said he is concerned that crooks will use the massive amounts of stolen data to create false identities and then go online to steal from banks and credit unions.

“In my humble opinion, I think crooks will use this data to target credit unions that offer online membership and online account opening,” Otsuka said. “Fraudsters can open fake accounts at the branch, but we know they prefer to avoid the personal interaction.”

And the biggest targets, said Otsuka, will be those credit unions that offer membership through joining a non-profit agency or another organization.

“If a credit union has a non-profit organization in its field of membership, that is a very easy way for criminals to qualify,” said Otsuka. “We have seen that multiple times in the past in cases in which crooks have opened fake accounts.”

Once those bogus accounts are opened bogus loan applications will follow using information extracted from the Equifax hack, said Otsuka.

“They can use a fraudulent method of funding the fake account to steal money, or they can go for the big-ticket and apply for loans online and get approved, especially with auto decisioning. These types of losses tend to be the most severe.”

A Particular Danger

What makes this hack so dangerous to credit unions and their members, said Otsuka, is the completeness of the data stolen.

“In this breach, 143 million records were compromised, records that contain names, addresses, phone numbers, birth dates . . . everything fraudsters need to open up fake accounts at financial institutions,” he said.

Otsuka stressed the risk is going to last much longer than the time it typically takes to reissue plastic cards, as has been the case in other breaches at retailers.

Otsuka

Ken Otsuka

“History tells us that data of this type can be used many years down the line, so credit unions really have to keep their guards up,” said Otsuka. “This is not a short-lived exposure. We have seen, from the Anthem breach, fraudulent accounts opened three years later. Fraudsters can use this stolen data for years to come. I would not be surprised if it is not already up for sale on dark web.”

Risk Mitigation Steps

Risk mitigation steps are critical for those CUs that offer online account and membership opening, said Otsuka, outlining steps to take:

  • Disable automatic approvals over weekends. These applications should require manual review
  • Require a manual review of applications for individuals qualifying for membership by joining a nonprofit organization or who live outside of the credit union’s normal trade area
  • Scrutinize IP addresses, including: geolocation tracking of IP addresses to ensure they are consistent with the individual’s address
  • Be alert for multiple applications received from the same IP address
  • Block IP addresses if fraud is suspected. Note that fraudsters may quickly switch to different IP addresses after the block is in place
  • Ensure the monetary limits are reasonable if members can fund the account online (e.g., by ACH or payment card)

Otsuka said that credit unions should also notify members of the Equifax breach and instruct them to visit the dedicated Equifax website to determine if their information was accessed.

“Inform impacted members of their options for protecting themselves by placing a fraud alert on their credit file, placing a freeze on their credit reports, and monitoring their deposit and credit accounts for suspicious or fraudulent activity,” recommended Otsuka. “In addition, remind members of the importance of annually requesting and reviewing their credit report from the three major consumer reporting agencies.”

CUNA Mutual Cybersecurity Webinar

CUNA Mutual Group is conducting a free Cybersecurity Trends and Tips webinar for existing policyholders, Wednesday, Sept. 20 at 10 C.T.CUNA Mutual Group's Risk And Compliance Consultant Carlos Molina and guest speaker Vinny Sakore, chief technology officer from NetDiligence, will discuss the latest cybersecurity trends and provide actionable tips to help CUs assess cyber threats and protect sensitive data. 

Topics covered include:

  • IOT device management
  • Ransomware
  • Third-party access control
  • Cloud storage
  • Mobile device management

To register, go click here.

Section: Standard
Word Count: 962
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/Which-CUs-Are-Most-at-Risk-What-to-Do-Now