Active incident

TruStage Security Updates

TruStage says it detected unusual network activity on July 11, shut its systems down, and is running a phased, prioritized restoration — rebuilding parts of its infrastructure rather than simply switching systems back on, out of a clean, isolated environment it says outside experts validated. Its public outage pages describe the event as a cybersecurity attack identified on July 11 and carry the company's target of having the majority of its key processes operational by mid-August; on August 5 those pages were rewritten again and no longer say in their lead that the attack has been contained, though TruStage's July 31 press release still does — a target that until now appeared only in its press release, CEO video, and partner materials. TruStage cautions that services returning by then may still run on temporary workarounds rather than at full functionality. It has stated a likely cause, an employee inadvertently downloading a malicious file, and says its cybersecurity partner Mandiant and its internal teams are still working to determine whether any data was accessed. It gives no product-specific claim payment timelines, and says some servicing and claims activities remain limited.

Last updated Aug 9, 2026 · Tracking since July 14, 2026 · 37 updates logged
Affected TruStage services
GAP claimsDisrupted
Mechanical repair coverage — contracts & claimsDisrupted
Payment protection claimsDisrupted
Online account access & transactionsDisrupted
Retirement plan servicing (BenefitsForYou)Disrupted
Retirement payroll files — other submissionsDisrupted
GAP waiver issuance (PAX workaround)Delays
Mechanical repair coverage — quoting (Assurant GLOW)Delays
Annuity withdrawals & surrenders (forms)Delays
Life & AD&D policy servicing (mail-in forms)Delays
Available (7): Credit insurance & debt protection · Auto & home — quotes, purchase, servicing & claims (Liberty Mutual, Polly) · Bond & business protection renewals · Retirement payroll files — 360 via aggregator (PayKonnect, Payroll Integrations) · Retirement scheduled installments & annuity distributions · Compliance Solutions service desk · Compliance Solutions cloud products

Statuses reflect TruStage’s most recent public updates.

For member credit unions

What your credit union can do now

01

Work from TruStage's credit-union page

trustage.com/outage/business/credit-union now carries TruStage's own interim GAP and mechanical-repair processes, claims handling, and what you can still sell. Check it before relying on secondhand summaries.

02

Use TruStage's member communication materials

TruStage has published an optional member letter template and a talking points and FAQ sheet for staff, both dated July 31, that credit unions may adapt and share. Run them through your own review and approval process first.

03

Expect claim delays — keep a log

Claims filed through TruStage may still be delayed. Keep collecting claim details and supporting documentation, and record member inquiries so each one can be followed up as systems return.

04

Point members to official sources

Send member questions to trustage.com/outage/individual, the claims-start page at connect.trustage.com/startclaim, and the outage line at 844-958-8910 — not to secondhand reports. Members with individual life or AD&D coverage who need a policy change can now use TruStage's mail-in service forms at trustage.com/outage/individual/service-forms.

05

Reassure members

This is a disruption at TruStage, not at your credit union. Deposits, cards, ATMs, and online banking are unaffected, and TruStage says annuity and retirement balances are unaffected as well.

06

Watch for phishing

Scams may reference the outage. TruStage says it is not currently sending premium-payment requests or past-due notices, and it will not ask members for passwords or account credentials by email or text.

Background

What this means for your credit union

TruStage — formerly CUNA Mutual Group — provides insurance and financial-services products that many credit unions offer their members. On its own outage pages the company says it identified unusual network activity on July 11, 2026 and shut its systems down to investigate, disclosing the incident publicly on July 15. It has since begun a phased restoration, and says the likely cause was an employee inadvertently downloading a malicious file while trying to install a legitimate tool.

The incident is at TruStage — not at your credit union

A disruption to TruStage products does not affect your credit union's own deposits, cards, ATMs, or online banking. For most credit unions the immediate effect is a service disruption, not a confirmed data breach.

Restoration has started, but it is phased

TruStage says systems are coming back in a controlled, prioritized sequence over days and weeks, that not all of them return at once, and that some functions are running on tested workarounds in the meantime. It says publicly that it anticipates the majority of its key processes will be operational by mid-August — which it defines as priority processes being available, not every system at full functionality.

Scope and impact are still open

TruStage has not said whether any member or credit union information was accessed, or whether ransomware was involved — it says its cybersecurity partner Mandiant and its internal teams are still working that out. Treat anything beyond TruStage's own statements as unconfirmed.

Brief your front-line staff

If your credit union relies on TruStage products, make sure staff know which services are affected, what interim processes exist, and where to direct member questions. We will keep this page current as TruStage and reputable outlets report.

Rumor control

What is known — and what is not

Confirmed by TruStage

  • TruStage says it identified unusual activity on its network on July 11, 2026 and immediately shut its systems down to investigate; its first public statement came July 15.
  • TruStage says the likely cause was a member of its workforce inadvertently downloading a malicious file while trying to install a legitimate tool. The investigation is still open.
  • Outside cybersecurity experts are engaged for containment, remediation, and recovery; TruStage says it notified law enforcement and continues to notify regulatory authorities as appropriate.
  • Restoration has begun and is running in a phased, prioritized sequence over days and weeks, with tested workarounds covering some functions. TruStage says it anticipates the majority of its key processes will be operational by mid-August, prioritizing the operations most critical to partners and their members.
  • TruStage says most credit-insurance and debt-protection products are running again, auto and home new business is processing through Liberty Mutual and Polly, bond and business-protection renewals are supported, and a GAP waiver workaround is being rolled out to credit unions.
  • Interim processes are published for credit unions: eligible PAX credit unions may use the approved GAP workaround, and a limited group may quote mechanical repair coverage through Assurant's GLOW platform — quoting only, with contracts and certificates issuing after PAX is restored and the sale entered.
  • GAP, mechanical repair, and payment protection claims remain disrupted; credit unions are told to keep collecting claim details and documentation.
  • TruStage says annuity contract values, balances, and benefits are unaffected, and that it has found no evidence of unauthorized transactions on contract-owner funds, the assets backing its annuity obligations, or other company financial accounts.
  • TruStage says individual coverage will not lapse during the outage: a policy that is active or in a grace period stays in that status until payment processing resumes. As of July 30 it also says it will extend applicable grace periods once processing resumes, and that more than one premium payment may then come due depending on the policy's normal payment schedule.
  • TruStage states it is not currently sending communications requesting premium payments or telling customers a policy payment is delinquent, and tells anyone who receives one not to click links, share personal information, or submit payment information.
  • Retirement plan balances and benefits are unaffected and BenefitsForYou remains offline, but as of July 30 TruStage says payroll files submitted for 360 processing through third-party aggregators (it names PayKonnect and Payroll Integrations) are being processed, other payroll submissions are not, and previously scheduled installment and annuity distributions are being processed. Sponsors are told to continue normal payroll operations and to document any outage-related delay.
  • The NCUA is aware of the event. A credit union that determines the incident is reportable may report by calling 1-833-CYBERCU (1-833-292-3728) or emailing cybercu@ncua.gov, naming the credit union and referencing the TruStage cybersecurity event.
  • TruStage has launched an outage resource hub with audience-specific pages, a consumer FAQ, an online claims-intake page, and an outage support line (844-958-8910), alongside the general line 1-833-374-1541.
  • TruStage Compliance Solutions restored Service Desk access on July 14 and says its cloud products are unaffected.
  • As of July 31 TruStage says it cannot give product-specific claim payment timelines. Claims will be evaluated and paid under the applicable policy terms as operational capabilities are restored, and while representatives can take inquiries, some servicing and claims activities remain limited.
  • In materials for credit union partners dated July 31, TruStage says it is working toward being operational by mid-August. It defines that as priority processes and services being available through a mix of restored systems, interim processes, and alternative support paths — not every system immediately at full functionality, with temporary workarounds possibly remaining in place. TruStage has since stated the same target publicly — in a July 31 newsroom press release, in a new CEO video on its credit union outage page, and, as of August 4, in a new question and answer on its ordinary public outage pages. That same question and answer was added to its credit union page on August 5.
  • TruStage says it stood up a clean, isolated technology environment segmented from systems that were impacted, potentially impacted, or still under investigation, that outside cybersecurity experts validated it using secure recovery practices, and that restored services pass established validation before entering production workflows.
  • TruStage says it will work directly with credit unions and other partners if it determines data was compromised, and would notify affected credit unions before communicating with their members.
  • TruStage has published materials credit unions may adapt for member communication: an optional member and customer letter template and a talking points and FAQ sheet for staff, both dated July 31, 2026.
  • TruStage says the incident has been contained. Because the event was broad, it says it rebuilt parts of its infrastructure so systems could be brought back safely rather than simply switched back on, and that as it rebuilds it is confirming no malicious code or bad actor remains in its systems or network.
  • TruStage names Mandiant as the outside cybersecurity partner working with its internal teams on the data investigation. It says it does not yet know whether member data was accessed, and that if members' personal information is involved it will notify affected partners first and support them through any notification or reporting process.
  • TruStage says it refreshed employee laptops and updated security measures before staff re-engage with systems, and that this work is close to completion.
  • TruStage says it will send partners email updates multiple times a week while restoration continues.
  • TruStage's public outage pages and consumer FAQ describe the event as a cybersecurity attack identified on July 11, rather than as a cybersecurity incident. On August 5 the opening paragraph was rewritten again: it now stresses the breadth of the impact across the company's network and systems and the rebuilding of portions of its infrastructure, and the sentence saying the attack had been contained after detection was dropped from that lead and removed from the outage hub. TruStage has not withdrawn the containment statement, which still stands in its July 31 press release; it no longer appears in the outage-page lead copy.
  • As of August 4, annuity contract owners can submit application cancellation, right to examine, partial withdrawal, and surrender requests through electronically signed forms on TruStage's annuity outage page, handled through its partner AssureSign, with downloadable transfer and allocation-change forms also posted. Online account access remains unavailable and processing still depends on restoration.
  • TruStage says that on July 29 it began a temporary business continuity process for credit unions whose members were already approved for recurring Debt Protection benefit payments. It says those payments are being issued as a single lump sum generally reflecting the prior month's recurring payments, adjusted where a benefit has ended, and that because the lump sum carries no member-level ledger its claims team will contact participating credit unions directly with the payment detail. TruStage says it is starting the process proactively for credit unions that received six or more recurring member benefit payments in the previous month, and that credit unions below that threshold may ask the claims team to review an individual member.

Not yet known

  • Whether any member, customer, or credit union data was accessed — TruStage calls conclusions premature.
  • Whether ransomware was involved, and whether anyone has claimed responsibility.
  • How the attacker got in beyond the stated likely cause, when access began, and how long it lasted.
  • Firm dates for individual systems and products. TruStage's mid-August target covers its priority processes overall; it still gives no product-specific claim payment timelines and says platforms with more dependencies may take longer.
  • Whether the July 12 Compliance Solutions service-desk outage is connected to the broader incident.

No public evidence

  • No public evidence that credit unions' own systems, member deposits, cards, or online banking are affected.
  • No public evidence of misuse of member or credit union information.
  • No breach-notification filing for TruStage has appeared in any state attorney general database we have been able to enumerate, and no incident filing has appeared with the SEC.
Incident log

Timeline of updates

37 updates · newest first
Aug 7, 2026
Official · TruStageService Impact

TruStage says auto and home coverage is running normally through Liberty Mutual and Polly

TruStage has added a product question to its credit-union outage page confirming that auto and home insurance is operating through its partnership with Liberty Mutual and Polly. The company says members can still get quotes, buy coverage, have their existing policies serviced, and reach claims support, and that none of that is interrupted by the cybersecurity attack. It adds one caveat: while the servicing experience “remains largely unchanged,” in TruStage's words, the online experience a member sees may look different for the time being, and the company is still refining it as systems come back. This is broader than what TruStage had previously put on the record. Its chief executive said in the July 23 video that Liberty Mutual and Polly were processing new business from direct-mail leads; the company is now describing the full policy lifecycle, servicing and claims included, as running without disruption. For credit unions this is one of the few product lines that can be discussed as working normally, which is worth knowing for staff fielding member questions. The credit-union page carries no date stamp, so the date recorded here is the date this tracker could verify the answer was publicly visible.

TruStage (credit union outage page)
Aug 7, 2026
Official · TruStageMember Guidance

TruStage tells policyholders it is not behind offers to replace their insurance coverage

A new question has appeared on TruStage's individual outage page addressing policyholders who have been approached about replacing their insurance policy with another company's. TruStage answers plainly that such an offer does not come from the company, and states that it is not encouraging, facilitating, or taking part in any effort to replace, surrender, or discontinue coverage that is currently in force, either because of the cybersecurity incident or as part of its recovery work. The answer is worth passing along to members: an insurer's systems being offline is exactly the circumstance in which policyholders may be told their coverage is at risk and pressed to switch, and TruStage is now on record that it is not the source of those approaches. Credit unions fielding questions from members who have received such offers can point to this statement. TruStage did not advance the page's timestamp when the question appeared, which still reads August 6, so the company has not itself given a publication date; the date recorded here is the date this tracker could verify the answer was publicly visible.

TruStage (individual outage page)
Aug 7, 2026
Official · TruStageService Impact

Wealth Management page says advisors and credit unions can reach Salesforce by direct login

TruStage has rewritten its Wealth Management Solutions outage page and answered a question it had been deferring since the outage began. Where the page previously said only that teams were working to bring systems back online, it now tells advisors and credit unions that they can get into Salesforce through a direct login, and points them to their assigned Advisor Manager Specialist or Regional Program Consultant for instructions. One caution worth passing to program staff: the page's own "What you should know" paragraph still says advisors cannot access Salesforce for client-specific notes, so the old and new statements now sit side by side on the same page without being reconciled. Treat the direct-login route as the newer of the two and confirm the scope with your TruStage contact rather than assuming full access. The page also adds a compensation answer for the second half of July, saying managed and dual advisors were paid on the regular schedule and credit unions received the same amount paid for the first half of July, which was based on the average of the six pay periods earned before July. Finally, the page has taken the mid-August recovery answer and the standard recovery lead that the other outage pages adopted on August 5, making it the last outage sub-page to catch up.

TruStage (Wealth Management Solutions outage page)
Aug 6, 2026
Official · TruStageService Impact

TruStage adds direct deposit and income benefit forms to its annuity outage page

TruStage has extended the self-service annuity forms it introduced on August 4 with two further routes for contract owners. Owners can now submit a direct deposit form through the company's e-signature partner AssureSign to change where their deposits are sent, in separate single-owner and joint-owner versions, and a downloadable income benefit service form has been added for Zone Income Annuity and ZoneChoice Income Annuity contracts. The general resources block was also reorganized, with the transfer and allocation-change forms consolidated under a single heading and the claims link moved alongside them. In the same edit, the advisor resources block that pointed producers to their wholesaler was removed from the page. As with the forms added on August 4, these are workarounds rather than restored processing: online account access remains down, and TruStage has not said that requests submitted this way will be handled any faster than its recovery timetable allows.

TruStage (annuity outage page)
Aug 6, 2026
Official · TruStageService Impact

TruStage rewrites its Retirement Solutions outage page, promising interim processes and dating the delayed benefit statements

TruStage's Retirement Solutions outage page was substantially rewritten under an August 6 timestamp, and the changes go beyond the recovery wording applied across the other outage pages. The company now says it will introduce temporary processes while recovery continues and that it is contacting plan sponsors as solutions become available for their plans. On payroll, the page previously stated flatly that files outside the third-party aggregator route could not be processed; it now says TruStage is working on an interim solution for those submissions and will share news with plan sponsors. On statements, the page has moved from an open-ended delay to specific commitments: quarterly paper statements for the period ended June 30, 2026 have been mailed, and participants who had elected electronic statements will instead be sent a paper statement, which TruStage says is in process and expected to be mailed the week of August 10, 2026. The company warns that some participants who had signed up for paper statements may receive a duplicate copy. Two items also came off the list of unavailable services: the sentence stating that the Participant Service Center phone and email system was unavailable no longer appears, and loan and distribution requests are no longer listed among the requests TruStage cannot accept. TruStage did not describe either removal as a restoration, and this tracker does not treat it as one.

TruStage (Retirement Solutions outage page)
Aug 6, 2026
Official · TruStageMember Guidance

TruStage opens a mail-in service-forms page for individual life and AD&D policies

TruStage has added a new page to its outage site giving individual life insurance and accidental death and dismemberment policyholders a way to submit servicing requests while its systems are down. The page carries downloadable PDF forms covering changes of ownership, beneficiary changes, and general service requests such as billing-frequency changes, withdrawals, loans, and cancellation or surrender, with separate versions depending on whether the policy is issued by CMFG Life Insurance Company or MEMBERS Life Insurance Company and which digits the policy number begins with. Ownership changes must be accompanied by a completed W-9. TruStage instructs policyholders to print the form, complete and sign it, and mail it to the address printed on the form, and states that fax is not available at this time. The company says these requests will be processed as its systems are restored and that they will be honored dating back to the date the request was received. This is the first servicing route TruStage has published for individual life and AD&D coverage during the outage, and it parallels the annuity forms route added on August 4, though it is mail-based rather than electronically signed. TruStage did not advance the individual outage page's timestamp when the forms appeared, so the company has not itself stated a publication date; the page still reads August 5, 2026 | 4:48 PM CT.

TruStage (individual outage page — service forms)
Aug 5, 2026
Official · TruStageMember Guidance

TruStage publishes a lump-sum continuity process for recurring Debt Protection benefit payments

TruStage's credit union outage page now carries two new answers describing how recurring Debt Protection benefit payments are being handled while its systems are down. The company says it began a temporary business continuity process on July 29 for credit unions whose members had already been approved for recurring benefit payments. Rather than issuing those payments individually, TruStage says it will pay a single lump sum that generally mirrors what the member received the previous month, adjusted where a benefit has since ended. Because the lump sum arrives without a member-level ledger, TruStage says a member of its claims team will contact each participating credit union directly with the payment detail needed to get the money to the right members. The company says it is starting the process proactively for credit unions that received six or more recurring member benefit payments in the previous month, and that credit unions below that threshold may ask the claims team to review a member they believe should have been paid. This is the first time the arrangement has appeared on TruStage's own public page; trade-press reporting in early August had described it only as a test running with a small number of credit unions.

TruStage (credit union outage page)
Aug 5, 2026
Official · TruStageOfficial Statement

TruStage rewrites its outage-page lead again and brings the credit union page into line

TruStage revised the opening paragraph across its outage pages and consumer FAQ, re-stamping the dated pages August 5 at 4:48 p.m. central. The new lead drops the sentence saying the incident had been contained since detection, and instead stresses the breadth of the impact across the company's network and systems, saying it is rebuilding portions of its infrastructure so services are restored safely and describing this as a deliberate approach that protects the people it serves as systems come back online. On the outage hub, the paragraph that had said the incident was contained and that TruStage was confirming no malicious code or bad actor remained was removed altogether. The containment statement itself has not been withdrawn: it still stands in the company's July 31 press release, which is unchanged. It simply no longer appears in the lead copy on the outage pages. Separately, the credit union page joined the rewrite it had sat out for two days. It now calls the event an attack rather than an incident, replaces its older passage about having shut all systems down with the same recovery language used elsewhere, adds the mid-August resolution answer already posted on the other pages, and sharpens its claims guidance to tell credit unions to file new claims through TruStage's online intake page. That page is still undated, and the status field across the site still reads Investigating.

TruStage (outage pages and consumer FAQ)

How this page is maintained

This tracker is compiled by monitoring TruStage’s official newsroom alongside reputable credit‑union trade press, regional news, and peer associations. Official TruStage statements are logged as issued; third‑party reports are reviewed for credibility before they are added. Summaries are written in our own words — follow each source link for the full report.

Official source

TruStage newsroom update

About this page. This page compiles publicly reported information about the TruStage cybersecurity incident for the situational awareness of our member credit unions. It is not an official TruStage communication, and it is not legal, security, or compliance advice. Details are evolving and some early reports may prove incomplete or inaccurate; always rely on TruStage directly for official guidance.

Print Friendly, PDF & Email