Active incident

TruStage Security Updates

TruStage detected a cybersecurity incident and proactively took its network offline. The cause, whether any data was accessed, and a restoration timeline have not been disclosed.

Last updated Jul 20, 2026 · Tracking since July 14, 2026 · 11 updates logged
Affected TruStage services
Guaranteed Asset Protection (GAP) claimsDisrupted
Mechanical repair coverage claimsDisrupted
Payment protection claimsDisrupted
Online account access & transactionsDisrupted
401(k) accessDelays
Compliance Solutions service deskAvailable
Compliance Solutions cloud productsAvailable

Statuses reflect TruStage’s most recent public updates.

For member credit unions

What your credit union can do now

01

Point members to official sources

Direct questions to TruStage's consumer FAQ, the claims-start page at connect.trustage.com/startclaim, and the support line at 1-833-374-1541 — not to secondhand reports.

02

Expect claim delays — keep a log

Claims filed through TruStage may be delayed. Record member inquiries now so each one can be followed up once service is restored.

03

Reassure members

This is a disruption at TruStage, not at your credit union. Deposits, cards, ATMs, and online banking are unaffected.

04

Watch for phishing

Scams may reference the outage. TruStage will not ask members for passwords or account credentials by email or text.

Background

What this means for your credit union

TruStage — formerly CUNA Mutual Group — provides insurance and financial-services products that many credit unions offer their members. On or about July 14, 2026, it identified a cybersecurity incident and shut down parts of its network to contain it: a standard precaution, but one that has temporarily taken several services offline.

The incident is at TruStage — not at your credit union

A disruption to TruStage products does not affect your credit union's own deposits, cards, ATMs, or online banking. For most credit unions the immediate effect is a service disruption, not a confirmed data breach.

Scope and impact are unverified

TruStage has not said whether any member or credit union information was accessed, or whether ransomware was involved — it calls conclusions about scope premature. Treat anything beyond TruStage's own statements as unconfirmed.

Brief your front-line staff

If your credit union relies on TruStage products, make sure staff know which services are affected and where to direct member questions. We will keep this page current as TruStage and reputable outlets report.

Rumor control

What is known — and what is not

Confirmed by TruStage

  • TruStage detected a cybersecurity incident and proactively took its network offline on or about July 14.
  • Outside cybersecurity experts are engaged for containment, remediation, and recovery.
  • GAP, mechanical repair, and payment protection claims are disrupted; online account access is affected; 401(k) access is delayed.
  • TruStage has launched a consumer FAQ, an online claims-intake page, and a support line (1-833-374-1541).
  • TruStage Compliance Solutions restored Service Desk access on July 14 and says its cloud products are unaffected.

Not yet known

  • The cause of the incident, including whether ransomware was involved.
  • Whether any member, customer, or credit union data was accessed.
  • A timeline for restoring affected systems.
  • Whether the July 12 Compliance Solutions service-desk outage is connected to the broader incident.

No public evidence

  • No public evidence that credit unions' own systems, member deposits, cards, or online banking are affected.
  • No public evidence of misuse of member or credit union information.
Incident log

Timeline of updates

11 updates · newest first
Jul 19, 2026
Official · TruStageOfficial StatementNew

Consumer FAQ status stamp advances; restoration still under way

TruStage refreshed the status line on its consumer FAQ to July 19, 2026, 11:15 a.m. CT. The substance did not change: systems remain shut down while the company works to restore them, customers may still have trouble reaching accounts or completing transactions online, and TruStage says it is premature to draw conclusions about the scope or impact of the incident. No restoration date and no data-exposure finding were given.

TruStage Consumer FAQ
Jul 16, 2026
Official · TruStageOfficial Statement

TruStage provides update on cybersecurity incident

In an update posted to its newsroom, TruStage said it had activated its incident response and recovery protocols and engaged outside cybersecurity experts. With its systems still down, the company directed customers to newly launched resources: a consumer FAQ, an online page to start a claim, and a support line at 1-833-374-1541.

TruStage Newsroom
Jul 16, 2026
Official · TruStageService Impact

Consumer FAQ: systems proactively shut down, restoration underway

TruStage's consumer FAQ (marked last updated July 16) describes the situation as under investigation, with systems proactively shut down while restoration efforts continue. It warns that customers may have difficulty accessing account information, completing transactions, or submitting requests online, and specifically addresses delayed 401(k) access and how to file claims. TruStage said it would be 'premature to draw conclusions about the scope or impact' of the incident, including whether any data was accessed.

TruStage Consumer FAQ
Jul 16, 2026
Official · TruStageMember Guidance

Online claims page opened for filing during the disruption

TruStage opened an online form for consumers to begin a claim while systems are down, covering protected-loan, death-or-dismemberment, and business-protection claim types, and says it will follow up as soon as possible. Rather than collecting sensitive details, the form asks members to choose a relationship and a preferred contact time, and cautions users not to include policy, contract, account, or Social Security numbers.

TruStage Claims Intake
Jul 15, 2026
Official · TruStageService ImpactNew

Compliance Solutions says its cloud products are unaffected

TruStage Compliance Solutions posted a notice on its community portal saying it was aware of the cybersecurity issue TruStage had announced, and that its own cloud products were not affected. Clients were told they could keep using those applications as usual, and the notice repeated that the outage did not originate in Compliance Solutions technology. The notice did not address the cause or scope of the wider TruStage incident.

TruStage Compliance Solutions
Jul 15, 2026
Official · TruStageOfficial Statement

TruStage discloses incident and activates response protocols

TruStage disclosed that it had detected a cybersecurity incident affecting its environment and immediately activated its incident-response and recovery procedures. The company said it engaged outside cybersecurity experts to assist with containment, remediation, and recovery, and that the work remained ongoing. It said it was still establishing the facts and did not indicate whether any data had been accessed or name specific affected systems.

TruStage Newsroom
Jul 15, 2026
Security pressMedia Report

TruStage cyber incident disrupts credit union partner claims

DysruptionHub, an outlet that tracks cybersecurity incidents and service disruptions, reported that TruStage shut down its network after identifying a cybersecurity incident affecting its technology environment and immediately began response and recovery efforts. It noted the outage affected some services offered through credit union partners — specifically GAP insurance, mechanical repair coverage, and payment protection claims — while a partner credit union reported no disruption to deposits, cards, ATMs, or online banking. The report stressed that TruStage had not disclosed how it was compromised, whether any information was accessed, or a restoration timeline, and had not confirmed ransomware, data theft, a ransom demand, or a threat actor.

DysruptionHub
Jul 15, 2026
Trade pressMedia Report

TruStage shuts down portions of network in response to threat

Credit Union Daily reported that TruStage had voluntarily shut down portions of its network after detecting suspicious activity, triggering its incident-response protocols alongside third-party specialists. The outlet emphasized that TruStage had not indicated whether ransomware was involved or whether any customer or employee information had been accessed.

Credit Union Daily
Jul 15, 2026
Trade pressService Impact

Outage confined to TruStage products, not credit unions' core services

Coverager highlighted the downstream effect on a partner institution: First Commonwealth Federal Credit Union told members that TruStage was temporarily unavailable for GAP, mechanical repair coverage, and payment protection claims. The report noted the disruption was confined to TruStage products offered through the credit union and did not affect the credit union's own deposits, cards, ATMs, or online banking.

Coverager
Jul 14, 2026
Official · TruStageRestorationNew

Compliance Solutions service desk access restored

TruStage Compliance Solutions reported that Service Desk access was fully restored as of 3:20 p.m. ET on July 14, two days after the outage that began the morning of July 12. The team said it could again view and process the support tickets submitted while access was unavailable, and that those tickets would be worked in the order received. The notice did not say what caused the outage or whether it was related to the broader TruStage incident disclosed the following day.

TruStage Compliance Solutions
Jul 12, 2026
Official · TruStageService Impact

Compliance Solutions service desk went offline two days before disclosed incident

A notice on TruStage Compliance Solutions' community portal reported that as of 8:30 AM ET on July 12 a systems outage was preventing its team from accessing the Service Desk, delaying responses to support tickets. The notice said the outage was not related to Compliance Solutions technology and directed clients and partners to email support addresses instead. TruStage has not publicly said whether this outage is connected to the broader incident it disclosed on July 15.

TruStage Compliance Solutions

How this page is maintained

This tracker is compiled by monitoring TruStage’s official newsroom alongside reputable credit‑union trade press, regional news, and peer associations. Official TruStage statements are logged as issued; third‑party reports are reviewed for credibility before they are added. Summaries are written in our own words — follow each source link for the full report.

Official source

TruStage newsroom update

About this page. This page compiles publicly reported information about the TruStage cybersecurity incident for the situational awareness of our member credit unions. It is not an official TruStage communication, and it is not legal, security, or compliance advice. Details are evolving and some early reports may prove incomplete or inaccurate; always rely on TruStage directly for official guidance.

Print Friendly, PDF & Email