What your credit union can do now
Work from TruStage's credit-union page
trustage.com/outage/business/credit-union now carries TruStage's own interim GAP and mechanical-repair processes, claims handling, and what you can still sell. Check it before relying on secondhand summaries.
Use TruStage's member communication materials
TruStage has published an optional member letter template and a talking points and FAQ sheet for staff, both dated July 31, that credit unions may adapt and share. Run them through your own review and approval process first.
Expect claim delays — keep a log
Claims filed through TruStage may still be delayed. Keep collecting claim details and supporting documentation, and record member inquiries so each one can be followed up as systems return.
Point members to official sources
Send member questions to trustage.com/outage/individual, the claims-start page at connect.trustage.com/startclaim, and the outage line at 844-958-8910 — not to secondhand reports. Members with individual life or AD&D coverage who need a policy change can now use TruStage's mail-in service forms at trustage.com/outage/individual/service-forms.
Reassure members
This is a disruption at TruStage, not at your credit union. Deposits, cards, ATMs, and online banking are unaffected, and TruStage says annuity and retirement balances are unaffected as well.
Watch for phishing
Scams may reference the outage. TruStage says it is not currently sending premium-payment requests or past-due notices, and it will not ask members for passwords or account credentials by email or text.
What this means for your credit union
TruStage — formerly CUNA Mutual Group — provides insurance and financial-services products that many credit unions offer their members. On its own outage pages the company says it identified unusual network activity on July 11, 2026 and shut its systems down to investigate, disclosing the incident publicly on July 15. It has since begun a phased restoration, and says the likely cause was an employee inadvertently downloading a malicious file while trying to install a legitimate tool.
The incident is at TruStage — not at your credit union
A disruption to TruStage products does not affect your credit union's own deposits, cards, ATMs, or online banking. For most credit unions the immediate effect is a service disruption, not a confirmed data breach.
Restoration has started, but it is phased
TruStage says systems are coming back in a controlled, prioritized sequence over days and weeks, that not all of them return at once, and that some functions are running on tested workarounds in the meantime. It says publicly that it anticipates the majority of its key processes will be operational by mid-August — which it defines as priority processes being available, not every system at full functionality.
Scope and impact are still open
TruStage has not said whether any member or credit union information was accessed, or whether ransomware was involved — it says its cybersecurity partner Mandiant and its internal teams are still working that out. Treat anything beyond TruStage's own statements as unconfirmed.
Brief your front-line staff
If your credit union relies on TruStage products, make sure staff know which services are affected, what interim processes exist, and where to direct member questions. We will keep this page current as TruStage and reputable outlets report.
What is known — and what is not
Confirmed by TruStage
- TruStage says it identified unusual activity on its network on July 11, 2026 and immediately shut its systems down to investigate; its first public statement came July 15.
- TruStage says the likely cause was a member of its workforce inadvertently downloading a malicious file while trying to install a legitimate tool. The investigation is still open.
- TruStage says the incident has been contained. Because the event was broad, it rebuilt parts of its infrastructure rather than simply switching systems back on, standing up a clean, isolated technology environment segmented from systems that were impacted, potentially impacted, or still under investigation. It says outside cybersecurity experts validated that environment using secure recovery practices, restored services pass established validation before entering production workflows, and as it rebuilds it is confirming no malicious code or bad actor remains in its systems or network.
- TruStage names Mandiant as the outside cybersecurity partner working with its internal teams on the data investigation, and says it notified law enforcement and continues to notify regulatory authorities as appropriate. It says it does not yet know whether member data was accessed; if it determines data was compromised it will work directly with credit unions and other partners, notifying affected credit unions first — before any communication with their members — and supporting them through any notification or reporting process.
- Restoration is running in a phased, prioritized sequence, and TruStage says it is working toward being operational by mid-August, prioritizing the operations most critical to partners and their members. It defines that as priority processes and services being available through a mix of restored systems, interim processes, and alternative support paths — not every system immediately at full functionality, with temporary workarounds possibly remaining in place. The target appears in partner materials dated July 31 and has since been stated publicly — in a July 31 newsroom press release, in a CEO video on the credit union outage page, and, as of August 4–5, on its public outage pages.
- Most credit-insurance and debt-protection products are running again; auto and home new business is processing through Liberty Mutual and Polly; bond and business-protection renewals are supported. Interim processes are published for credit unions: eligible PAX credit unions may use the approved GAP waiver workaround, and a limited group may quote mechanical repair coverage through Assurant's GLOW platform — quoting only, with contracts and certificates issuing after PAX is restored and the sale entered. GAP, mechanical repair, and payment protection claims remain disrupted; credit unions are told to keep collecting claim details and documentation.
- TruStage says annuity contract values, balances, and benefits are unaffected, and that it has found no evidence of unauthorized transactions on contract-owner funds, the assets backing its annuity obligations, or other company financial accounts.
- TruStage says individual coverage will not lapse during the outage: a policy that is active or in a grace period stays in that status until payment processing resumes. As of July 30 it also says it will extend applicable grace periods once processing resumes, and that more than one premium payment may then come due depending on the policy's normal payment schedule.
- TruStage states it is not currently sending communications requesting premium payments or telling customers a policy payment is delinquent, and tells anyone who receives one not to click links, share personal information, or submit payment information.
- Retirement plan balances and benefits are unaffected and BenefitsForYou remains offline, but as of July 30 TruStage says payroll files submitted for 360 processing through third-party aggregators (it names PayKonnect and Payroll Integrations) are being processed, other payroll submissions are not, and previously scheduled installment and annuity distributions are being processed. Sponsors are told to continue normal payroll operations and to document any outage-related delay.
- As of July 31 TruStage says it cannot give product-specific claim payment timelines. Claims will be evaluated and paid under the applicable policy terms as operational capabilities are restored, and while representatives can take inquiries, some servicing and claims activities remain limited.
- The NCUA is aware of the event. A credit union that determines the incident is reportable may report by calling 1-833-CYBERCU (1-833-292-3728) or emailing cybercu@ncua.gov, naming the credit union and referencing the TruStage cybersecurity event.
- TruStage has published materials credit unions may adapt for member communication: an optional member and customer letter template and a talking points and FAQ sheet for staff, both dated July 31, 2026.
- TruStage's public outage pages and consumer FAQ describe the event as a cybersecurity attack identified on July 11, rather than as a cybersecurity incident. On August 5 the opening paragraph was rewritten again: it now stresses the breadth of the impact across the company's network and systems and the rebuilding of portions of its infrastructure, and the sentence saying the attack had been contained after detection was dropped from that lead and removed from the outage hub. TruStage has not withdrawn the containment statement, which still stands in its July 31 press release; it no longer appears in the outage-page lead copy.
- As of August 4, annuity contract owners can submit application cancellation, right to examine, partial withdrawal, and surrender requests through electronically signed forms on TruStage's annuity outage page, handled through its partner AssureSign, with downloadable transfer and allocation-change forms also posted. Online account access remains unavailable and processing still depends on restoration.
- TruStage says that on July 29 it began a temporary business continuity process for credit unions whose members were already approved for recurring Debt Protection benefit payments. It says those payments are being issued as a single lump sum generally reflecting the prior month's recurring payments, adjusted where a benefit has ended, and that because the lump sum carries no member-level ledger its claims team will contact participating credit unions directly with the payment detail. TruStage says it is starting the process proactively for credit unions that received six or more recurring member benefit payments in the previous month, and that credit unions below that threshold may ask the claims team to review an individual member.
- As of August 11 TruStage says recurring ACH premium payments are beginning to resume for some eligible customers using payment details already on file. Recurring credit card payments and one-time payments are still unavailable, and representatives cannot verify an individual customer's payment activity or policy status while account access remains limited.
Not yet known
- Whether any member, customer, or credit union data was accessed — TruStage calls conclusions premature.
- Whether ransomware was involved, and whether anyone has claimed responsibility.
- How the attacker got in beyond the stated likely cause, when access began, and how long it lasted.
- Firm dates for individual systems and products. TruStage's mid-August target covers its priority processes overall; it still gives no product-specific claim payment timelines and says platforms with more dependencies may take longer.
- Whether the July 12 Compliance Solutions service-desk outage is connected to the broader incident.
No public evidence
- No public evidence that credit unions' own systems, member deposits, cards, or online banking are affected.
- No public evidence of misuse of member or credit union information.
- No breach-notification filing for TruStage has appeared in any state attorney general database we have been able to enumerate, and no incident filing has appeared with the SEC.
Timeline of updates
TruStage tells credit unions a temporary process to resume GAP claim payments began August 12
A temporary process to resume GAP claim payments began August 12 — but only for claims established before the attack. Claims filed since, through the interim intake form, are not part of the process yet.
More detail
TruStage rewrote the claims and payments answers on its credit-union outage page (snapshots place the change between 4:01 and 7:04 p.m. ET), and one part has not appeared on any TruStage page before: a temporary process to resume GAP claim payments began Wednesday, August 12, covering open and pending claims established before the attack, with two payment options to be available. The page does not say what the two options are — expect to be told separately.
The limit matters as much as the restart: claims submitted after the attack through the claim intake form are not part of this process at this time. A credit union that filed through the interim intake route since mid-July should not read this as covering those claims. Otherwise the page repeats its position — representatives can take inquiries, some servicing and claims activity remains limited, and no product-specific claim payment timelines are available.
The same rewrite finally carries TruStage's August 12 billing detail onto the partner-facing page, closing a gap flagged yesterday: the August 4 ACH restart for certain life and AD&D policies, the late-July and August due dates being worked through, recurring card and one-time payments still unavailable, and card billing expected before direct bill. It mirrors the honored-by-date-received guidance for outage-period cancellations and changes, and routes life and AD&D changes to the mail-in forms page.
Two things did not move: the page remains undated, and it says nothing about the life and annuity call centers reported as due to open Friday, August 14.
Trade press: TruStage says it is still on track for mid-August, and that answers on whether data was accessed are likely two to three months away
Trade press: TruStage says it remains on track for mid-August and claim payments have begun across business lines — and, for the first time with an interval attached, says the data question will likely take two to three months to answer.
More detail
Credit Union Daily reported a new TruStage recovery update in which president and CEO Terrance Williams said the company is making 'steady advancements in restoring our technology environment' and remains on track for most key processes by mid-August. Per the report: the retirement contact center has reopened and the life and annuity centers are due August 14; claim payments have begun moving across business lines, with the pre-outage backlog of life and accidental death claims prioritized; billing has resumed so coverage is not disrupted; and defined contribution participants may request withdrawals and loans by phone. Retirement and annuity account values remain unaffected.
On data, Williams reportedly said it will likely be two to three months before the company can say whether member or employee information was involved — the first time any interval has been attached to that answer.
The statement is undated and appears on no TruStage public page as of capture; TruStage's own pages were unchanged this morning, so this is recorded as reported rather than confirmed. TruStage's own August 12 email update to partners, received by the association on August 14, has since confirmed the account firsthand — see the entry logged for that update.
Direct from TruStage: the August 12 partner update confirms the recovery picture firsthand, and adds preplanning claims to the restart list
The association has now received TruStage's August 12 partner update directly, converting this week's trade-press picture — call centers reopening, claim payments restarting, a two-to-three-month data timeline — into first-party confirmation. New in it: preplanning and funeral claims are being paid, and most defined-contribution participants can request account-balance updates by phone.
More detail
TruStage's August 12 email update to partners, signed by president and CEO Terrance Williams, reached the association directly on the morning of August 14. It confirms firsthand what this tracker had carried only through trade-press and peer-association relays: basic servicing targeted for mid-August, the retirement call center open with the life and annuity contact centers opening Friday, August 14, billing resumed so coverage is not disrupted, and Mandiant's confirmation of the clean, isolated environment built apart from impacted systems.
Two details had not appeared in any relay. Claims are being paid across the business including preplanning and funeral claims — alongside the GAP and debt-protection restarts already tracked — with life and AD&D processing still working pre-outage pending claims before newer submissions. And the majority of defined-contribution participants, other than those on certain legacy platforms, can request withdrawals and loans where their plan allows and ask for account-balance updates over the phone.
On data, the update repeats the two-to-three-month estimate for complete answers and the commitment to notify affected parties first if member or employee data is compromised.
Because this is a communication addressed to partners rather than a public page, this entry links TruStage's public credit-union outage hub instead of the email. None of this content appeared on TruStage's public pages as of this morning's sweep.
TruStage dates the ACH restart to August 4 and says late-July and August due dates are being worked through
TruStage dates the ACH restart to August 4 for certain life and AD&D policies and says late-July and August due dates are being worked through, with card billing expected back before direct bill. Changes and cancellations requested during the outage will be honored by date received.
More detail
TruStage re-stamped its dated outage pages on the afternoon of August 12 and used the individual page to put detail behind its billing position. The payment answer now carries a start date: recurring ACH premium collection began coming back on August 4 for certain life and AD&D policies, and TruStage is working through policies whose due dates fall in late July and August. Recurring credit card and one-time payments remain unavailable; TruStage expects card billing to return ahead of direct bill, which will take additional time.
That partially answers the eligibility question flagged as unanswerable on August 11 — it describes a scope, though still no way for a member or credit union to confirm whether a particular policy sits inside it.
Two new answers concern servicing: requests to change or cancel a policy submitted while systems were down may not yet be reflected in billing; TruStage will process them as capability returns and honor each by the date received. Life and AD&D changes are routed to the mail-in service forms page, itself reorganized the same evening.
Quieter changes worth flagging: the individual page shortened weekday outage-line hours from 5:30 to 5:00 p.m. CT (Saturday unchanged), and the credit-union page picked up none of the new billing language — staff should read the individual page directly. Status still reads Investigating.
TruStage says recurring ACH premium payments are beginning to resume for some customers
The first payment processing actually restarts: recurring ACH premium payments are resuming for some eligible customers using details on file. Credit card and one-time payments remain down, and there is no way to check whether a particular policy is in scope.
More detail
TruStage rewrote the payment section of its individual and credit-union outage pages late on August 11 (snapshots place the change between 4:25 and 6:12 p.m. CT). Recurring ACH premium payments are beginning to resume for some eligible customers, drawing on payment information already on file. Recurring credit card payments and one-time payments are still unavailable, and because account access remains limited, representatives cannot verify an individual customer's payment activity or policy status.
This is the first time TruStage has said any premium payment processing is actually restarting rather than promised for when systems return — a concrete restoration step. Read the scope carefully before passing it to members: one payment method, only 'some eligible customers' in TruStage's words, and no way for a member or credit union to find out whether a particular policy is in that group.
The individual page also restructured its coverage answer — customers will not lose coverage because they were unable to pay during the disruption; active and grace-period policies keep their status until normal processing resumes, with accommodations including extended grace periods to follow. The warning that TruStage is not sending premium-payment requests or past-due notices carries over and has been added to the credit-union page, so staff fielding a call about a suspicious notice can point to the page written for them.
Neither page advanced a date stamp for this change, and status across the outage family still reads Investigating.
TruStage's status page now calls the event a cybersecurity attack and replaces its technical FAQs with a new Investigation FAQs for vendors and partners
TruStage's status page now calls the event a cybersecurity attack and replaces its technical FAQs with a new Investigation FAQs document for vendors and partners — the consolidated channel for the vendor-management questions credit unions will be asked.
More detail
TruStage rewrote its outage-information status page. The heading now describes an actively investigated cybersecurity attack (previously incident), and the body matches the July 31 press release: the attack was broad, portions of the network and systems are being rebuilt rather than switched back on, and services restore in a deliberate sequence protecting employees, partners, members, and customers.
The closing pointer changed too: the Technical Incident FAQs reference that stood since July has been replaced by a new Investigation FAQs document dated August 10, described as answering vendors' and partners' questions about what happened, what steps TruStage has taken, what is known, and what remains under investigation. The link opens TruStage's document viewer displaying the four-page PDF rather than downloading a file.
Operationally nothing changes — status still reads Investigating and the mid-August target is unchanged — but the new document is TruStage's consolidated channel for the vendor-management questions credit unions are expected to ask their vendors after an event like this. It is linked under Resources below.
TruStage puts Mandiant on the record publicly: a new FAQ says the incident is contained and systems return to a clean environment
For the first time, TruStage's containment claim is sourced to its forensic firm: a new FAQ points to a public Mandiant memo saying the incident is contained and systems return to a clean environment. It is not a data-exposure finding, and Mandiant confines its findings to the scope of its investigation.
More detail
TruStage added the same new question to five of its outage pages and a matching line to the hub — the most substantive change in a week. The question: has a cybersecurity expert provided information on whether the incident is contained and whether TruStage is operating in a clean, safe environment as systems return? TruStage answers yes, says it continues to work closely with Mandiant, and directs readers to a Mandiant investigation memo dated August 10, published at a public address on TruStage's own site. The memo is linked under Resources below — a three-page PDF that downloads rather than opening as a web page.
Why this matters: TruStage has said since July 31 that the incident was contained, but that was TruStage speaking about itself. This is the first time the outside forensic firm's assessment is public under Mandiant's name — the first time the containment claim is sourced to something a reader can inspect.
On the question credit unions ask most, Mandiant writes that it has not observed the threat actor interacting with files shared with third parties, or with third-party systems, portals, VPNs, APIs, or other environments connected to TruStage. Read that with the limit Mandiant places on it: the preceding sentence confines its findings to the environments within its investigation's scope, and the memo does not define that scope. It is not an unqualified all-clear for every connected credit union system, and it says nothing about whether data was accessed — which TruStage still calls premature to judge. It does not replace your own review of any connection you maintain to TruStage.
It is also not a restoration announcement: every page still shows status Investigating and the mid-August target is unchanged. The five pages carrying the question are credit union, business, annuity, preneed, and retirement; individual and wealth management had not picked it up at capture. TruStage re-stamped the outage family August 11 at 12:13 p.m. CT alongside this change.
TruStage reopens dedicated retirement phone lines and says its representatives can now do more
TruStage reopened dedicated retirement phone lines — 844-999-2677 for plan sponsors, advisors, and TPAs; 800-999-8786 for participants — and says representatives now have limited account access. A staffing improvement, not a systems restoration: BenefitsForYou is still offline.
More detail
TruStage improved the contact and servicing posture on its Retirement Solutions page. Where it previously said representatives could not access account information or process transactions, it now says they have limited access to account information and limited transaction capabilities. Two dedicated lines replace the general outage number: a Retirement Service Center at 844-999-2677 for plan sponsors, advisors, and third-party administrators, and a Participant Service Center at 800-999-8786 for participants — weekdays 8:00 a.m.-5:00 p.m. CT. Neither number had appeared on any TruStage outage page previously captured.
Two cautions for credit unions passing this along. This is a change in what staffed phone lines can do, not a systems restoration: BenefitsForYou is still offline, contribution and investment election changes, trades, and beneficiary updates still cannot be accepted, and status still reads Investigating. The new lines also carry narrower hours than the general line they replace, which ran to 5:30 p.m. weekdays and covered Saturdays.
TruStage did not advance the page's timestamp for this change, and the later August 11 family re-stamp accompanied a separate change — so the date recorded is the date this tracker verified the new language.
Wealth Management page says advisors and credit unions can reach Salesforce by direct login
Advisors and credit unions can now reach Salesforce by direct login, per the Wealth Management page — though the page's own line that advisors cannot access client notes still stands unreconciled, so confirm the scope with your TruStage contact.
More detail
TruStage rewrote its Wealth Management Solutions outage page and answered a question it had deferred since the outage began: advisors and credit unions can get into Salesforce through a direct login, with instructions from their assigned Advisor Manager Specialist or Regional Program Consultant.
One caution for program staff: the page's own 'What you should know' paragraph still says advisors cannot access Salesforce for client-specific notes — the old and new statements sit unreconciled on the same page. Treat the direct-login route as the newer of the two and confirm its scope with your TruStage contact.
The page also adds a compensation answer for the second half of July — managed and dual advisors paid on the regular schedule, credit unions paid the same amount as the first half, which was based on a six-pay-period average — and finally adopts the mid-August recovery answer and standard recovery lead, making it the last outage sub-page to catch up.
TruStage tells policyholders it is not behind offers to replace their insurance coverage
TruStage is on record that it is not behind any offer to replace, surrender, or discontinue in-force coverage. Useful for members being pressed to switch policies during the outage — the offer is not coming from TruStage.
More detail
A new question on TruStage's individual outage page addresses policyholders who have been approached about replacing their insurance with another company's. TruStage answers plainly: such offers do not come from the company, and it is not encouraging, facilitating, or taking part in any effort to replace, surrender, or discontinue in-force coverage — because of the incident or as part of recovery.
Worth passing to members: an insurer's systems being offline is exactly the circumstance in which policyholders may be told their coverage is at risk and pressed to switch. TruStage is now on record that it is not the source of those approaches.
TruStage did not advance the page's timestamp (still August 6), so the date recorded is the date this tracker verified the answer was publicly visible.
TruStage says auto and home coverage is running normally through Liberty Mutual and Polly
Auto and home insurance is running normally through Liberty Mutual and Polly — quotes, purchases, servicing, and claims all uninterrupted — the first product line TruStage describes as fully working.
More detail
TruStage added a product question to its credit-union outage page confirming that auto and home insurance is operating through its partnership with Liberty Mutual and Polly: members can get quotes, buy coverage, have policies serviced, and reach claims support, none of it interrupted by the attack. One caveat: while the servicing experience 'remains largely unchanged,' the online experience may look different for now.
This is broader than what was previously on the record — the July 23 video had Liberty Mutual and Polly processing new business from direct-mail leads; TruStage now describes the full policy lifecycle, servicing and claims included, as running without disruption. For staff fielding member questions, it is one of the few product lines that can be discussed as working normally.
The credit-union page carries no date stamp, so the date recorded is the date this tracker verified the answer was publicly visible.
TruStage rewrites its Retirement Solutions outage page, promising interim processes and dating the delayed benefit statements
TruStage now promises interim retirement processes and commits to statement dates: paper quarterly statements have mailed, and participants who elected e-statements will be sent paper copies expected the week of August 10.
More detail
TruStage substantially rewrote its Retirement Solutions outage page under an August 6 timestamp. It now says it will introduce temporary processes while recovery continues and is contacting plan sponsors as solutions become available. On payroll, where the page previously said flatly that non-aggregator files could not be processed, TruStage now says it is working on an interim solution and will share news with sponsors.
Statements moved from open-ended delay to specific commitments: quarterly paper statements for the period ended June 30 have been mailed, and participants who elected electronic statements will be sent a paper copy, expected to mail the week of August 10 — some who signed up for paper may receive a duplicate.
Two items also quietly left the unavailable list: the sentence about the Participant Service Center phone and email being down, and loan and distribution requests among those TruStage cannot accept. TruStage did not describe either removal as a restoration, and this tracker does not treat it as one.
TruStage adds direct deposit and income benefit forms to its annuity outage page
Two more annuity self-service routes: an e-signed direct-deposit change form and a downloadable income-benefit form for Zone and ZoneChoice Income contracts. These are workarounds, not restored processing.
More detail
TruStage extended the self-service annuity forms introduced August 4 with two further routes: an e-signed direct deposit change form through AssureSign, in single- and joint-owner versions, and a downloadable income benefit service form for Zone Income Annuity and ZoneChoice Income Annuity contracts. The general resources block was reorganized — transfer and allocation-change forms consolidated, the claims link moved alongside — and the advisor-resources block pointing producers to their wholesaler was removed.
As with the August 4 forms, these are workarounds rather than restored processing: online account access remains down, and TruStage has not said requests submitted this way will be handled faster than its recovery timetable allows.
TruStage opens a mail-in service-forms page for individual life and AD&D policies
Individual life and AD&D policyholders get their first servicing route of the outage: mail-in PDF forms for ownership, beneficiary, and service changes, honored back to the date each request was received.
More detail
A new page on TruStage's outage site gives individual life insurance and AD&D policyholders a way to submit servicing requests while systems are down — their first servicing route of the outage. It carries downloadable PDF forms for changes of ownership, beneficiary changes, and general service requests (billing-frequency changes, withdrawals, loans, cancellation or surrender), with versions depending on whether the policy is issued by CMFG Life or MEMBERS Life and the policy-number prefix. Ownership changes require a completed W-9.
Instructions: print, complete, sign, and mail to the address on the form — fax is not available. TruStage says requests will be processed as systems are restored and honored back to the date received.
It parallels the annuity forms route added August 4, though mail-based rather than e-signed. TruStage did not advance the individual page's timestamp when the forms appeared, so the company has not itself stated a publication date.
TruStage rewrites its outage-page lead again and brings the credit union page into line
TruStage's outage-page lead no longer says the attack was contained. The claim still stands in the July 31 press release, but the lead copy now stresses the breadth of the impact and the rebuilding of infrastructure instead.
More detail
TruStage revised its outage-page lead again, re-stamping the dated pages August 5 at 4:48 p.m. CT. The sentence saying the incident had been contained since detection is gone from the lead; the new copy stresses the breadth of the impact across the network and systems and the deliberate rebuilding of infrastructure so services restore safely. On the outage hub, the paragraph stating the incident was contained and no malicious code or bad actor remained was removed altogether.
The containment statement has not been withdrawn — it still stands in the unchanged July 31 press release. It simply no longer appears in the outage-page lead copy.
Separately, the credit-union page joined the rewrite it had sat out for two days: it now calls the event an attack, adopts the same recovery language, adds the mid-August resolution answer, and sharpens its claims guidance to file new claims through the online intake page. That page is still undated, and status across the site still reads Investigating.
TruStage publishes a lump-sum continuity process for recurring Debt Protection benefit payments
Credit unions whose members were already approved for recurring Debt Protection payments are being paid a single lump sum mirroring the prior month. TruStage's claims team will contact each participating credit union directly with the member-level detail.
More detail
TruStage's credit-union outage page now describes how recurring Debt Protection benefit payments are handled while systems are down: a temporary business-continuity process, begun July 29, for credit unions whose members were already approved for recurring payments. Rather than paying individually, TruStage pays a single lump sum generally mirroring what the member received the previous month, adjusted where a benefit has since ended.
Because the lump sum arrives without a member-level ledger, a member of TruStage's claims team will contact each participating credit union directly with the payment detail needed to get the money to the right members. The process starts proactively for credit unions that received six or more recurring member benefit payments the previous month; credit unions below that threshold may ask the claims team to review a member they believe should have been paid.
This is the first time the arrangement has appeared on TruStage's own public page; early-August trade press had described it only as a test with a small number of credit unions.
TruStage rewrites its public outage pages: calls the event an attack, dates it to July 11, and puts the mid-August target on the pages themselves
TruStage rewrote its public outage pages: the event is now a cybersecurity attack identified on July 11, described as contained, and the mid-August target now appears on the ordinary public pages members are sent to.
More detail
TruStage revised every dated public outage page and its consumer FAQ on the morning of August 4 — the first substantive rewrite of that language since the incident began. The event is now called a cybersecurity attack rather than an incident throughout, 'identified on July 11' — a date previously given mainly through partner materials and press releases. The opening paragraphs now say TruStage continues to make progress on recovery, that the attack has been contained since detection, and that it is rebuilding portions of its infrastructure and restoring systems in a controlled way.
Most significant for members: a new question on when this will be resolved now appears on the business, retirement, and other outage pages, answering with the mid-August target for the majority of key processes. That target had lived only in the July 31 press release, the CEO video, and emailed partner materials — it is now on the ordinary public pages members are sent to.
The status field still reads Investigating everywhere, and TruStage still calls it premature to draw conclusions about whether any data was accessed.
TruStage adds e-signature annuity forms and an individual service hub while systems stay offline
Annuity owners now have a forms-based way to transact: e-signed cancellation, right-to-examine, partial-withdrawal, and surrender forms through AssureSign, plus downloadable transfer forms. Online account access remains down.
More detail
Alongside the August 4 rewrite, TruStage expanded what annuity contract owners can actually do while systems are down. The annuity outage page now offers electronically signed forms through third-party partner AssureSign for cancelling a pending application, exercising the right to examine, taking a partial withdrawal, and surrendering a contract in full — each in single- and joint-owner versions. A general-resources block adds downloadable transfer and allocation-change forms for the ZoneChoice, Zone, Horizon, and Variable Annuity products, labelled as PDF downloads on TruStage's page. The consumer FAQ also gains a link to a new individual service hub covering claims, annuity resources, and retirement support.
The practical effect: annuity owners who previously had no route to transact now have a forms-based one. Processing still depends on TruStage's restoration — transactions will be handled by the date and time received — and online account access remains unavailable.
TruStage's credit union outage page swaps in a new CEO video, and the outage pages re-stamp for the first time in three days
A new CEO video on the credit-union page carries the July 31 message — attack contained, Mandiant named, mid-August target. It replaces the July 23 video, whose cause-and-NCUA material now lives only in this tracker's earlier entry.
More detail
TruStage refreshed its dated outage pages on the afternoon of August 3 — the first stamp movement in three days — and the substantive change is on the credit-union page, where the July 23 CEO video has been replaced by a new one. In it, Terrance Williams describes the July 11 event as a broad attack on TruStage's network and systems, says the incident was contained and the company is confirming no malicious code or threat actor remains as it rebuilds, and repeats the mid-August target with the caveat that systems may return before fully normal. He notes refreshed workforce laptops and updated security, names Mandiant as the partner on the data investigation, tells credit unions TruStage still does not know whether member data was accessed — partners will be the first to know — and commits to email updates multiple times a week.
The content matches the July 31 newsroom release; what is new for credit unions is that it now sits on the page they are directed to. The July 23 video's material — including the malicious-file account and the NCUA reporting process — is no longer on the page; it remains recorded in this tracker's July 23 entry.
Official: TruStage says the incident is contained, names Mandiant, and states the mid-August target on its own newsroom
In its fullest public statement yet, TruStage says the incident is contained, names Mandiant as its forensic partner, and puts the mid-August target on the record — while saying it still does not know whether member data was accessed.
More detail
TruStage published a second incident press release in its newsroom, dated July 31 — the fullest public account it has given. The incident has been contained; the event was broad enough that TruStage rebuilt parts of its infrastructure so systems could be brought back safely rather than simply switched back on, and as it rebuilds it is confirming no malicious code or bad actor remains. Employee laptops have been refreshed and security measures updated, with that work close to complete.
On timing, TruStage states publicly for the first time that it anticipates the majority of its key processes will be operational by mid-August, prioritizing the operations most critical to partners and their members — cautioning that some systems may come back before they are fully operational, with workarounds continuing meanwhile.
On data, it names Mandiant as the outside cybersecurity partner on the investigation, says forensic work takes time, states it does not yet know whether member data was accessed, and commits that if members' personal information is involved it will tell affected partners first and help with any notification or reporting. It also commits to partner email updates multiple times a week.
For credit unions this matters on three counts: the mid-August target is now an on-the-record public statement, the forensic firm is named for the first time, and the containment statement is TruStage's own words.
Official: TruStage publishes member-letter and talking-point materials for credit unions, and puts the mid-August target in writing
TruStage published an optional member-letter template and a staff talking-points sheet, both dated July 31 — its first published documents to put the mid-August operational target in writing, with a careful definition of what that target means.
More detail
TruStage published two dated communications documents for credit union partners, both stamped July 31 and hosted on trustage.com: an optional member-and-customer letter template that credit unions may adapt and send, and a talking-points-and-FAQ sheet for staff. Neither carries a confidentiality marking. Their significance: they are the first TruStage-published documents to state a restoration target — 'working toward being operational by mid-August.'
The definition is careful: priority processes and services available through a mix of restored systems, interim processes, and alternative support paths — not every system immediately at full functionality, with temporary workarounds possibly remaining. Until now the target had appeared only in trade-press reporting of a CEO video, and it was still absent from TruStage's public outage pages.
On the recovery, TruStage says it stood up a clean, isolated technology environment segmented from impacted systems, validated by outside cybersecurity experts using secure recovery practices, with restored services passing established validation before production. It describes the event in its own words as a cybersecurity attack that significantly impacted critical technology infrastructure.
The materials summarize progress — claims reporting, expanded phone support including a third-party contact center, lending-related payment processes, certain annuity and retirement processes, recurring disbursements restored — note that platforms with more dependencies may take longer, repeat that conclusions on data are premature, and commit that TruStage will work directly with credit unions and partners if it determines data was compromised.
Trade press: CEO tells credit union partners most key processes should be operational by mid-August; data question still open
Trade press: the CEO told credit union partners most key processes should be operational by mid-August — the first restoration timeline attributed to TruStage, though it appeared on no public TruStage page at capture.
More detail
CU Today reported that TruStage president and CEO Terrance Williams gave credit union partners a new video update saying the company anticipates the majority of its key processes will be operational by mid-August, cautioning that systems coming back online may not be fully operational or fully back to normal. On data, he said the company does not yet know whether member data was accessed, and partners would be the first to know if that changes.
Per the report: customer calls are handled through a third-party contact center, lending capability is in testing with eight credit unions, annuity transactions, death claims, and withdrawals are moving again, and basic billing and claims servicing is expected in the first half of August. The life insurance platform is more complex, spanning several interconnected systems, and broader systems remain offline.
This was the first restoration timeline attributed to TruStage. At capture it appeared on no TruStage public page — the credit union outage page still said no product-specific claim timelines were available — so it is recorded as reported rather than confirmed.
Official: TruStage expands its credit union FAQ — servicing and claims still limited, no product-level payment timelines
TruStage still cannot say when claims will be paid: product-specific timelines are not available, and claims will be evaluated and paid under policy terms as capabilities return. Some servicing and claims activity remains limited.
More detail
TruStage substantially expanded the FAQ on its credit-union outage page, adding a general outage section and answers written for credit union leaders. The most decision-relevant point: TruStage still cannot say when claims will be paid. 'Product-specific claim payment timelines are not available,' and claims will be evaluated and paid under the applicable policy terms as operational capabilities are restored. Representatives can take inquiries and offer guidance, but some servicing and claims activity remains limited.
It restates: premature to draw conclusions on scope, impact, or data access; grace periods are being extended, with more than one premium possibly coming due; BenefitsForYou is still unavailable; annuity and retirement balances and benefits are unaffected.
New for credit unions planning ahead: the timing and approach for restarting marketing activity, including direct mail scheduled for August, is under evaluation, with lead-fulfillment plans to be communicated separately. The page's question-submission form was replaced with a pointer to the credit union's account representative. The page carries no date stamp of its own; the content appeared between midday and late afternoon on July 31.
Official: TruStage resumes some Retirement Solutions processing — aggregator payroll files and scheduled distributions
The first Retirement Solutions processing resumes: payroll files submitted through third-party aggregators (PayKonnect, Payroll Integrations) and previously scheduled distributions are moving again. BenefitsForYou is still offline.
More detail
TruStage's Retirement Solutions outage page (re-stamped July 30, 4:43 p.m. CT) reverses two answers that previously read as unavailable: payroll files submitted in good order for 360 processing through third-party aggregators — the page names PayKonnect and Payroll Integrations — are now being processed, and previously scheduled installment and annuity distributions are being processed again. Other payroll submissions remain unavailable.
Plan sponsors are no longer told to withhold payroll files; the guidance now says to continue normal payroll operations, including withholding participant deferrals and loan repayments.
Two limits are newly stated: participants and employers who elected electronic benefit statements may see a delay for the quarter ended June 30, and sponsors whose custodian or directed trustee is Matrix Trust Company can log in through Matrix/Broadridge for plan-level statements — an option that does not apply to Choice Group Variable Annuity plans. BenefitsForYou is still offline and participant transactions remain unavailable.
Official: TruStage will extend grace periods, and warns it is not sending past-due payment notices
TruStage will extend applicable grace periods once payment processing resumes — and states it is not currently sending premium-payment requests or past-due notices, so members receiving one should treat it as suspect and not click, share, or pay.
More detail
TruStage added two answers to its consumer FAQ and its individual and preplanning outage pages, first seen on the July 30 stamp. Because payment processing is unavailable, it will extend applicable grace periods once processing resumes — and depending on when premiums normally fall due, more than one payment may come due during the extended period. Policies that are active or in a grace period keep that status meanwhile.
Separately, TruStage states it is not currently sending communications requesting premium payments or telling customers a payment is delinquent, and tells anyone receiving such a message not to click links, provide personal information, or submit payment information. That gives credit unions a concrete answer for members who call about a past-due notice during the outage.
TruStage publishes credit-union outage guidance: interim GAP and MRC processes, claims handling, and what can still be sold
TruStage itself now publishes the credit-union interim processes: credit insurance, debt protection, and GAP can still be sold; eligible PAX credit unions may use the GAP workaround; GLOW produces MRC quotes but no contracts; and every outage-period sale must be documented for later PAX entry.
More detail
TruStage's outage hub now includes a page written for credit unions. Credit insurance, debt protection, and GAP can still be sold, and members are directed to start claims at trustage.com/startclaim.
The interim processes that earlier reached us through a state association are now stated by TruStage itself: eligible PAX credit unions may use the approved GAP workaround, must document every sale made during the outage, and must enter those sales into PAX once service is restored. A limited group of high-volume credit unions may use Assurant's GLOW platform to generate mechanical repair coverage quotes and member pricing and finance the cost into the loan — GLOW explicitly cannot issue contracts, so the official MRC certificate issues only after PAX is back and the sale entered. Selected credit unions receive separate implementation instructions.
For GAP claims and servicing — including a vehicle totaled before a contract could be completed in PAX — the instruction is to keep collecting claim details and supporting documentation. TruStage does not date this page, so the date shown is the date the IT Department captured it.
Wealth Management Solutions page states the NCUA reporting path and tells credit unions to take their own notification advice
TruStage spells out the NCUA reporting path — 1-833-CYBERCU or cybercu@ncua.gov, referencing the TruStage event — and tells credit unions to consult their own legal, compliance, and risk teams on notification duties.
More detail
TruStage's Wealth Management Solutions outage page (stamped July 28) spells out the regulatory mechanics in TruStage's own words: the NCUA is aware of the event, and a credit union that determines the incident is reportable may satisfy that by calling 1-833-CYBERCU (1-833-292-3728) and leaving a voicemail, or emailing cybercu@ncua.gov, giving the credit union's name and referencing the TruStage cybersecurity event.
On whether a credit union must notify its regulators at all, TruStage does not advise: requirements depend on the credit union's own customer relationships, applicable law, and internal policy — consult legal, compliance, and risk teams.
Operationally, the program's financial advisors can serve members through their LPL access and can sell and service every product except TruStage annuities; advisors cannot reach Salesforce for client notes; and an online option is open for annuity partial withdrawals and surrenders, with processing slowed by manual handling. Advisor and credit-union compensation for the first half of July was paid on schedule using an estimate based on the average of the last six pay periods.
TruStage tells individual policyholders that coverage will not lapse during the outage
TruStage says individual coverage will not lapse: a policy that is active or in a grace period keeps that status until payment processing resumes. A dedicated outage line, 844-958-8910, is now staffed seven days a week.
More detail
TruStage's outage pages for individuals and preplanning coverage (stamped July 28) answer the question front-line staff are most likely to be asked: individual coverage status is not at risk during the outage. A policy that is active or in a grace period stays in that status until regular payment processing resumes, and policyholders can make or update payments once operations are restored.
If someone dies during the disruption, the claim will be processed and paid under the applicable policy terms once TruStage is able; claims start at trustage.com/startclaim. Representatives currently cannot see policy or account information, process transactions, or submit requests.
A dedicated outage line is published: 844-958-8910, weekdays 8:00 a.m.-5:30 p.m. CT and weekends 9:00 a.m.-4:00 p.m. CT, with a warning that waits are longer than usual. On data, the answer is unchanged: conclusions about scope or impact remain premature.
TruStage: annuity and retirement balances are unaffected, and it has seen no unauthorized transactions on contract-owner funds
TruStage says annuity contract values and retirement balances are unaffected, and it has found no evidence of unauthorized transactions on contract-owner funds. BenefitsForYou remains offline, and plan sponsors get record-keeping guidance for the delay.
More detail
TruStage's annuity and retirement outage pages (both stamped July 28, 10:43 a.m. CT) carry the most concrete reassurance the company has published so far. On annuities: contract values, account balances, and benefits have not been impacted; transactions will be processed by the date and time received once servicing resumes; and the investigation to date shows no evidence that contract-owner funds, the assets backing annuity obligations, or other company financial accounts saw unauthorized transactions. Owners can submit partial-withdrawal and surrender forms through the company's e-signature partner meanwhile.
On retirement plans: account balances and plan benefits are unaffected, but with BenefitsForYou offline participants cannot view balances, change contributions or investments, trade, update beneficiaries, or request loans and distributions, and the participant service center's phone and email are down. Plan sponsors are told not to submit payroll and contribution files — including through aggregators — but to continue normal payroll operations and withholding, to keep records of processing dates and outage communications, and that Department of Labor guidance allows additional time when the delay is the service provider's outage.
Previously scheduled installments and annuity distributions cannot be processed at present; quarterly statements for the quarter ended June 30 are mailing on the normal schedule. On data, both pages still call conclusions premature.
Trade press: TruStage partner FAQ names Mandiant, confirms regulator and NCUA notification, reports no threat activity since July 11
Trade press: TruStage's partner FAQ names forensic firm Mandiant, confirms law-enforcement, NCUA, and regulator notification, and reports no threat-actor activity since July 11 — but still no answer on whether credit union data was accessed.
More detail
Credit Union Daily reported that TruStage issued an updated technical FAQ for its business partners. Per the report, TruStage notified law enforcement, engaged the forensic firm Mandiant, made the NCUA aware of the event, and notified applicable regulators. It states it has seen no threat-actor activity since July 11, has identified no known CVEs tied to the compromise, and has not observed the attacker interacting with files shared through third-party systems, portals, VPNs, or APIs connected to TruStage.
It still will not say whether partner or credit union data was accessed or exfiltrated, when access began, how long the intruder remained, what type of attack occurred, or whether anyone claimed responsibility — and it cannot yet give an individual credit union a written attestation about its data. A credit union that determines the event is reportable may notify the NCUA by phone or email, referencing the TruStage event.
The underlying partner FAQ is dated July 20 and marked proprietary and not for distribution, so this entry cites the published report and omits the technical indicators of compromise the document contains. None of these points appeared on TruStage's public pages at capture.
TruStage opens a dedicated outage resource hub
TruStage opened a central outage hub at trustage.com/outage, routing individuals and businesses to service-specific pages, claim filing, and the 1-833-374-1541 support line.
More detail
TruStage stood up a central resource hub at trustage.com/outage, dated July 24. It repeats that the company identified a cybersecurity incident affecting its environment, that systems remain down while teams work to establish the facts, and that outside experts and business-continuity plans are engaged.
The hub routes individuals and businesses to service-specific pages, claim filing, and retirement-solutions support, and lists the 1-833-374-1541 support line. It gives no restoration timeline and no finding on data, and continues to call conclusions about scope premature.
TruStage's own site now carries the CEO video confirming the July 11 detection, the likely cause, and a phased restart
TruStage now states it directly on its own site, in a CEO video: July 11 detection, a workforce member likely downloading a malicious file as the cause, phased restoration under way, and most credit-insurance and debt-protection products running again. Still no conclusion on data.
More detail
TruStage's credit-union outage page carries a recorded update from CEO Terrance Williams, posted July 23. He says TruStage identified unusual activity on July 11 and shut systems down immediately, engaged outside cybersecurity experts, notified law enforcement, and continues notifying regulators. On cause: a member of the workforce may have inadvertently downloaded a malicious file while trying to install a legitimate tool. Investigation and recovery both remain in progress.
He describes restoration as phased and prioritized over days and weeks, with tested workarounds carrying some functions: most credit-insurance and debt-protection products running again, Liberty Mutual and Polly processing auto and home business from direct-mail leads, a GAP-waiver workaround rolling out to credit unions, bond and business-protection renewals supported, and Compliance Solutions cloud products unimpacted. A streamlined NCUA process exists for credit unions that deem the event reportable.
On data, he repeats it is premature to draw conclusions. This material had reached credit unions only through trade press until now; it is significant because TruStage is stating it directly on its own page.
Trade press: second outlet reports the likely cause and lists business lines back in service
A second outlet corroborates the likely cause — an employee inadvertently downloading a malicious file — and reports the phased restoration under way, adding that auto and home business is processing through Liberty Mutual and Polly.
More detail
Credit Union Daily reported that TruStage traces the incident to an employee who, per the company, may have inadvertently downloaded a malicious file while attempting to install what looked like a legitimate tool — corroborating CU Today's earlier account.
CEO Terrance Williams described a phased restoration that began the week of July 21, with manual workarounds in the meantime; he was quoted saying the company would not 'sacrifice quality, security or reliability for speed.' The report lists most credit insurance and debt protection products, auto and home processing through Liberty Mutual and Polly, GAP waiver issuance, and bond and business protection renewals as operating, with Compliance Solutions unaffected.
TruStage still called it premature to conclude whether any data was accessed. None of this yet appeared on TruStage's own newsroom or consumer FAQ.
Trade press: TruStage begins phased recovery; report points to a likely cause
Trade press: TruStage has begun a phased recovery, with most credit-insurance and debt-protection products operating again — and investigators believe the incident began with an employee inadvertently downloading a malicious file.
More detail
CU Today reported that TruStage has entered recovery, bringing systems back in a controlled, prioritized sequence expected to span days and weeks. Most credit-insurance and debt-protection products are operating again, with temporary manual workarounds supporting some claims, GAP waivers, and bond and business-protection renewals; cloud-based Compliance Solutions were unaffected.
Investigators reportedly believe the incident began when an employee inadvertently downloaded a malicious file while installing what appeared to be a legitimate tool; TruStage detected unusual network activity on July 11 and shut systems down to contain it. CEO Terrance Williams was quoted saying the company would 'be methodical.'
TruStage still calls it premature to say whether any data was accessed, and says it is coordinating with outside experts, law enforcement, and regulators, including a streamlined NCUA reporting path. Separately, American Banker reported no ransom demand and no threat-actor activity since discovery. These details came from trade press and were not yet on TruStage's own pages.
SEC filings: MEMBERS Life annuity transactions suspended during outage
SEC filings from TruStage subsidiary MEMBERS Life confirm annuity transactions — withdrawals, surrenders, beneficiary changes, death-claim payments, new contracts — are suspended during the outage, with mail-in interim options for some requests.
More detail
MEMBERS Life Insurance Company, the TruStage subsidiary that issues annuity contracts, filed prospectus supplements with the SEC on July 20-21 (Forms 497/497VPU) disclosing that the incident has disrupted its operations.
The filings say the company temporarily cannot process a range of contract transactions — cash withdrawals, surrenders, systematic withdrawals, beneficiary changes, death-claim payments — and cannot issue new contracts while systems are restored; interim mail-in arrangements cover certain requests.
The filings do not state that any non-public personal information was accessed, and no restoration date is given. Members holding TruStage annuities may see delays in these transactions.
Consumer FAQ status stamp advances; restoration still under way
TruStage advanced its consumer FAQ's status stamp to July 19 with no substantive change: systems still down, no restoration date, no data-exposure finding.
More detail
TruStage refreshed the status line on its consumer FAQ to July 19, 2026, 11:15 a.m. CT. The substance did not change: systems remain shut down while the company works to restore them, customers may still have trouble reaching accounts or completing transactions online, and TruStage says it is premature to draw conclusions about the scope or impact of the incident. No restoration date and no data-exposure finding were given.
TruStage provides update on cybersecurity incident
TruStage pointed customers to newly launched resources — a consumer FAQ, an online claim-start page, and the support line 1-833-374-1541 — while systems remain down.
More detail
In an update posted to its newsroom, TruStage said it had activated its incident response and recovery protocols and engaged outside cybersecurity experts. With its systems still down, the company directed customers to newly launched resources: a consumer FAQ, an online page to start a claim, and a support line at 1-833-374-1541.
Consumer FAQ: systems proactively shut down, restoration underway
TruStage's consumer FAQ confirms systems were proactively shut down and warns customers may have trouble reaching accounts or completing transactions. The company calls it premature to say whether any data was accessed.
More detail
TruStage's consumer FAQ (marked last updated July 16) describes the situation as under investigation, with systems proactively shut down while restoration continues. Customers may have difficulty accessing account information, completing transactions, or submitting requests online; delayed 401(k) access and how to file claims are specifically addressed.
TruStage said it would be 'premature to draw conclusions about the scope or impact' of the incident, including whether any data was accessed.
Online claims page opened for filing during the disruption
Members can start a claim online through TruStage's new form while systems are down. It deliberately collects no policy, account, or Social Security numbers — a useful anti-phishing detail to share.
More detail
TruStage opened an online form for consumers to begin a claim while systems are down, covering protected-loan, death-or-dismemberment, and business-protection claim types, and says it will follow up as soon as possible. Rather than collecting sensitive details, the form asks members to choose a relationship and a preferred contact time, and cautions users not to include policy, contract, account, or Social Security numbers.
Compliance Solutions says its cloud products are unaffected
TruStage Compliance Solutions says its cloud products are not affected and clients can keep using them as usual.
More detail
TruStage Compliance Solutions posted a notice on its community portal saying it was aware of the cybersecurity issue TruStage had announced, and that its own cloud products were not affected. Clients were told they could keep using those applications as usual, and the notice repeated that the outage did not originate in Compliance Solutions technology. The notice did not address the cause or scope of the wider TruStage incident.
TruStage discloses incident and activates response protocols
TruStage publicly disclosed a cybersecurity incident, activated its incident-response procedures, and engaged outside experts. It did not say whether any data was accessed.
More detail
TruStage disclosed that it had detected a cybersecurity incident affecting its environment and immediately activated its incident-response and recovery procedures. The company said it engaged outside cybersecurity experts to assist with containment, remediation, and recovery, and that the work remained ongoing. It said it was still establishing the facts and did not indicate whether any data had been accessed or name specific affected systems.
TruStage shuts down portions of network in response to threat
Credit Union Daily reported TruStage voluntarily shut down portions of its network after detecting suspicious activity, with no word on ransomware or whether any data was accessed.
More detail
Credit Union Daily reported that TruStage had voluntarily shut down portions of its network after detecting suspicious activity, triggering its incident-response protocols alongside third-party specialists. The outlet emphasized that TruStage had not indicated whether ransomware was involved or whether any customer or employee information had been accessed.
Outage confined to TruStage products, not credit unions' core services
The disruption is confined to TruStage products — GAP, mechanical repair coverage, and payment protection claims. A partner credit union's own deposits, cards, ATMs, and online banking were unaffected.
More detail
Coverager highlighted the downstream effect on a partner institution: First Commonwealth Federal Credit Union told members that TruStage was temporarily unavailable for GAP, mechanical repair coverage, and payment protection claims. The report noted the disruption was confined to TruStage products offered through the credit union and did not affect the credit union's own deposits, cards, ATMs, or online banking.
Compliance Solutions service desk access restored
Service Desk access was restored the afternoon of July 14; tickets submitted during the two-day outage are being worked in the order received.
More detail
TruStage Compliance Solutions reported that Service Desk access was fully restored as of 3:20 p.m. ET on July 14, two days after the outage that began the morning of July 12. The team said it could again view and process the support tickets submitted while access was unavailable, and that those tickets would be worked in the order received. The notice did not say what caused the outage or whether it was related to the broader TruStage incident disclosed the following day.
Compliance Solutions service desk went offline two days before disclosed incident
TruStage Compliance Solutions' Service Desk went offline the morning of July 12 — two days before TruStage's disclosed incident — delaying support-ticket responses. TruStage has not said whether the two are connected.
More detail
A notice on TruStage Compliance Solutions' community portal reported that as of 8:30 AM ET on July 12 a systems outage was preventing its team from accessing the Service Desk, delaying responses to support tickets. The notice said the outage was not related to Compliance Solutions technology and directed clients and partners to email support addresses instead. TruStage has not publicly said whether this outage is connected to the broader incident it disclosed on July 15.
How this page is maintained
This tracker is compiled by monitoring TruStage’s official newsroom alongside reputable credit‑union trade press, regional news, and peer associations. Official TruStage statements are logged as issued; third‑party reports are reviewed for credibility before they are added. Summaries are written in our own words — follow each source link for the full report.