What your credit union can do now
Work from TruStage's credit-union page
trustage.com/outage/business/credit-union now carries TruStage's own interim GAP and mechanical-repair processes, claims handling, and what you can still sell. Check it before relying on secondhand summaries.
Use TruStage's member communication materials
TruStage has published an optional member letter template and a talking points and FAQ sheet for staff, both dated July 31, that credit unions may adapt and share. Run them through your own review and approval process first.
Expect claim delays — keep a log
Claims filed through TruStage may still be delayed. Keep collecting claim details and supporting documentation, and record member inquiries so each one can be followed up as systems return.
Point members to official sources
Send member questions to trustage.com/outage/individual, the claims-start page at connect.trustage.com/startclaim, and the outage line at 844-958-8910 — not to secondhand reports. Members with individual life or AD&D coverage who need a policy change can now use TruStage's mail-in service forms at trustage.com/outage/individual/service-forms.
Reassure members
This is a disruption at TruStage, not at your credit union. Deposits, cards, ATMs, and online banking are unaffected, and TruStage says annuity and retirement balances are unaffected as well.
Watch for phishing
Scams may reference the outage. TruStage says it is not currently sending premium-payment requests or past-due notices, and it will not ask members for passwords or account credentials by email or text.
What this means for your credit union
TruStage — formerly CUNA Mutual Group — provides insurance and financial-services products that many credit unions offer their members. On its own outage pages the company says it identified unusual network activity on July 11, 2026 and shut its systems down to investigate, disclosing the incident publicly on July 15. It has since begun a phased restoration, and says the likely cause was an employee inadvertently downloading a malicious file while trying to install a legitimate tool.
The incident is at TruStage — not at your credit union
A disruption to TruStage products does not affect your credit union's own deposits, cards, ATMs, or online banking. For most credit unions the immediate effect is a service disruption, not a confirmed data breach.
Restoration has started, but it is phased
TruStage says systems are coming back in a controlled, prioritized sequence over days and weeks, that not all of them return at once, and that some functions are running on tested workarounds in the meantime. It says publicly that it anticipates the majority of its key processes will be operational by mid-August — which it defines as priority processes being available, not every system at full functionality.
Scope and impact are still open
TruStage has not said whether any member or credit union information was accessed, or whether ransomware was involved — it says its cybersecurity partner Mandiant and its internal teams are still working that out. Treat anything beyond TruStage's own statements as unconfirmed.
Brief your front-line staff
If your credit union relies on TruStage products, make sure staff know which services are affected, what interim processes exist, and where to direct member questions. We will keep this page current as TruStage and reputable outlets report.
What is known — and what is not
Confirmed by TruStage
- TruStage says it identified unusual activity on its network on July 11, 2026 and immediately shut its systems down to investigate; its first public statement came July 15.
- TruStage says the likely cause was a member of its workforce inadvertently downloading a malicious file while trying to install a legitimate tool. The investigation is still open.
- Outside cybersecurity experts are engaged for containment, remediation, and recovery; TruStage says it notified law enforcement and continues to notify regulatory authorities as appropriate.
- Restoration has begun and is running in a phased, prioritized sequence over days and weeks, with tested workarounds covering some functions. TruStage says it anticipates the majority of its key processes will be operational by mid-August, prioritizing the operations most critical to partners and their members.
- TruStage says most credit-insurance and debt-protection products are running again, auto and home new business is processing through Liberty Mutual and Polly, bond and business-protection renewals are supported, and a GAP waiver workaround is being rolled out to credit unions.
- Interim processes are published for credit unions: eligible PAX credit unions may use the approved GAP workaround, and a limited group may quote mechanical repair coverage through Assurant's GLOW platform — quoting only, with contracts and certificates issuing after PAX is restored and the sale entered.
- GAP, mechanical repair, and payment protection claims remain disrupted; credit unions are told to keep collecting claim details and documentation.
- TruStage says annuity contract values, balances, and benefits are unaffected, and that it has found no evidence of unauthorized transactions on contract-owner funds, the assets backing its annuity obligations, or other company financial accounts.
- TruStage says individual coverage will not lapse during the outage: a policy that is active or in a grace period stays in that status until payment processing resumes. As of July 30 it also says it will extend applicable grace periods once processing resumes, and that more than one premium payment may then come due depending on the policy's normal payment schedule.
- TruStage states it is not currently sending communications requesting premium payments or telling customers a policy payment is delinquent, and tells anyone who receives one not to click links, share personal information, or submit payment information.
- Retirement plan balances and benefits are unaffected and BenefitsForYou remains offline, but as of July 30 TruStage says payroll files submitted for 360 processing through third-party aggregators (it names PayKonnect and Payroll Integrations) are being processed, other payroll submissions are not, and previously scheduled installment and annuity distributions are being processed. Sponsors are told to continue normal payroll operations and to document any outage-related delay.
- The NCUA is aware of the event. A credit union that determines the incident is reportable may report by calling 1-833-CYBERCU (1-833-292-3728) or emailing cybercu@ncua.gov, naming the credit union and referencing the TruStage cybersecurity event.
- TruStage has launched an outage resource hub with audience-specific pages, a consumer FAQ, an online claims-intake page, and an outage support line (844-958-8910), alongside the general line 1-833-374-1541.
- TruStage Compliance Solutions restored Service Desk access on July 14 and says its cloud products are unaffected.
- As of July 31 TruStage says it cannot give product-specific claim payment timelines. Claims will be evaluated and paid under the applicable policy terms as operational capabilities are restored, and while representatives can take inquiries, some servicing and claims activities remain limited.
- In materials for credit union partners dated July 31, TruStage says it is working toward being operational by mid-August. It defines that as priority processes and services being available through a mix of restored systems, interim processes, and alternative support paths — not every system immediately at full functionality, with temporary workarounds possibly remaining in place. TruStage has since stated the same target publicly — in a July 31 newsroom press release, in a new CEO video on its credit union outage page, and, as of August 4, in a new question and answer on its ordinary public outage pages. That same question and answer was added to its credit union page on August 5.
- TruStage says it stood up a clean, isolated technology environment segmented from systems that were impacted, potentially impacted, or still under investigation, that outside cybersecurity experts validated it using secure recovery practices, and that restored services pass established validation before entering production workflows.
- TruStage says it will work directly with credit unions and other partners if it determines data was compromised, and would notify affected credit unions before communicating with their members.
- TruStage has published materials credit unions may adapt for member communication: an optional member and customer letter template and a talking points and FAQ sheet for staff, both dated July 31, 2026.
- TruStage says the incident has been contained. Because the event was broad, it says it rebuilt parts of its infrastructure so systems could be brought back safely rather than simply switched back on, and that as it rebuilds it is confirming no malicious code or bad actor remains in its systems or network.
- TruStage names Mandiant as the outside cybersecurity partner working with its internal teams on the data investigation. It says it does not yet know whether member data was accessed, and that if members' personal information is involved it will notify affected partners first and support them through any notification or reporting process.
- TruStage says it refreshed employee laptops and updated security measures before staff re-engage with systems, and that this work is close to completion.
- TruStage says it will send partners email updates multiple times a week while restoration continues.
- TruStage's public outage pages and consumer FAQ describe the event as a cybersecurity attack identified on July 11, rather than as a cybersecurity incident. On August 5 the opening paragraph was rewritten again: it now stresses the breadth of the impact across the company's network and systems and the rebuilding of portions of its infrastructure, and the sentence saying the attack had been contained after detection was dropped from that lead and removed from the outage hub. TruStage has not withdrawn the containment statement, which still stands in its July 31 press release; it no longer appears in the outage-page lead copy.
- As of August 4, annuity contract owners can submit application cancellation, right to examine, partial withdrawal, and surrender requests through electronically signed forms on TruStage's annuity outage page, handled through its partner AssureSign, with downloadable transfer and allocation-change forms also posted. Online account access remains unavailable and processing still depends on restoration.
- TruStage says that on July 29 it began a temporary business continuity process for credit unions whose members were already approved for recurring Debt Protection benefit payments. It says those payments are being issued as a single lump sum generally reflecting the prior month's recurring payments, adjusted where a benefit has ended, and that because the lump sum carries no member-level ledger its claims team will contact participating credit unions directly with the payment detail. TruStage says it is starting the process proactively for credit unions that received six or more recurring member benefit payments in the previous month, and that credit unions below that threshold may ask the claims team to review an individual member.
Not yet known
- Whether any member, customer, or credit union data was accessed — TruStage calls conclusions premature.
- Whether ransomware was involved, and whether anyone has claimed responsibility.
- How the attacker got in beyond the stated likely cause, when access began, and how long it lasted.
- Firm dates for individual systems and products. TruStage's mid-August target covers its priority processes overall; it still gives no product-specific claim payment timelines and says platforms with more dependencies may take longer.
- Whether the July 12 Compliance Solutions service-desk outage is connected to the broader incident.
No public evidence
- No public evidence that credit unions' own systems, member deposits, cards, or online banking are affected.
- No public evidence of misuse of member or credit union information.
- No breach-notification filing for TruStage has appeared in any state attorney general database we have been able to enumerate, and no incident filing has appeared with the SEC.
Timeline of updates
TruStage says auto and home coverage is running normally through Liberty Mutual and Polly
TruStage has added a product question to its credit-union outage page confirming that auto and home insurance is operating through its partnership with Liberty Mutual and Polly. The company says members can still get quotes, buy coverage, have their existing policies serviced, and reach claims support, and that none of that is interrupted by the cybersecurity attack. It adds one caveat: while the servicing experience “remains largely unchanged,” in TruStage's words, the online experience a member sees may look different for the time being, and the company is still refining it as systems come back. This is broader than what TruStage had previously put on the record. Its chief executive said in the July 23 video that Liberty Mutual and Polly were processing new business from direct-mail leads; the company is now describing the full policy lifecycle, servicing and claims included, as running without disruption. For credit unions this is one of the few product lines that can be discussed as working normally, which is worth knowing for staff fielding member questions. The credit-union page carries no date stamp, so the date recorded here is the date this tracker could verify the answer was publicly visible.
TruStage (credit union outage page)TruStage tells policyholders it is not behind offers to replace their insurance coverage
A new question has appeared on TruStage's individual outage page addressing policyholders who have been approached about replacing their insurance policy with another company's. TruStage answers plainly that such an offer does not come from the company, and states that it is not encouraging, facilitating, or taking part in any effort to replace, surrender, or discontinue coverage that is currently in force, either because of the cybersecurity incident or as part of its recovery work. The answer is worth passing along to members: an insurer's systems being offline is exactly the circumstance in which policyholders may be told their coverage is at risk and pressed to switch, and TruStage is now on record that it is not the source of those approaches. Credit unions fielding questions from members who have received such offers can point to this statement. TruStage did not advance the page's timestamp when the question appeared, which still reads August 6, so the company has not itself given a publication date; the date recorded here is the date this tracker could verify the answer was publicly visible.
TruStage (individual outage page)Wealth Management page says advisors and credit unions can reach Salesforce by direct login
TruStage has rewritten its Wealth Management Solutions outage page and answered a question it had been deferring since the outage began. Where the page previously said only that teams were working to bring systems back online, it now tells advisors and credit unions that they can get into Salesforce through a direct login, and points them to their assigned Advisor Manager Specialist or Regional Program Consultant for instructions. One caution worth passing to program staff: the page's own "What you should know" paragraph still says advisors cannot access Salesforce for client-specific notes, so the old and new statements now sit side by side on the same page without being reconciled. Treat the direct-login route as the newer of the two and confirm the scope with your TruStage contact rather than assuming full access. The page also adds a compensation answer for the second half of July, saying managed and dual advisors were paid on the regular schedule and credit unions received the same amount paid for the first half of July, which was based on the average of the six pay periods earned before July. Finally, the page has taken the mid-August recovery answer and the standard recovery lead that the other outage pages adopted on August 5, making it the last outage sub-page to catch up.
TruStage (Wealth Management Solutions outage page)TruStage adds direct deposit and income benefit forms to its annuity outage page
TruStage has extended the self-service annuity forms it introduced on August 4 with two further routes for contract owners. Owners can now submit a direct deposit form through the company's e-signature partner AssureSign to change where their deposits are sent, in separate single-owner and joint-owner versions, and a downloadable income benefit service form has been added for Zone Income Annuity and ZoneChoice Income Annuity contracts. The general resources block was also reorganized, with the transfer and allocation-change forms consolidated under a single heading and the claims link moved alongside them. In the same edit, the advisor resources block that pointed producers to their wholesaler was removed from the page. As with the forms added on August 4, these are workarounds rather than restored processing: online account access remains down, and TruStage has not said that requests submitted this way will be handled any faster than its recovery timetable allows.
TruStage (annuity outage page)TruStage rewrites its Retirement Solutions outage page, promising interim processes and dating the delayed benefit statements
TruStage's Retirement Solutions outage page was substantially rewritten under an August 6 timestamp, and the changes go beyond the recovery wording applied across the other outage pages. The company now says it will introduce temporary processes while recovery continues and that it is contacting plan sponsors as solutions become available for their plans. On payroll, the page previously stated flatly that files outside the third-party aggregator route could not be processed; it now says TruStage is working on an interim solution for those submissions and will share news with plan sponsors. On statements, the page has moved from an open-ended delay to specific commitments: quarterly paper statements for the period ended June 30, 2026 have been mailed, and participants who had elected electronic statements will instead be sent a paper statement, which TruStage says is in process and expected to be mailed the week of August 10, 2026. The company warns that some participants who had signed up for paper statements may receive a duplicate copy. Two items also came off the list of unavailable services: the sentence stating that the Participant Service Center phone and email system was unavailable no longer appears, and loan and distribution requests are no longer listed among the requests TruStage cannot accept. TruStage did not describe either removal as a restoration, and this tracker does not treat it as one.
TruStage (Retirement Solutions outage page)TruStage opens a mail-in service-forms page for individual life and AD&D policies
TruStage has added a new page to its outage site giving individual life insurance and accidental death and dismemberment policyholders a way to submit servicing requests while its systems are down. The page carries downloadable PDF forms covering changes of ownership, beneficiary changes, and general service requests such as billing-frequency changes, withdrawals, loans, and cancellation or surrender, with separate versions depending on whether the policy is issued by CMFG Life Insurance Company or MEMBERS Life Insurance Company and which digits the policy number begins with. Ownership changes must be accompanied by a completed W-9. TruStage instructs policyholders to print the form, complete and sign it, and mail it to the address printed on the form, and states that fax is not available at this time. The company says these requests will be processed as its systems are restored and that they will be honored dating back to the date the request was received. This is the first servicing route TruStage has published for individual life and AD&D coverage during the outage, and it parallels the annuity forms route added on August 4, though it is mail-based rather than electronically signed. TruStage did not advance the individual outage page's timestamp when the forms appeared, so the company has not itself stated a publication date; the page still reads August 5, 2026 | 4:48 PM CT.
TruStage (individual outage page — service forms)TruStage publishes a lump-sum continuity process for recurring Debt Protection benefit payments
TruStage's credit union outage page now carries two new answers describing how recurring Debt Protection benefit payments are being handled while its systems are down. The company says it began a temporary business continuity process on July 29 for credit unions whose members had already been approved for recurring benefit payments. Rather than issuing those payments individually, TruStage says it will pay a single lump sum that generally mirrors what the member received the previous month, adjusted where a benefit has since ended. Because the lump sum arrives without a member-level ledger, TruStage says a member of its claims team will contact each participating credit union directly with the payment detail needed to get the money to the right members. The company says it is starting the process proactively for credit unions that received six or more recurring member benefit payments in the previous month, and that credit unions below that threshold may ask the claims team to review a member they believe should have been paid. This is the first time the arrangement has appeared on TruStage's own public page; trade-press reporting in early August had described it only as a test running with a small number of credit unions.
TruStage (credit union outage page)TruStage rewrites its outage-page lead again and brings the credit union page into line
TruStage revised the opening paragraph across its outage pages and consumer FAQ, re-stamping the dated pages August 5 at 4:48 p.m. central. The new lead drops the sentence saying the incident had been contained since detection, and instead stresses the breadth of the impact across the company's network and systems, saying it is rebuilding portions of its infrastructure so services are restored safely and describing this as a deliberate approach that protects the people it serves as systems come back online. On the outage hub, the paragraph that had said the incident was contained and that TruStage was confirming no malicious code or bad actor remained was removed altogether. The containment statement itself has not been withdrawn: it still stands in the company's July 31 press release, which is unchanged. It simply no longer appears in the lead copy on the outage pages. Separately, the credit union page joined the rewrite it had sat out for two days. It now calls the event an attack rather than an incident, replaces its older passage about having shut all systems down with the same recovery language used elsewhere, adds the mid-August resolution answer already posted on the other pages, and sharpens its claims guidance to tell credit unions to file new claims through TruStage's online intake page. That page is still undated, and the status field across the site still reads Investigating.
TruStage (outage pages and consumer FAQ)TruStage adds e-signature annuity forms and an individual service hub while systems stay offline
Alongside the August 4 rewrite, TruStage expanded what annuity contract owners can actually do while its systems are down. The annuity outage page now offers electronically signed forms handled through a third-party partner, AssureSign, for cancelling a pending application, exercising the right to examine a contract, taking a partial withdrawal, and surrendering a contract in full — each in single-owner and joint-owner versions. A separate general-resources block carries downloadable transfer and allocation-change forms for the ZoneChoice, Zone, Horizon, and Variable Annuity products, and these are labelled as PDF downloads on TruStage's own page. The consumer FAQ has also been given a link to a new individual service hub covering claims, annuity resources, and retirement support. The practical effect for credit unions is that annuity owners who previously had no route to transact now have a forms-based one, though processing still depends on TruStage's restoration and the company continues to say transactions will be handled by the date and time received. Online account access remains unavailable.
TruStage (annuity outage page)TruStage rewrites its public outage pages: calls the event an attack, dates it to July 11, and puts the mid-August target on the pages themselves
TruStage revised every one of its dated public outage pages and its consumer FAQ on the morning of August 4, the first substantive rewrite of that language since the incident began. The company now calls the event a cybersecurity attack rather than a cybersecurity incident throughout, and states on the public pages that it was "identified on July 11" — a date it had previously given mainly through partner materials and press releases. The opening paragraph on each page has been replaced: instead of saying it proactively shut down its network and is working to restore it, TruStage now says it continues to make progress on recovery, that the attack has been contained since detection, and that it is rebuilding portions of its technology infrastructure and restoring systems in a controlled way. Its commitment line also changed, from working to determine the scope and impact of the incident to prioritizing a safe and responsible restoration. Most significant for members: a new question, on when this will be resolved, now appears on the business, retirement, and other outage pages, and answers with the mid-August target for the majority of key processes. That target had until now lived only in TruStage's July 31 press release, its CEO video, and emailed partner materials — it is now on the ordinary public pages members are sent to. The status field still reads Investigating everywhere, and TruStage still says it is premature to draw conclusions about whether any data was accessed.
TruStage (outage pages and consumer FAQ)TruStage's credit union outage page swaps in a new CEO video, and the outage pages re-stamp for the first time in three days
TruStage refreshed its credit-union-facing outage page and the rest of its dated outage pages on the afternoon of August 3, moving a stamp that had sat unchanged at July 31 for three days. The substantive change is on the credit union page, where the recorded update from chief executive Terrance Williams posted July 23 has been replaced by a new video. In it Williams describes the July 11 event as a broad attack on TruStage's network and systems, says the incident was contained and that the company is confirming no malicious code or threat actor remains as it rebuilds, and repeats the mid-August target for the majority of key processes with the caveat that systems may return before they are fully normal. He says workforce laptops have been refreshed and security measures updated, names Mandiant as the company's cybersecurity partner on the data investigation, and tells credit unions that TruStage still does not know whether member data was accessed and that partners will be the first to know if that changes. He also commits to email updates multiple times a week. The content matches TruStage's July 31 newsroom release; what is new for credit unions is that it now sits on the page they are directed to. Note that the July 23 video's material — including the account of an employee inadvertently downloading a malicious file and the NCUA reporting process — is no longer on the page; it remains recorded in this tracker's July 23 entry.
TruStage (credit-union outage page)Official: TruStage publishes member-letter and talking-point materials for credit unions, and puts the mid-August target in writing
TruStage has published two dated communications documents for its credit union partners, both stamped July 31, 2026 and hosted on trustage.com: an optional member and customer letter template that credit unions may adapt and send, and a talking points and FAQ sheet for staff who field member questions. Neither carries a confidentiality marking; the letter template is headed as optional and asks that it be shared with members and customers. Their significance for credit unions is that they are the first TruStage-published documents to state a restoration target. TruStage says it is "working toward being operational by mid-August," and defines that carefully: priority processes and services available through a mix of restored systems, interim processes, and alternative support paths, not every system immediately at full functionality, with temporary workarounds possibly remaining in place. Until now the mid-August timeline had appeared only in trade-press reporting of a CEO video, and it still does not appear on any of TruStage's public outage pages. On the recovery itself, TruStage says it stood up a clean, isolated technology environment segmented from systems that were impacted, potentially impacted, or still under investigation, that outside cybersecurity experts validated that environment using secure recovery practices, and that restored services are put through established validation before being introduced into production workflows. It describes the event in its own words as a cybersecurity attack that significantly impacted critical technology infrastructure. On data, the materials repeat that it is premature to draw conclusions about the full scope or impact of the incident, and commit that TruStage will work directly with credit unions and other partners if it determines data was compromised. The documents also summarize where progress has been made: claims reporting, expanded phone support including a third-party contact center, lending-related payment processes, and certain annuity and retirement processes, with recurring disbursements restored for customers who depend on periodic payments. TruStage notes that platforms with more system dependencies may take longer to fully recover.
TruStage (partner communications materials) PDF downloadOfficial: TruStage says the incident is contained, names Mandiant, and states the mid-August target on its own newsroom
TruStage published a second incident press release in its newsroom, dated July 31, 2026 and carried on its own URL separate from the July 24 update. It is the fullest public account the company has given. TruStage says the incident has been contained, that the event was broad enough that it rebuilt parts of its infrastructure so systems could be brought back safely rather than simply switched back on, and that as it rebuilds it is confirming there is no malicious code or bad actor left in its systems or network. It says employee laptops have been refreshed and security measures updated before staff re-engage with systems, and that this work is close to complete. On timing, TruStage states publicly for the first time that it anticipates the majority of its key processes will be operational by mid-August, prioritizing the operations most critical to partners and their members, while cautioning that some systems may come back before they are fully operational and that workarounds and alternate paths continue in the meantime. On data, it names Mandiant as the outside cybersecurity partner working with its internal teams on the investigation, says forensic work of this kind takes time, and states that it does not yet know whether member data was accessed — committing that if members' personal information turns out to be involved it will tell affected partners first and help them with any notification or reporting. It also commits to sending partners email updates multiple times a week. For credit unions this matters on three counts: the mid-August target is now an on-the-record public statement rather than trade-press reporting or emailed partner materials, the forensic firm is named for the first time, and TruStage says in its own words that the incident is contained.
TruStage (newsroom)Trade press: CEO tells credit union partners most key processes should be operational by mid-August; data question still open
CU Today reported on the evening of July 31 that TruStage president and chief executive Terrance Williams gave credit union partners a new video update in which he said the company anticipates the majority of its key processes will be operational by mid-August. Williams cautioned that systems coming back online may not be fully operational or fully back to normal. On the central open question he said the company does not yet know whether credit union member data was accessed, and told partners they would be the first to know if that changes. According to the report, customer calls are being handled through a third-party contact center, lending capability is in testing with eight credit unions, and annuity transactions, death claims, and withdrawals are moving again, with basic billing and claims servicing expected in the first half of August; the life insurance platform is described as more complex because it spans several interconnected systems, and broader systems remain offline. This is the first restoration timeline attributed to TruStage. As of this capture the mid-August timeline does not appear on any TruStage public page, and the company's credit union outage page, updated July 31, still says no product-specific claim payment timelines are available, so this is recorded as reported rather than confirmed.
CU TodayOfficial: TruStage expands its credit union FAQ — servicing and claims still limited, no product-level payment timelines
TruStage substantially expanded the FAQ on its credit-union outage page, adding a general outage section and a new set of answers written for credit union leaders. The most decision-relevant point for credit unions is that TruStage still cannot say when claims will be paid: it states that "product-specific claim payment timelines are not available" at this time, and that claims will be evaluated and paid under the applicable policy terms as operational capabilities are restored. It adds that its representatives can take customer inquiries and offer available guidance, but that some servicing and claims-related activities remain limited while systems are being brought back. On the question credit unions keep asking, TruStage repeats that it considers it premature to draw conclusions about the scope or impact of the incident, including whether any data may have been accessed. It restates that it is extending applicable grace periods and that more than one premium payment may come due during the extended period, that BenefitsForYou is still unavailable, and that annuity and retirement balances and benefits are unaffected. New for credit unions planning ahead: TruStage says the timing and approach for restarting marketing activity, including direct mail scheduled for August, is still under evaluation, and it will communicate lead-fulfillment plans separately. The page also replaced its question-submission form with a pointer to the credit union's account representative. Note that this page still carries no date stamp of its own, so this item is dated to the day the change was captured; the content appeared between midday and late afternoon on July 31.
TruStage (credit union outage page)Official: TruStage will extend grace periods, and warns it is not sending past-due payment notices
TruStage added two answers to its consumer service-disruption FAQ and to its individual and preplanning outage pages, first seen on the July 30 stamp. It now says that because payment processing is unavailable it will extend applicable grace periods once processing resumes, and cautions that depending on when a policy's premiums normally fall due, more than one payment may come due during the extended period. Policies that are active or in a grace period keep that status in the meantime. Separately, TruStage states that it is not currently sending communications requesting premium payments or telling customers a policy payment is delinquent, and it tells anyone receiving such a message not to click links, provide personal information, or submit payment information. That gives credit unions a concrete answer for members who call about a past-due notice during the outage.
TruStage (consumer service-disruption FAQ)Official: TruStage resumes some Retirement Solutions processing — aggregator payroll files and scheduled distributions
TruStage's Retirement Solutions outage page, re-stamped July 30 at 4:43 p.m. CT, reverses two answers that previously read as unavailable. Payroll files submitted in good order for 360 processing through third-party providers — the page names PayKonnect and Payroll Integrations — are now being processed, while other payroll file submissions remain unavailable. Previously scheduled installment and annuity distributions are also being processed again. The guidance to plan sponsors no longer tells them to withhold payroll files from TruStage; it now says to continue normal payroll operations, including withholding participant deferrals and loan repayments. Two limits are newly stated: participants who elected electronic benefit statements may see a delay for the quarter ended June 30, as will employers, and sponsors whose custodian or directed trustee is Matrix Trust Company can log in through Matrix / Broadridge for plan-level statements, an option that does not apply to Choice Group Variable Annuity plans. BenefitsForYou is still offline and participant transactions remain unavailable.
TruStage (Retirement Solutions outage page)TruStage publishes credit-union outage guidance: interim GAP and MRC processes, claims handling, and what can still be sold
TruStage's outage hub now includes a page written for credit unions. It says credit unions can still sell credit insurance, debt protection, and GAP, and directs members to start claims at trustage.com/startclaim. For interim processing it sets out the same business-continuity steps that reached us earlier through a state association, now stated by TruStage itself: eligible PAX credit unions may use the approved GAP workaround, must document every sale made during the outage, and must enter those sales into PAX once service is restored; a limited group of high-volume credit unions may use Assurant's GLOW platform to generate mechanical repair coverage quotes and member pricing and to finance the cost into the loan, with GLOW explicitly unable to issue contracts, so the official MRC certificate issues only after PAX is back and the sale is entered. Selected credit unions receive separate implementation instructions. For GAP claims and servicing, including a vehicle totaled before a contract can be completed in PAX, the instruction is to keep collecting claim details and supporting documentation while TruStage restores systems and issues further guidance. Note for the record: TruStage does not date this page, so the date shown here is the date the IT Department captured it, not necessarily the date TruStage posted it.
TruStage (credit-union outage page)TruStage: annuity and retirement balances are unaffected, and it has seen no unauthorized transactions on contract-owner funds
The annuity and retirement pages on TruStage's outage hub, both stamped July 28, 2026 at 10:43 a.m. CT, carry the most concrete reassurance the company has published so far. On annuities it says contract values, account balances, and benefits have not been impacted, that transactions will be processed by the date and time each request was received once servicing resumes, and that based on its investigation to date there is no evidence that contract-owner funds, the assets backing its annuity obligations, or any other company financial accounts were subject to unauthorized transactions. Owners can submit partial withdrawal and surrender forms through the company's e-signature partner in the meantime. On retirement plans it says account balances and plan benefits are unaffected while BenefitsForYou is offline, so participants cannot view balances, change contributions or investments, trade, update beneficiaries, or request loans and distributions, and the participant service center's phone and email are down. Plan sponsors are told not to submit payroll and contribution files, including through payroll aggregators, but to continue normal payroll operations and withholding, that Department of Labor guidance allows additional time to submit when the delay is the service provider's outage, and to keep records of processing dates, when files were ready, and outage communications. Previously scheduled installments and annuity distributions cannot be processed at present; quarterly participant statements for the quarter ended June 30 are being mailed on the normal schedule. On data, both pages still call conclusions premature.
TruStage (annuity and retirement outage pages)TruStage tells individual policyholders that coverage will not lapse during the outage
TruStage's outage pages for individuals and for preplanning coverage, both stamped July 28, 2026 at 10:43 a.m. CT and still showing status “Investigating,” answer the question front-line staff are most likely to be asked. The company says individual coverage status is not at risk during the outage: a policy that is active or in a grace period stays in that status until regular payment processing resumes, and policyholders can make or update payments once operations are restored. If someone dies during the disruption, the company says the claim will be processed and paid under the applicable policy terms once TruStage is able, with claims started at trustage.com/startclaim. The pages acknowledge that service representatives currently cannot see policy or account information, process transactions, or submit requests, and they publish a dedicated line for the outage, 844-958-8910, staffed Monday through Friday 8:00 a.m. to 5:30 p.m. CT and weekends 9:00 a.m. to 4:00 p.m. CT, with a warning that waits are longer than usual. On data, the answer is unchanged: the company calls conclusions about scope or impact premature.
TruStage (individual outage page)Wealth Management Solutions page states the NCUA reporting path and tells credit unions to take their own notification advice
TruStage's outage page for Wealth Management Solutions, stamped July 28, 2026 at 10:43 a.m. CT, is the page that spells out the regulatory mechanics in TruStage's own words. It says the NCUA is aware of the event, and that a credit union which determines the incident is reportable may satisfy that by calling the NCUA at 1-833-CYBERCU, or 1-833-292-3728, and leaving a voicemail, or emailing cybercu@ncua.gov, giving the credit union's name and stating that the report concerns the TruStage cybersecurity event. On whether a credit union must notify its regulators at all, TruStage does not advise: it says requirements depend on the credit union's own customer relationships, applicable law, and internal policy, and recommends consulting legal, compliance, and risk teams. Operationally, the page says the program's financial advisors can serve members through their LPL access and can sell and service every product except TruStage annuities, that advisors cannot reach Salesforce for client notes, and that an online option is now open for annuity partial withdrawal and surrender requests with processing still slowed by manual handling. It adds that advisor and credit-union compensation for the first half of July was paid on schedule using an estimate based on the average of the last six pay periods. On data, the answer is again that it is premature to share conclusions while the investigation is open.
TruStage (Wealth Management Solutions outage page)Trade press: TruStage partner FAQ names Mandiant, confirms regulator and NCUA notification, reports no threat activity since July 11
Credit Union Daily reported on July 27 that TruStage has issued an updated technical FAQ for its business partners about the July 11 incident. According to the report, TruStage says it notified law enforcement and engaged the forensic firm Mandiant, has made the NCUA aware of the event, and has notified applicable regulatory authorities. The company states it has seen no threat-actor activity since July 11, has identified no known Common Vulnerabilities and Exposures tied to the compromise, and has not observed the attacker interacting with files shared through third-party systems, portals, VPNs, or APIs connected to TruStage. It still will not say whether partner or credit union data was accessed or exfiltrated, and it declined to say when access began, how long the intruder remained, what type of attack occurred, or whether anyone has claimed responsibility; it also cannot yet give an individual credit union a written attestation about that credit union's data. The report notes that a credit union that determines the event is reportable may notify the NCUA by phone or email and reference the TruStage cybersecurity event. The underlying partner FAQ is dated July 20 and is marked proprietary and not for distribution, so this entry cites the published report rather than the document, and does not reproduce the technical indicators of compromise the document contains. None of these points appear on TruStage's public newsroom or consumer FAQ, which still show systems down and status “Investigating.”
Credit Union DailyTruStage opens a dedicated outage resource hub
TruStage stood up a central resource hub at trustage.com/outage to consolidate information about the cybersecurity incident and the resulting systems outage. Dated July 24, 2026, the page repeats that the company identified a cybersecurity incident affecting its environment, that systems remain down while teams work to understand the facts, and that outside cybersecurity experts and business-continuity plans are engaged. It routes individuals and businesses to service-specific hubs, claim filing, and retirement-solutions support, and lists the support line 1-833-374-1541. The hub gives no restoration timeline and no finding on whether any data was accessed, and continues to call conclusions about scope premature.
TruStageTruStage's own site now carries the CEO video confirming the July 11 detection, the likely cause, and a phased restart
TruStage's credit-union outage page carries a recorded update from chief executive Terrance Williams, posted to the company's YouTube channel on July 23, 2026. Speaking for the company, he says TruStage identified unusual activity on its network on July 11 and shut its systems down immediately to investigate, engaged outside cybersecurity experts to help contain and remediate, notified law enforcement, and will continue notifying regulatory authorities as appropriate. On cause, he says the company believes a member of its workforce may have inadvertently downloaded a malicious file while trying to install a legitimate tool, and that both the investigation and the recovery remain in progress. He describes restoration as beginning now and running in a phased, prioritized sequence over days and weeks, with some functions carried by tested workarounds, and says the company will “be methodical.” He also states that most credit-insurance and debt-protection products are running again, that Liberty Mutual and Polly are processing auto and home business from direct-mail leads, that a workaround for credit unions issuing GAP waivers is being rolled out, that bond and business-protection renewals and servicing are supported, that Compliance Solutions cloud products were not impacted, and that TruStage set up a streamlined NCUA process for credit unions that deem the event reportable. On data, he repeats that it is premature to draw conclusions about whether anything was accessed. This material had reached credit unions only through trade-press accounts until now; it is significant because it is TruStage stating it directly on a TruStage page.
TruStage (credit-union outage page)Trade press: second outlet reports the likely cause and lists business lines back in service
Credit Union Daily reported that TruStage traces the incident to an employee who, per the company, may have inadvertently downloaded a malicious file while attempting to install what looked like a legitimate tool. The outlet said CEO Terrance Williams described a phased restoration that began the week of July 21 and will run in a controlled, prioritized sequence over days and weeks, with manual workarounds covering some functions in the meantime; Williams was quoted saying the company would not "sacrifice quality, security or reliability for speed." The report lists most credit insurance and debt protection products, auto and home processing through Liberty Mutual and Polly, GAP waiver issuance, and bond and business protection renewals as operating, with cloud-based Compliance Solutions unaffected. It repeats that TruStage still calls it premature to conclude whether any data was accessed. This corroborates the CU Today account already on this page and adds the Liberty Mutual and Polly detail; none of it yet appears on TruStage's own newsroom or consumer FAQ, which still show systems down and status "Investigating."
Credit Union DailyTrade press: TruStage begins phased recovery; report points to a likely cause
CU Today reported that TruStage has entered a recovery phase and started bringing systems back online in what it described as a controlled, prioritized sequence expected to span the coming days and weeks. According to the report, most credit-insurance and debt-protection products are operating again, with temporary manual workarounds supporting some claims, GAP waivers, and bond and business-protection renewals; cloud-based Compliance Solutions were not affected. The outlet said investigators believe the incident began when an employee inadvertently downloaded a malicious file while trying to install what appeared to be a legitimate software tool, and that TruStage detected unusual network activity on July 11 and shut systems down to contain it. CEO Terrance Williams was quoted saying the company would 'be methodical,' noting not all systems would return at the same time; TruStage still calls it premature to say whether any data was accessed and says it is coordinating with outside experts, law enforcement, and regulators, including a streamlined NCUA reporting path for credit unions determining the incident is reportable. Separately, American Banker reported TruStage has seen no ransom demand and no threat-actor activity since initial discovery. These operational and cause details come from trade-press reporting and are not yet reflected on TruStage's public newsroom or consumer FAQ.
CU TodaySEC filings: MEMBERS Life annuity transactions suspended during outage
MEMBERS Life Insurance Company, a TruStage subsidiary that issues annuity contracts, filed prospectus supplements with the U.S. Securities and Exchange Commission on July 20-21, 2026 (Form 497 / 497VPU) disclosing that the TruStage cybersecurity incident has disrupted its operations. According to the filings, the company is temporarily unable to process a range of contract transactions — reported to include cash withdrawals, surrenders, systematic withdrawals, beneficiary changes, and death-claim payments — and cannot issue new contracts while systems are being restored; interim arrangements are offered for certain requests submitted by mail. The filings do not state that any non-public personal information was accessed, and no restoration date is given. Members holding TruStage annuity products may therefore see delays in these transactions.
MEMBERS Life Insurance Company (SEC Form 497 supplement)Consumer FAQ status stamp advances; restoration still under way
TruStage refreshed the status line on its consumer FAQ to July 19, 2026, 11:15 a.m. CT. The substance did not change: systems remain shut down while the company works to restore them, customers may still have trouble reaching accounts or completing transactions online, and TruStage says it is premature to draw conclusions about the scope or impact of the incident. No restoration date and no data-exposure finding were given.
TruStage Consumer FAQOnline claims page opened for filing during the disruption
TruStage opened an online form for consumers to begin a claim while systems are down, covering protected-loan, death-or-dismemberment, and business-protection claim types, and says it will follow up as soon as possible. Rather than collecting sensitive details, the form asks members to choose a relationship and a preferred contact time, and cautions users not to include policy, contract, account, or Social Security numbers.
TruStage Claims IntakeConsumer FAQ: systems proactively shut down, restoration underway
TruStage's consumer FAQ (marked last updated July 16) describes the situation as under investigation, with systems proactively shut down while restoration efforts continue. It warns that customers may have difficulty accessing account information, completing transactions, or submitting requests online, and specifically addresses delayed 401(k) access and how to file claims. TruStage said it would be 'premature to draw conclusions about the scope or impact' of the incident, including whether any data was accessed.
TruStage Consumer FAQTruStage provides update on cybersecurity incident
In an update posted to its newsroom, TruStage said it had activated its incident response and recovery protocols and engaged outside cybersecurity experts. With its systems still down, the company directed customers to newly launched resources: a consumer FAQ, an online page to start a claim, and a support line at 1-833-374-1541.
TruStage NewsroomCompliance Solutions says its cloud products are unaffected
TruStage Compliance Solutions posted a notice on its community portal saying it was aware of the cybersecurity issue TruStage had announced, and that its own cloud products were not affected. Clients were told they could keep using those applications as usual, and the notice repeated that the outage did not originate in Compliance Solutions technology. The notice did not address the cause or scope of the wider TruStage incident.
TruStage Compliance SolutionsOutage confined to TruStage products, not credit unions' core services
Coverager highlighted the downstream effect on a partner institution: First Commonwealth Federal Credit Union told members that TruStage was temporarily unavailable for GAP, mechanical repair coverage, and payment protection claims. The report noted the disruption was confined to TruStage products offered through the credit union and did not affect the credit union's own deposits, cards, ATMs, or online banking.
CoveragerTruStage shuts down portions of network in response to threat
Credit Union Daily reported that TruStage had voluntarily shut down portions of its network after detecting suspicious activity, triggering its incident-response protocols alongside third-party specialists. The outlet emphasized that TruStage had not indicated whether ransomware was involved or whether any customer or employee information had been accessed.
Credit Union DailyTruStage discloses incident and activates response protocols
TruStage disclosed that it had detected a cybersecurity incident affecting its environment and immediately activated its incident-response and recovery procedures. The company said it engaged outside cybersecurity experts to assist with containment, remediation, and recovery, and that the work remained ongoing. It said it was still establishing the facts and did not indicate whether any data had been accessed or name specific affected systems.
TruStage NewsroomCompliance Solutions service desk access restored
TruStage Compliance Solutions reported that Service Desk access was fully restored as of 3:20 p.m. ET on July 14, two days after the outage that began the morning of July 12. The team said it could again view and process the support tickets submitted while access was unavailable, and that those tickets would be worked in the order received. The notice did not say what caused the outage or whether it was related to the broader TruStage incident disclosed the following day.
TruStage Compliance SolutionsCompliance Solutions service desk went offline two days before disclosed incident
A notice on TruStage Compliance Solutions' community portal reported that as of 8:30 AM ET on July 12 a systems outage was preventing its team from accessing the Service Desk, delaying responses to support tickets. The notice said the outage was not related to Compliance Solutions technology and directed clients and partners to email support addresses instead. TruStage has not publicly said whether this outage is connected to the broader incident it disclosed on July 15.
TruStage Compliance SolutionsHow this page is maintained
This tracker is compiled by monitoring TruStage’s official newsroom alongside reputable credit‑union trade press, regional news, and peer associations. Official TruStage statements are logged as issued; third‑party reports are reviewed for credibility before they are added. Summaries are written in our own words — follow each source link for the full report.