Active incident

TruStage Security Updates

TruStage says it detected unusual network activity on July 11, shut its systems down, and is running a phased, prioritized restoration — rebuilding parts of its infrastructure rather than simply switching systems back on, out of a clean, isolated environment it says outside experts validated. Its public outage pages describe the event as a cybersecurity attack identified on July 11 and carry the company's target of having the majority of its key processes operational by mid-August; on August 5 those pages were rewritten again and no longer say in their lead that the attack has been contained, though TruStage's July 31 press release still does — a target that until now appeared only in its press release, CEO video, and partner materials. TruStage cautions that services returning by then may still run on temporary workarounds rather than at full functionality. It has stated a likely cause, an employee inadvertently downloading a malicious file, and says its cybersecurity partner Mandiant and its internal teams are still working to determine whether any data was accessed. It gives no product-specific claim payment timelines, and says some servicing and claims activities remain limited.

Last updated Aug 14, 2026 · Tracking since July 14, 2026 · 45 updates logged
Affected TruStage services
GAP claimsDisrupted
Mechanical repair coverage — contracts & claimsDisrupted
Payment protection claimsDisrupted
Premium payments — credit card & one-timeDisrupted
Online account access & transactionsDisrupted
Retirement plan servicing (BenefitsForYou)Disrupted
Retirement payroll files — other submissionsDisrupted
GAP waiver issuance (PAX workaround)Delays
Available (7): Credit insurance & debt protection · Auto & home — quotes, purchase, servicing & claims (Liberty Mutual, Polly) · Bond & business protection renewals · Retirement payroll files — 360 via aggregator (PayKonnect, Payroll Integrations) · Retirement scheduled installments & annuity distributions · Compliance Solutions service desk · Compliance Solutions cloud products

Statuses reflect TruStage’s most recent public updates.

For member credit unions

What your credit union can do now

01

Work from TruStage's credit-union page

trustage.com/outage/business/credit-union now carries TruStage's own interim GAP and mechanical-repair processes, claims handling, and what you can still sell. Check it before relying on secondhand summaries.

02

Use TruStage's member communication materials

TruStage has published an optional member letter template and a talking points and FAQ sheet for staff, both dated July 31, that credit unions may adapt and share. Run them through your own review and approval process first.

03

Expect claim delays — keep a log

Claims filed through TruStage may still be delayed. Keep collecting claim details and supporting documentation, and record member inquiries so each one can be followed up as systems return.

04

Point members to official sources

Send member questions to trustage.com/outage/individual, the claims-start page at connect.trustage.com/startclaim, and the outage line at 844-958-8910 — not to secondhand reports. Members with individual life or AD&D coverage who need a policy change can now use TruStage's mail-in service forms at trustage.com/outage/individual/service-forms.

05

Reassure members

This is a disruption at TruStage, not at your credit union. Deposits, cards, ATMs, and online banking are unaffected, and TruStage says annuity and retirement balances are unaffected as well.

06

Watch for phishing

Scams may reference the outage. TruStage says it is not currently sending premium-payment requests or past-due notices, and it will not ask members for passwords or account credentials by email or text.

Background

What this means for your credit union

TruStage — formerly CUNA Mutual Group — provides insurance and financial-services products that many credit unions offer their members. On its own outage pages the company says it identified unusual network activity on July 11, 2026 and shut its systems down to investigate, disclosing the incident publicly on July 15. It has since begun a phased restoration, and says the likely cause was an employee inadvertently downloading a malicious file while trying to install a legitimate tool.

The incident is at TruStage — not at your credit union

A disruption to TruStage products does not affect your credit union's own deposits, cards, ATMs, or online banking. For most credit unions the immediate effect is a service disruption, not a confirmed data breach.

Restoration has started, but it is phased

TruStage says systems are coming back in a controlled, prioritized sequence over days and weeks, that not all of them return at once, and that some functions are running on tested workarounds in the meantime. It says publicly that it anticipates the majority of its key processes will be operational by mid-August — which it defines as priority processes being available, not every system at full functionality.

Scope and impact are still open

TruStage has not said whether any member or credit union information was accessed, or whether ransomware was involved — it says its cybersecurity partner Mandiant and its internal teams are still working that out. Treat anything beyond TruStage's own statements as unconfirmed.

Brief your front-line staff

If your credit union relies on TruStage products, make sure staff know which services are affected, what interim processes exist, and where to direct member questions. We will keep this page current as TruStage and reputable outlets report.

Rumor control

What is known — and what is not

Confirmed by TruStage

  • TruStage says it identified unusual activity on its network on July 11, 2026 and immediately shut its systems down to investigate; its first public statement came July 15.
  • TruStage says the likely cause was a member of its workforce inadvertently downloading a malicious file while trying to install a legitimate tool. The investigation is still open.
  • TruStage says the incident has been contained. Because the event was broad, it rebuilt parts of its infrastructure rather than simply switching systems back on, standing up a clean, isolated technology environment segmented from systems that were impacted, potentially impacted, or still under investigation. It says outside cybersecurity experts validated that environment using secure recovery practices, restored services pass established validation before entering production workflows, and as it rebuilds it is confirming no malicious code or bad actor remains in its systems or network.
  • TruStage names Mandiant as the outside cybersecurity partner working with its internal teams on the data investigation, and says it notified law enforcement and continues to notify regulatory authorities as appropriate. It says it does not yet know whether member data was accessed; if it determines data was compromised it will work directly with credit unions and other partners, notifying affected credit unions first — before any communication with their members — and supporting them through any notification or reporting process.
  • Restoration is running in a phased, prioritized sequence, and TruStage says it is working toward being operational by mid-August, prioritizing the operations most critical to partners and their members. It defines that as priority processes and services being available through a mix of restored systems, interim processes, and alternative support paths — not every system immediately at full functionality, with temporary workarounds possibly remaining in place. The target appears in partner materials dated July 31 and has since been stated publicly — in a July 31 newsroom press release, in a CEO video on the credit union outage page, and, as of August 4–5, on its public outage pages.
  • Most credit-insurance and debt-protection products are running again; auto and home new business is processing through Liberty Mutual and Polly; bond and business-protection renewals are supported. Interim processes are published for credit unions: eligible PAX credit unions may use the approved GAP waiver workaround, and a limited group may quote mechanical repair coverage through Assurant's GLOW platform — quoting only, with contracts and certificates issuing after PAX is restored and the sale entered. GAP, mechanical repair, and payment protection claims remain disrupted; credit unions are told to keep collecting claim details and documentation.
  • TruStage says annuity contract values, balances, and benefits are unaffected, and that it has found no evidence of unauthorized transactions on contract-owner funds, the assets backing its annuity obligations, or other company financial accounts.
  • TruStage says individual coverage will not lapse during the outage: a policy that is active or in a grace period stays in that status until payment processing resumes. As of July 30 it also says it will extend applicable grace periods once processing resumes, and that more than one premium payment may then come due depending on the policy's normal payment schedule.
  • TruStage states it is not currently sending communications requesting premium payments or telling customers a policy payment is delinquent, and tells anyone who receives one not to click links, share personal information, or submit payment information.
  • Retirement plan balances and benefits are unaffected and BenefitsForYou remains offline, but as of July 30 TruStage says payroll files submitted for 360 processing through third-party aggregators (it names PayKonnect and Payroll Integrations) are being processed, other payroll submissions are not, and previously scheduled installment and annuity distributions are being processed. Sponsors are told to continue normal payroll operations and to document any outage-related delay.
  • As of July 31 TruStage says it cannot give product-specific claim payment timelines. Claims will be evaluated and paid under the applicable policy terms as operational capabilities are restored, and while representatives can take inquiries, some servicing and claims activities remain limited.
  • The NCUA is aware of the event. A credit union that determines the incident is reportable may report by calling 1-833-CYBERCU (1-833-292-3728) or emailing cybercu@ncua.gov, naming the credit union and referencing the TruStage cybersecurity event.
  • TruStage has published materials credit unions may adapt for member communication: an optional member and customer letter template and a talking points and FAQ sheet for staff, both dated July 31, 2026.
  • TruStage's public outage pages and consumer FAQ describe the event as a cybersecurity attack identified on July 11, rather than as a cybersecurity incident. On August 5 the opening paragraph was rewritten again: it now stresses the breadth of the impact across the company's network and systems and the rebuilding of portions of its infrastructure, and the sentence saying the attack had been contained after detection was dropped from that lead and removed from the outage hub. TruStage has not withdrawn the containment statement, which still stands in its July 31 press release; it no longer appears in the outage-page lead copy.
  • As of August 4, annuity contract owners can submit application cancellation, right to examine, partial withdrawal, and surrender requests through electronically signed forms on TruStage's annuity outage page, handled through its partner AssureSign, with downloadable transfer and allocation-change forms also posted. Online account access remains unavailable and processing still depends on restoration.
  • TruStage says that on July 29 it began a temporary business continuity process for credit unions whose members were already approved for recurring Debt Protection benefit payments. It says those payments are being issued as a single lump sum generally reflecting the prior month's recurring payments, adjusted where a benefit has ended, and that because the lump sum carries no member-level ledger its claims team will contact participating credit unions directly with the payment detail. TruStage says it is starting the process proactively for credit unions that received six or more recurring member benefit payments in the previous month, and that credit unions below that threshold may ask the claims team to review an individual member.
  • As of August 11 TruStage says recurring ACH premium payments are beginning to resume for some eligible customers using payment details already on file. Recurring credit card payments and one-time payments are still unavailable, and representatives cannot verify an individual customer's payment activity or policy status while account access remains limited.

Not yet known

  • Whether any member, customer, or credit union data was accessed — TruStage calls conclusions premature.
  • Whether ransomware was involved, and whether anyone has claimed responsibility.
  • How the attacker got in beyond the stated likely cause, when access began, and how long it lasted.
  • Firm dates for individual systems and products. TruStage's mid-August target covers its priority processes overall; it still gives no product-specific claim payment timelines and says platforms with more dependencies may take longer.
  • Whether the July 12 Compliance Solutions service-desk outage is connected to the broader incident.

No public evidence

  • No public evidence that credit unions' own systems, member deposits, cards, or online banking are affected.
  • No public evidence of misuse of member or credit union information.
  • No breach-notification filing for TruStage has appeared in any state attorney general database we have been able to enumerate, and no incident filing has appeared with the SEC.
Incident log

Timeline of updates

45 updates · newest first
Aug 13, 2026
Official · TruStageRestorationNew

TruStage tells credit unions a temporary process to resume GAP claim payments began August 12

A temporary process to resume GAP claim payments began August 12 — but only for claims established before the attack. Claims filed since, through the interim intake form, are not part of the process yet.

More detail

TruStage rewrote the claims and payments answers on its credit-union outage page (snapshots place the change between 4:01 and 7:04 p.m. ET), and one part has not appeared on any TruStage page before: a temporary process to resume GAP claim payments began Wednesday, August 12, covering open and pending claims established before the attack, with two payment options to be available. The page does not say what the two options are — expect to be told separately.

The limit matters as much as the restart: claims submitted after the attack through the claim intake form are not part of this process at this time. A credit union that filed through the interim intake route since mid-July should not read this as covering those claims. Otherwise the page repeats its position — representatives can take inquiries, some servicing and claims activity remains limited, and no product-specific claim payment timelines are available.

The same rewrite finally carries TruStage's August 12 billing detail onto the partner-facing page, closing a gap flagged yesterday: the August 4 ACH restart for certain life and AD&D policies, the late-July and August due dates being worked through, recurring card and one-time payments still unavailable, and card billing expected before direct bill. It mirrors the honored-by-date-received guidance for outage-period cancellations and changes, and routes life and AD&D changes to the mail-in forms page.

Two things did not move: the page remains undated, and it says nothing about the life and annuity call centers reported as due to open Friday, August 14.

TruStage (credit union outage page)
Aug 13, 2026
Trade pressRestorationNew

Trade press: TruStage says it is still on track for mid-August, and that answers on whether data was accessed are likely two to three months away

Trade press: TruStage says it remains on track for mid-August and claim payments have begun across business lines — and, for the first time with an interval attached, says the data question will likely take two to three months to answer.

More detail

Credit Union Daily reported a new TruStage recovery update in which president and CEO Terrance Williams said the company is making 'steady advancements in restoring our technology environment' and remains on track for most key processes by mid-August. Per the report: the retirement contact center has reopened and the life and annuity centers are due August 14; claim payments have begun moving across business lines, with the pre-outage backlog of life and accidental death claims prioritized; billing has resumed so coverage is not disrupted; and defined contribution participants may request withdrawals and loans by phone. Retirement and annuity account values remain unaffected.

On data, Williams reportedly said it will likely be two to three months before the company can say whether member or employee information was involved — the first time any interval has been attached to that answer.

The statement is undated and appears on no TruStage public page as of capture; TruStage's own pages were unchanged this morning, so this is recorded as reported rather than confirmed. TruStage's own August 12 email update to partners, received by the association on August 14, has since confirmed the account firsthand — see the entry logged for that update.

Credit Union Daily
Aug 12, 2026
Official · TruStageRestorationNew

Direct from TruStage: the August 12 partner update confirms the recovery picture firsthand, and adds preplanning claims to the restart list

The association has now received TruStage's August 12 partner update directly, converting this week's trade-press picture — call centers reopening, claim payments restarting, a two-to-three-month data timeline — into first-party confirmation. New in it: preplanning and funeral claims are being paid, and most defined-contribution participants can request account-balance updates by phone.

More detail

TruStage's August 12 email update to partners, signed by president and CEO Terrance Williams, reached the association directly on the morning of August 14. It confirms firsthand what this tracker had carried only through trade-press and peer-association relays: basic servicing targeted for mid-August, the retirement call center open with the life and annuity contact centers opening Friday, August 14, billing resumed so coverage is not disrupted, and Mandiant's confirmation of the clean, isolated environment built apart from impacted systems.

Two details had not appeared in any relay. Claims are being paid across the business including preplanning and funeral claims — alongside the GAP and debt-protection restarts already tracked — with life and AD&D processing still working pre-outage pending claims before newer submissions. And the majority of defined-contribution participants, other than those on certain legacy platforms, can request withdrawals and loans where their plan allows and ask for account-balance updates over the phone.

On data, the update repeats the two-to-three-month estimate for complete answers and the commitment to notify affected parties first if member or employee data is compromised.

Because this is a communication addressed to partners rather than a public page, this entry links TruStage's public credit-union outage hub instead of the email. None of this content appeared on TruStage's public pages as of this morning's sweep.

TruStage (credit union outage hub)
Aug 12, 2026
Official · TruStageRestoration

TruStage dates the ACH restart to August 4 and says late-July and August due dates are being worked through

TruStage dates the ACH restart to August 4 for certain life and AD&D policies and says late-July and August due dates are being worked through, with card billing expected back before direct bill. Changes and cancellations requested during the outage will be honored by date received.

More detail

TruStage re-stamped its dated outage pages on the afternoon of August 12 and used the individual page to put detail behind its billing position. The payment answer now carries a start date: recurring ACH premium collection began coming back on August 4 for certain life and AD&D policies, and TruStage is working through policies whose due dates fall in late July and August. Recurring credit card and one-time payments remain unavailable; TruStage expects card billing to return ahead of direct bill, which will take additional time.

That partially answers the eligibility question flagged as unanswerable on August 11 — it describes a scope, though still no way for a member or credit union to confirm whether a particular policy sits inside it.

Two new answers concern servicing: requests to change or cancel a policy submitted while systems were down may not yet be reflected in billing; TruStage will process them as capability returns and honor each by the date received. Life and AD&D changes are routed to the mail-in service forms page, itself reorganized the same evening.

Quieter changes worth flagging: the individual page shortened weekday outage-line hours from 5:30 to 5:00 p.m. CT (Saturday unchanged), and the credit-union page picked up none of the new billing language — staff should read the individual page directly. Status still reads Investigating.

TruStage (individual outage page)
Aug 11, 2026
Official · TruStageRestoration

TruStage says recurring ACH premium payments are beginning to resume for some customers

The first payment processing actually restarts: recurring ACH premium payments are resuming for some eligible customers using details on file. Credit card and one-time payments remain down, and there is no way to check whether a particular policy is in scope.

More detail

TruStage rewrote the payment section of its individual and credit-union outage pages late on August 11 (snapshots place the change between 4:25 and 6:12 p.m. CT). Recurring ACH premium payments are beginning to resume for some eligible customers, drawing on payment information already on file. Recurring credit card payments and one-time payments are still unavailable, and because account access remains limited, representatives cannot verify an individual customer's payment activity or policy status.

This is the first time TruStage has said any premium payment processing is actually restarting rather than promised for when systems return — a concrete restoration step. Read the scope carefully before passing it to members: one payment method, only 'some eligible customers' in TruStage's words, and no way for a member or credit union to find out whether a particular policy is in that group.

The individual page also restructured its coverage answer — customers will not lose coverage because they were unable to pay during the disruption; active and grace-period policies keep their status until normal processing resumes, with accommodations including extended grace periods to follow. The warning that TruStage is not sending premium-payment requests or past-due notices carries over and has been added to the credit-union page, so staff fielding a call about a suspicious notice can point to the page written for them.

Neither page advanced a date stamp for this change, and status across the outage family still reads Investigating.

TruStage (individual and credit union outage pages)
Aug 11, 2026
Official · TruStageOfficial Statement

TruStage's status page now calls the event a cybersecurity attack and replaces its technical FAQs with a new Investigation FAQs for vendors and partners

TruStage's status page now calls the event a cybersecurity attack and replaces its technical FAQs with a new Investigation FAQs document for vendors and partners — the consolidated channel for the vendor-management questions credit unions will be asked.

More detail

TruStage rewrote its outage-information status page. The heading now describes an actively investigated cybersecurity attack (previously incident), and the body matches the July 31 press release: the attack was broad, portions of the network and systems are being rebuilt rather than switched back on, and services restore in a deliberate sequence protecting employees, partners, members, and customers.

The closing pointer changed too: the Technical Incident FAQs reference that stood since July has been replaced by a new Investigation FAQs document dated August 10, described as answering vendors' and partners' questions about what happened, what steps TruStage has taken, what is known, and what remains under investigation. The link opens TruStage's document viewer displaying the four-page PDF rather than downloading a file.

Operationally nothing changes — status still reads Investigating and the mid-August target is unchanged — but the new document is TruStage's consolidated channel for the vendor-management questions credit unions are expected to ask their vendors after an event like this. It is linked under Resources below.

TruStage outage information page
Aug 11, 2026
Official · TruStageInvestigation-Cause

TruStage puts Mandiant on the record publicly: a new FAQ says the incident is contained and systems return to a clean environment

For the first time, TruStage's containment claim is sourced to its forensic firm: a new FAQ points to a public Mandiant memo saying the incident is contained and systems return to a clean environment. It is not a data-exposure finding, and Mandiant confines its findings to the scope of its investigation.

More detail

TruStage added the same new question to five of its outage pages and a matching line to the hub — the most substantive change in a week. The question: has a cybersecurity expert provided information on whether the incident is contained and whether TruStage is operating in a clean, safe environment as systems return? TruStage answers yes, says it continues to work closely with Mandiant, and directs readers to a Mandiant investigation memo dated August 10, published at a public address on TruStage's own site. The memo is linked under Resources below — a three-page PDF that downloads rather than opening as a web page.

Why this matters: TruStage has said since July 31 that the incident was contained, but that was TruStage speaking about itself. This is the first time the outside forensic firm's assessment is public under Mandiant's name — the first time the containment claim is sourced to something a reader can inspect.

On the question credit unions ask most, Mandiant writes that it has not observed the threat actor interacting with files shared with third parties, or with third-party systems, portals, VPNs, APIs, or other environments connected to TruStage. Read that with the limit Mandiant places on it: the preceding sentence confines its findings to the environments within its investigation's scope, and the memo does not define that scope. It is not an unqualified all-clear for every connected credit union system, and it says nothing about whether data was accessed — which TruStage still calls premature to judge. It does not replace your own review of any connection you maintain to TruStage.

It is also not a restoration announcement: every page still shows status Investigating and the mid-August target is unchanged. The five pages carrying the question are credit union, business, annuity, preneed, and retirement; individual and wealth management had not picked it up at capture. TruStage re-stamped the outage family August 11 at 12:13 p.m. CT alongside this change.

TruStage (credit union outage page)
Aug 11, 2026
Official · TruStageRestoration

TruStage reopens dedicated retirement phone lines and says its representatives can now do more

TruStage reopened dedicated retirement phone lines — 844-999-2677 for plan sponsors, advisors, and TPAs; 800-999-8786 for participants — and says representatives now have limited account access. A staffing improvement, not a systems restoration: BenefitsForYou is still offline.

More detail

TruStage improved the contact and servicing posture on its Retirement Solutions page. Where it previously said representatives could not access account information or process transactions, it now says they have limited access to account information and limited transaction capabilities. Two dedicated lines replace the general outage number: a Retirement Service Center at 844-999-2677 for plan sponsors, advisors, and third-party administrators, and a Participant Service Center at 800-999-8786 for participants — weekdays 8:00 a.m.-5:00 p.m. CT. Neither number had appeared on any TruStage outage page previously captured.

Two cautions for credit unions passing this along. This is a change in what staffed phone lines can do, not a systems restoration: BenefitsForYou is still offline, contribution and investment election changes, trades, and beneficiary updates still cannot be accepted, and status still reads Investigating. The new lines also carry narrower hours than the general line they replace, which ran to 5:30 p.m. weekdays and covered Saturdays.

TruStage did not advance the page's timestamp for this change, and the later August 11 family re-stamp accompanied a separate change — so the date recorded is the date this tracker verified the new language.

TruStage (Retirement Solutions outage page)

How this page is maintained

This tracker is compiled by monitoring TruStage’s official newsroom alongside reputable credit‑union trade press, regional news, and peer associations. Official TruStage statements are logged as issued; third‑party reports are reviewed for credibility before they are added. Summaries are written in our own words — follow each source link for the full report.

Official source

TruStage newsroom update

About this page. This page compiles publicly reported information about the TruStage cybersecurity incident for the situational awareness of our member credit unions. It is not an official TruStage communication, and it is not legal, security, or compliance advice. Details are evolving and some early reports may prove incomplete or inaccurate; always rely on TruStage directly for official guidance.

Print Friendly, PDF & Email