Research

    Credit Union and Community Bank Cyber Incident Report 2026: 539 NCUA Reports, One Vendor Breach Across 74 Institutions, and the New Exam

    Jeff SowellAugust 30, 2026
    Credit Union and Community Bank Cyber Incident Report 2026: 539 NCUA Reports, One Vendor Breach Across 74 Institutions, and the New Exam

    Credit unions and community banks sit in an odd spot in the cyber threat picture. They hold the same kind of data and money as the largest institutions, they run on a small number of shared vendors, and most of them have no full-time security leadership. This report pulls together what the regulators, the FBI, the breach filings, and the industry datasets actually show for 2024 through mid-2026. Every figure below is tied to a public source in the list at the end.

    Key findings

    • Federally insured credit unions reported 539 cyber incidents to the NCUA between May 1, 2024 and April 30, 2025, roughly four every business day. The prior reporting window (September 2023 to May 2024) logged 892.[1][2]
    • About 73 percent of reported incidents involved a third party, according to the NCUA's own analysis. The agency estimates that roughly 90 percent of industry assets, about $1.9 trillion, are managed or affected in some way by service providers it does not examine.[2]
    • When the 72-hour notification rule took effect in September 2023, the NCUA received 146 incident reports in the first month, about what it used to see in a year.[3]
    • One vendor breach can hit dozens of institutions at once. The November 2023 ransomware attack on Ongoing Operations took about 60 credit unions offline; the August 2025 Marquis Software breach exposed data held by 74 banks and credit unions, at least 672,000 people in state filings and by some counts more than a million.[4][5][6]
    • The largest single credit union breach of the period, Patelco (see our California breach report), was first reported at 726,000 people and later revised to 1,009,472. Attackers were inside the network for about five weeks before the ransomware fired.[7][8]
    • Notification is slow. Georgia Heritage FCU was hit in January 2025 and mailed member notices in January 2026. MemberSource CU in Houston was breached in June 2025 and notified members in May 2026.[9][10]
    • Across all industries, Verizon's 2026 DBIR found third-party involvement in 48 percent of breaches, up 60 percent year over year, and vulnerability exploitation overtook stolen credentials as the top entry point.[11]
    • The FBI's IC3 logged 1,008,597 complaints and $20.9 billion in losses in 2025, with financial services among the most targeted critical infrastructure sectors for ransomware.[12]
    • The examination ground shifted underneath all of this: the FFIEC retired its Cybersecurity Assessment Tool on August 31, 2025, and the NCUA's 2026 priorities add board-level cyber training and AI oversight to the Information Security Examination.[13][14]

    What the NCUA's own numbers say

    The NCUA publishes an annual Cybersecurity and Credit Union System Resilience Report to Congress. The 2025 edition, released in April 2026, states that from May 1, 2024 through April 30, 2025 credit unions reported 539 cyber incidents "related to ATM jackpotting, business email compromises and phishing attacks, ransomware, and third-party service providers."[1] The agency does not break that figure down by type, and it does not publish loss figures, so 539 is the whole of the public count.

    The prior report covered a shorter window with a bigger number: 892 incidents between September 1, 2023 and May 1, 2024, the first eight months the 72-hour rule was in force. That report also carries the statistic that matters most for a small institution: approximately 73 percent of all reported incidents were related to the use or involvement of a third party.[2]

    Two things explain the drop from 892 to 539. The first window included the immediate rush of reporting after a new rule, plus the fallout from a single provider outage that touched about 60 institutions in one week. The second is that the NCUA has since clarified what counts as reportable. Either way, four incidents a business day across roughly 4,400 federally insured credit unions is not a rounding error, and the third-party share has not moved.

    The NCUA has said for years that it cannot examine the credit union service organizations and vendors that its members depend on. Chairman Todd Harper put it this way after the 2023 outage: more than 60 percent of the cyber incidents reported to the agency involve third-party service providers and CUSOs, and "until this growing regulatory blind spot is closed, thousands of federally insured credit unions, tens of millions of consumers who use credit unions, and trillions in assets are exposed to high levels of risk."[4]

    The incidents that defined the period

    Ongoing Operations and FedComp, November 2023

    On November 26, 2023, a ransomware attack on Ongoing Operations, a cloud services provider owned by the CUSO Trellance, and on the core processor FedComp, took about 60 credit unions offline. Some were down for days. Members of affected institutions could not check balances or move money, and the NCUA had to remind the public that deposits remained insured up to $250,000.[4] The entry point was reported to be the Citrix Bleed vulnerability, which had a patch available at the time.[6]

    Patelco Credit Union, 2024

    Patelco, a $9 billion California credit union, is the largest single-institution breach of the period. An unauthorized party gained access on May 23, 2024. The ransomware was deployed on June 29, 2024, and customer-facing systems stayed down for about two weeks. The RansomHub group published the stolen data on August 15, 2024. Patelco's initial filing counted 726,000 people; a revised notice put the number at 1,009,472. Names, Social Security numbers, driver's license numbers, dates of birth, and email addresses were taken.[7][8]

    The detail worth sitting with is the five weeks between first access and the ransomware event. That dwell time is where a monitoring program earns its keep, and it is the window that most institutions under $1 billion in assets have nobody watching.

    Georgia Heritage Federal Credit Union, 2025

    Georgia Heritage, a $160 million credit union in Savannah (see our Georgia breach report for the state picture), was hit by ransomware on January 25, 2025 and discovered the intrusion on February 10. The breach affected 43,077 people and exposed an unusually broad set of data: names, addresses, dates of birth, driver's license and passport details, employment and financial account information, health information, and Social Security numbers. Consumer notices were mailed on January 15, 2026, almost a year after the attack, with a filing to the Maine Attorney General on April 17, 2026.[9]

    MemberSource Credit Union, 2025

    MemberSource, a $200 million credit union in Houston (one of the incidents behind our Texas breach analysis), was breached on June 3, 2025. The SafePay ransomware group claimed the attack on June 17 and said it had taken about 50 gigabytes of data. State filings put the number of affected Texans at 22,308. Members were notified in May 2026, roughly eleven months after the intrusion.[10]

    Marquis Software, August 2025

    Marquis is a Texas-based provider of analytics, CRM, compliance reporting, and marketing software to more than 700 banks, credit unions, and mortgage lenders. On August 14, 2025 attackers came through a SonicWall firewall to gain VPN access and then deployed ransomware. Marquis notified its institutional customers in late October, and state filings followed in December. The count stands at 74 banks and credit unions and at least 672,075 individuals in filings, with Minnesota's Blaze Credit Union alone reporting 253,000 members; some researchers put the total above 1.35 million. A breach letter from Community 1st Credit Union in Iowa indicates Marquis paid the ransom.[5][6]

    None of the 74 institutions were attacked directly. Their exposure came entirely through a vendor contract, which is exactly the pattern the NCUA's 73 percent figure describes.

    Alaska Air Group Federal Credit Union, 2026

    In March 2026 a third-party IT service provider used by Alaska Air Group FCU experienced an incident that potentially exposed personal and banking information for 10,705 people. The credit union discovered it on March 9 and mailed notices on April 16, a five-week turnaround that is the exception in this list rather than the rule.[9]

    The third-party problem, quantified

    The credit union numbers line up with the broader data. Verizon's 2026 Data Breach Investigations Report, covering more than 22,000 confirmed breaches between November 2024 and October 2025, found third-party involvement in 48 percent of them, up 60 percent from the prior year. The same report found that exploitation of software vulnerabilities, at 31 percent, overtook stolen credentials as the leading way in, and that ransomware appeared in 48 percent of breaches.[11] The Marquis firewall, the Citrix Bleed entry at Ongoing Operations, and the SonicWall path in dozens of Akira-family attacks all fit that shape: a known vulnerability on an internet-facing device, at a vendor, with a patch available.

    For a community institution the practical reading is simple. Your attack surface is your vendor list (our vendor risk assessment questions are a starting checklist). The core processor, the online banking platform, the marketing CRM, the disaster-recovery host, and the managed IT firm each carry your member data and each has its own patch cadence, MFA policy, and incident-response maturity. The NCUA cannot examine them for you. The banking regulators only reach the largest of them through the Bank Service Company Act.

    What the FBI sees

    The FBI's Internet Crime Complaint Center recorded 1,008,597 complaints in 2025, the first year over one million, and $20.9 billion in reported losses, up 26 percent from 2024. Ransomware complaints rose for a third straight year to 3,611. The FBI lists financial services among the critical infrastructure sectors most heavily targeted by ransomware, alongside healthcare, manufacturing, government, and IT, and names Akira, Qilin, INC Ransom, BianLian, and Play as the most reported variants.[12] The FBI's ransomware loss figure excludes downtime, remediation, and lost business, which for a credit union is where most of the cost lands; our cyber insurance guide covers what policies do and do not pick up.

    Texas ranks second nationally in both complaint volume and total losses. The state's Finance Code requires notification to the Attorney General for any incident affecting 250 or more Texas residents, which is why Houston's MemberSource shows up in the public record with a precise count.[15]

    The exam has changed

    Three regulatory shifts overlap with the incident data.

    The 72-hour rule. Since September 1, 2023, federally insured credit unions must notify the NCUA within 72 hours of reasonably believing a reportable cyber incident has occurred. The agency received 146 reports in the first month, about a year's worth under the old voluntary approach.[3] Banks have carried a stricter 36-hour requirement to their primary federal regulator since May 1, 2022.[16]

    The CAT is gone. The FFIEC retired its Cybersecurity Assessment Tool on August 31, 2025. Thousands of institutions had built their annual self-assessment around it. The FFIEC's replacement guidance points to the NIST Cybersecurity Framework 2.0, CISA's Cybersecurity Performance Goals, the Cyber Risk Institute's Cyber Profile, and the CIS Critical Security Controls, and is clear that the expectation of a documented self-assessment has not changed, only the tool.[13]

    The 2026 NCUA priorities. The Information Security Examination program enters its fourth year in 2026. The agency's priorities letter adds annual board-level cybersecurity training as a named exam item, keeps payment-system risk and vendor management in scope, and introduces oversight of artificial intelligence use.[14] Examiners will ask for evidence that directors received structured training, not just that a policy exists.

    What this means for an institution under $1 billion

    Most of the credit unions and community banks in this report have between 20 and 300 employees and no chief information security officer. The pattern in the incidents is consistent: a vendor or an edge device is the way in, weeks pass before anyone notices, and a year passes before members are told. The fixes are not exotic.

    • Know the vendor list and rank it. Every provider that touches member data or can reach the network gets a risk tier, an annual review, and a named owner, the same structure as a formal security risk assessment. The Marquis and Ongoing Operations incidents were vendor incidents first.
    • Patch the edge on a clock. Firewalls, VPN appliances, and remote-access gateways get a defined patch window measured in days. Every large incident above began at one of these.
    • Watch for dwell time. Five weeks at Patelco, sixteen days at Georgia Heritage. Detection is a monitoring problem, and monitoring is a staffing problem most small institutions solve with a managed service rather than a hire.
    • Rehearse the 72 hours. A written incident response plan, tested in a tabletop exercise, that names who decides an incident is reportable, who calls the NCUA or the FDIC, and who talks to members. The institutions that notified in five weeks had one; the ones that took a year did not.
    • Replace the CAT before the next exam. Pick one of the FFIEC-named frameworks (our NIST CSF guide for small organizations covers the most common choice), map last year's CAT results to it, and document the gap list. Examiners will ask.
    • Train the board and keep the record. An annual session built around the questions a board should be asking with minutes and attendance is now an exam item, not a nice-to-have.

    None of this requires a full-time CISO. It requires someone accountable for the program who has done it before, a few hours a month, and a system of record that keeps the vendor tiers, the patch evidence, and the board training minutes current between exams.

    Related from BlueRadius: what a fractional CISO costs for an institution this size, how a vCISO runs SOC 2 and audit programs, our virtual CISO service, and a free assessment that starts with the vendor list.

    Methodology and limits

    Incident counts come from the NCUA's annual reports to Congress and are as the agency published them; the NCUA does not itemize incidents by type or publish losses. Individual breach figures come from state Attorney General filings (Maine, Texas, Iowa, Minnesota) and the trade and security press that reported on them, and are cited per incident. Bank-side counts are not available because the federal banking agencies do not publish computer-security incident notification totals. Cross-industry statistics are from Verizon's 2026 DBIR and the FBI's 2025 Internet Crime Report. Where figures were later revised, the report gives both the original and the revised number.

    Sources

    1. NCUA, 2025 Cybersecurity and Credit Union System Resilience Report (April 2026)
    2. NCUA, Cybersecurity and Credit Union System Resilience Annual Report to Congress (June 2024)
    3. Cybersecurity Dive, Dozens of credit unions confront outages linked to third-party ransomware attack (December 2023), citing NCUA Chairman Harper on first-month report volume
    4. The Record, 60 credit unions facing outages due to ransomware attack on popular tech provider (December 2023)
    5. BleepingComputer, Marquis data breach impacts over 74 US banks, credit unions (December 2025)
    6. Cyberuptive, Credit Unions in the Crosshairs: 2024 to 2026 Breach Wave, compiling Maine and Minnesota filings, TechCrunch, and Twin Cities Business
    7. BleepingComputer, Patelco notifies 726,000 customers of ransomware data breach (August 2024)
    8. Comparitech, Patelco Credit Union increases ransomware data breach figure to over 1M people
    9. CUToday, Georgia Heritage FCU discloses data breach affecting more than 43,000 members (April 2026); CU Times, Credit unions in Georgia, Alaska hit by ransomware and data breach incidents (April 2026)
    10. CU Times, MemberSource CU breach exposes unencrypted data of 22,000 persons (May 2026); ClaimDepot, MemberSource data breach
    11. Verizon, 2026 Data Breach Investigations Report
    12. FBI Internet Crime Complaint Center, 2025 Internet Crime Report (April 2026)
    13. FFIEC, Cybersecurity Assessment Tool Sunset; OCC, Bulletin 2024-25
    14. NCUA, NCUA's 2026 Supervisory Priorities
    15. CoreRecon, Texas Credit Union Cyber Threat Brief 2026, citing FBI IC3 state rankings and Texas Finance Code Chapter 521
    16. FDIC, Computer-Security Incident Notification Final Rule (FIL-74-2021)

    Also from BlueRadius: the Accounting Firm Cyber Incident Report 2026, covering WISP enforcement and the breach filings across CPA and tax firms.

    credit union cybersecuritycommunity bank cybersecurityncuacyber incident reportthird-party riskransomwarevcisoffiec

    Related from the BlueRadius Library

    Sourced posts on adjacent topics, ranked by tag overlap.

    Related on Radius360

    Have a security story worth telling? We publish practitioner guest articles.

    Write for us

    Take the Next Step

    Ready to Strengthen Your Security Posture?

    BlueRadius delivers Fortune 500-grade protection for mid-market companies — virtual CISO leadership, 24/7 managed security, and compliance programs that actually close deals. Let's talk.