CU Gives Advice On Preventing Ransomware Attacks

By Ray Birch

CYBERSPACE—How devious have some ransomware attacks become? For one credit union that’s been hit twice, it has even involved a dead member.

ransomware

That’s why that same credit union says that to battle growing ransomware attacks it takes a combination of employee training and technology.

An executive with the CU, who requested anonymity, told CUToday.info that the credit union learned that lesson the hard way, after experiencing two ransomware attacks this year within three months—one in the summer and the second in September.

Ransomware is a type of malicious software designed to block access to a computer system until a sum of money is paid. Crooks first use the malware to encrypt the contents of a victim’s computer and then extract a ransom in exchange for decrypting the data and allowing the victim to regain access. Losses to ransomware across the globe are in the hundreds of millions of dollars, experts say.

In this the second of a two-part series on a credit union hit by two ransomware attacks, the CU’s CIO shared with CUToday.info that employee education on safely using the Internet and email is paramount, as staff opening an email and clicking on an attachment led to both of its compromises.

More Aggressive Attack

While the credit union never considered paying either ransom demand, the second attack was a more aggressive virus, called Zepto, the CIO explained.

The executive said the September intrusion was “sneakier,” in that crooks may have had gathered intelligence on the credit union to craft its email message to fool an employee into opening it.

“We had a member who died, let’s say his name was Sam. The emails going back and forth between the family members and our employee addressed ‘Sam’ in their correspondence. Well, the employee who eventually opened the malicious email thought all of the business had been taken care of. But then two days later she gets an email from a ‘Samuel.’”

The credit union had been referring to the deceased member as ‘Sam,’ but the CIO said the employee thought the new email was using the late member’s formal name, and that the email included one final document to address.

“So she opened it and, boom, we got hit,” the CIO said.

But this time, instead of only eight computers affected—as was the case in the first ransomware bout—45 desktop computers and approximately 8,000 files on the file server were encrypted within 30 minutes.

“It moved fast—8,000 files on the server in a half hour,” he said.

Employee Uncovers Crime

The CIO said that again, like with the first attack, what uncovered the crime was the help desk assisting an employee and then noticing an unusual file extension in one of the directories.

“The IT employee said to herself, ‘What is .zepto?’ and then called our security officer,” explained the CIO. “He told her it was a virus. We immediately sent emails and made phone calls to staff telling them to immediately disconnect their computers from the network.”

But the ransomware spread too fast to keep it contained to a small number of PCs.

The CIO explained that unlike the first “Locky” ransomware attack, Zepto did not begin deleting previous emails, which in the first incident made it difficult to trace back exactly how the compromise occurred.

“This time we were able to trace this back, and we got the email and the attachment,” said the CIO. “That allowed us to do research on the malicious file and provide this information to the FBI and Secret Service.”

He said the credit union did not call in a forensic expert, as it did with the initial compromise.

“We felt our security officer had learned enough from the forensic expert who visited the credit union just a few months ago to conduct the research himself. Our security officer went through some training with the forensic analyst during the first ransomware incident, and we felt we could handle this attack ourselves. But if it got beyond our capabilities we would call the forensic expert in again.”

Holiday Gives CU More Time

The second attack happened the Friday before Labor Day. The CU assembled a tiger team to research every computer, and the team worked through the weekend.

“We replaced hard drives again and stored and labeled the infected drives in case we needed to go back and do forensics on them.”

The CU’s system administrator started identifying all of the infected files and what the credit union needed to do to get them back.

“We got lucky,” the CIO said.

The two major directories encrypted contained files that were either backed up the night before or contained files not essential to the business.

“One of the directories contained scans for branch capture images,” he said. “The attack occurred early in the morning so no new files had been scanned that day and the images from the previous day were already processed.”

While the credit union was fortunate, the CIO emphasized that getting the attack under control quickly, taking all computers offline, made the difference.

“That is why I don’t do cloud. If my data was in the cloud there is no way I can pull the plug, and no way I can do all of the research on the attack I need to do,” the CIO explained. “If my data is local, I can pull the plug on the PC or server if a server is impacted, but then I can walk up to that PC or server and still do research on it.”

Back To Normal

Having the three-day weekend helped the credit union get all employees whose PCs were hit by the virus back up and running by Tuesday. Their machines all had new hard drives reimaged to a baseline level that allowed them to work.

“They could use email, the Internet, access the core system—they had basic functionality,” he said. “We spent the rest of the week helping the employees restore shortcuts and install any special software they had on their PC before the ransomware incident.”

Two IT team members, too, worked side-by-side with the staff for the week to help with individual requests, like getting bookmarks or shortcuts back.

The Zepto attack was more sophisticated, the CIO explained. He said what was particularly concerning is that Zepto was able to jump from one VPN to another, which allows the malware to spread to a larger area.

“Most ransomware can’t jump from one VPN to another,” the CIO said. “But this one appeared to do that.”

Like in the first attack, the credit union’s investigation found the ransomware note in a file, this time demanding $8,000, instead of $450. The CU does not believe the two crimes are connected. And, like in the initial strike, member’s access to their accounts was not prevented, member data was not encrypted or compromised, nor was credit union business significantly affected.

$10,000 Ticket

Cost for the second compromise totaled about $10,000 as the forensic expert was not called in on this incident.

The CIO credited having ransomware in its business continuity planning—backing up the system regularly—for playing a big role in the credit union being able to shrug off both attacks.

But after these two assaults, the credit union is updating its ransomware defenses, both in new and ongoing training to prevent employees from opening malicious emails and clicking on attachments, and then adding a security solution to help detect and stop ransomware threats before they occur.

The credit union has contracted with security awareness training firm KnowBe4 to educate its staff.

ransomware

The two employees who clicked on the ransomware attachments have been with the CU for many years. He said that within the last year the credit union’s new employee training includes an hour on credit union security, which includes direction on avoiding opening emails from unknown sources, visiting unapproved websites, phishing attacks, clicking on attachments etc.

“What these two attacks tell us is that we have to go back and do remedial training with some of our more tenured staff, which is where we use KnowBe4,” he said.

The two attacks also showed the credit union that it is relying on its staff to detect ransomware threats. And while that was effective in the two attacks, the CU plans to automate ransomware detection and prevention.

He said the credit union is looking at solutions from CarbonBlack+Bit9 and Kaspersky.

The credit union is also looking at a new solution from AT&T partnered with Akamai, through which all employee Internet traffic can be routed. If staff go to a site that is known or suspected to have malware, the solution blocks that access.

“The employee gets a message and says their access has been blocked and to contact IT. That would most likely have prevented the two successful ransomware attacks on our credit union because both of the emails, when the employees clicked on the attachments, the attachments were reaching out to malware sites,” the CIO said. “This tool would most likely have identified the sites and blocked the employees’ computers right then.”

Huge Concern

The CIO said ransomware is a huge concern for his credit union and others. In conversations with credit unions at a recent technology summit, the CU learned that a number of credit unions have been hit with malware, as much as three and four times in one month.

“If I had to give one piece of advice to credit unions regarding ransomware it is educate your staff. That’s your number one line of defense,” the CIO said. “Educate your employees on an ongoing basis—but don’t make the training so regular that they begin become immune to it.”

Test staff, too, he said.

“Send them a fake message just like a crook would. Then, for those who open the message and click on the attachment, let them know they failed the test,” the CIO said. “I send them a message with a big skull and crossbones on it that says they failed and if this were a real ransomware attack that the credit union would have been infected. I can now identify employees who are likely clicking on suspicious emails and put those employees through remedial training.”

Section: Standard
Word Count: 1999
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto.flux5.ccplatform.net/THE-feature/CU-Gives-Advice-On-Preventing-Ransomware-Attacks