CU Hit With Two Attacks In 3 Months

By Ray Birch

CYBERSPACE—One credit union, hit by its first bout with ransomware this summer, said it was not shocked it was attacked again in the fall.

image

An executive with the CU, who requested anonymity, told CUToday.info that many other credit unions are also being hit with malware, with some getting hit by ransomware attacks two or three times in one month.

In this the first of a two-part series, the credit union’s CIO shares what the credit union experienced, how the crooks got in, and how it responded. In part two, the credit union shares what it has learned as it has now dealt with two such attacks.

Ransomware is a type of malicious software designed to block access to a computer system until a sum of money is paid. Crooks first use the malware to encrypt the contents of a victim’s computer and then extract a ransom, in bitcoins, in exchange for decrypting the data and allowing the victim to regain access. Losses to ransomware across the globe are in the hundreds of millions of dollars, experts say.

These losses are spread throughout all business sizes. In fact, several security firms report that ransomware targets smaller businesses at a rate eight times higher than that of their larger counterparts. These attacks are on the rise, with some saying they will become as prevalent as distributed denial of service (DDoS) attacks in 2017.

A report from a credit union hit by two ransomware attacks in 90 days confirms credit unions are squarely in fraudsters’ crosshairs.

Crooks Target CU

The credit union that spoke to CUToday.info described how it was targeted, how it handled the threats, and what it has learned to help prevent and lessen the impact of ransomware attacks.

The chief information officer from the credit union confirmed that the attacks are increasing and that inexpensive ransomware kits, easily and inexpensively available on the ‘Dark Web,’ are attracting more crooks to this form of extortion.

The CU, which did not pay the ransom demands, said that ransomware threats can be prevented, and the attacks managed at some cost if they occur. The CIO said there are security solutions to help the credit union better defend against ransomware attacks, as opposed to relying on the IT team to be monitoring on a 24/7 basis.

But what the CIO emphasized most is that employee training is the key to stopping ransomware from getting inside the credit union in the first place, as staff mistakes are the primary reason these attacks are successful.

“That was the case at our credit union,” the CIO said. “In both instances, it was an employee clicking on an e-mail and then opening an attachment that led to the attacks.”

He said that although the attacks came close together, the credit union believes they were not executed by the same thieves. “Both were different forms of ransomware,” the CIO said

First Attack

In July, the credit union was hit with the first attack. The CIO explained that the large credit union learned of the threat when an employee called the help desk and said she was having a problem running an end-of-day process on a specific server. IT then called the vendor that supports that server and the vendor remoted in. The vendor searched through the server but did not find anything suspicious.

“Then my security person ported in, and in less than five minutes identified that system files on one PC had been encrypted with a .locky extension. This form of ransomware is commonly known as ‘Locky,’” the CIO explained. “He then immediately disconnected the vendor since we didn’t know if the threat came in through them.”

The CU’s security expert notified the CIO, and the credit union quickly disconnected the server linked to the infected PC, as well as the PC itself, from the network. The credit union continued investigating its system and found eight more computers had been infected, all with connections to the same server. Those were pulled from the network.

“We called our managed security service provider, because they have forensic engineers,” the CIO said. “They asked us to begin imaging the infected hard drives, and one of their experts flew in the next day.”

The forensic expert spent two days on site conducting an extensive investigation on the infected desktops and on the system. The credit union learned that the server connected to the infected PC had not been compromised.

“So it was only the eight desktops within one business unit,” the CIO said. “We pulled those hard drives and replaced them with reimaged hard drives from backup data, bringing staff who use those computers up to a baseline working level.”

ransomware

Employee Error

As the CIO explained, the credit union was able to pinpoint the PC, and the employee, that led to the infection.

“We were able to figure out that the employee had opened an e-mail and then opened an attachment,” the CIO said. “What was unusual about this attack is that the virus began deleting log files and actually deleted about an hour’s worth of e-mails. So while we were able to discern what happened, we could not recover the exact e-mail with the attachment that let the crooks in, which made this more difficult to trace back to the originating host.”

The threat turned out to be small—the crooks were only asking for $450—and the credit union contained the attack quickly, never considering paying the ransom.

“We had everything cleaned up in about two business days. Our impacted employees were back online, the server was back online, and we simply continued to monitor our system closely to make sure no other computers were infected.”

The CIO said cost to the credit union was about $24,000—to pay for the forensic expert, the new hard drives and staff time. No member data was compromised, there was no lengthy employee downtime, and business was not interrupted.

CU Got Lucky

The CIO believes the credit union was fortunate, because an employee reported a problem running a program and that led to early discovery of the threat. The credit union never saw a ransom note pop up. Instead, the CU found an HTML file with the ransom note as it was investigating the attack.

Another key to controlling the attack is that it was contained to only one business unit at one branch location and eight PCs.

“We took that entire location down from the network. And as we investigated we brought the branch back up. That way we kept this under control,” he said.

The CIO believes what would have been a demand for a small amount from a financial institution is likely a sign the crooks were novices and that they might be testing the ransomware. Experts have stated that criminals are testing ransomware on smaller businesses because they have fewer layers of protection.

The CIO said that is also a sign that more criminals are turning to ransomware, even the inexperienced crooks, as ransomware kits have become less expensive.

Lesson Learned

The credit union learned a lot from the first attack, which helped it address the second threat, one that was more widespread and demanded a lot more money from the credit union.

Read part two of the story tomorrow to find out how the credit union managed the second attack, and what it has learned about defending against this growing threat—including why storing data in the cloud might be a problem for the CU when ransomware strikes.

Section: Standard
Word Count: 1478
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto.flux5.ccplatform.net/THE-feature/CU-Hit-With-Two-Attacks-In-3-Months