- Key insight: A month after the cyberattack, TruStage still cannot say whether anyone's data was taken, and it would not say whether it will meet its own mid-August target to restore most key processes.
- What's at stake: A credit union that uses TruStage is now a defendant itself, testing whether a member can hold her own institution responsible for a vendor's failure.
- Supporting data: A July 29 court order counted 13 class actions filed against TruStage in a single Wisconsin court since July 17, listing each case number. A 14th arrived the same day.
Overview bullets generated by AI with editorial review.
TruStage Financial Group shut down its own network a month ago to contain a cyberattack, and it still cannot say whether the intruders took anyone's data.
The Madison, Wisconsin, company sells life and auto insurance, retirement accounts and payment protection products through credit unions. It says
TruStage's
TruStage anticipates that "the majority of our key processes will be operational by mid-August, with priority placed on the operations most critical to partners and their members," the company said in a
Asked Wednesday whether it will meet that target, TruStage did not say. The company began processing and paying claims this week, about a month after the attack, a spokesperson told American Banker, including claims on guaranteed asset protection and "recurring debt protection and credit insurance benefits." (Guaranteed asset protection covers the difference when a totaled car is worth less than the loan against it.)
TruStage did not say which key processes remain down, or whether the services it has restored amount to the majority it promised by mid-August.
TruStage identified the attack on July 11 and responded by "proactively shutting down our network," a spokesperson said in a July 21 statement to American Banker. The company
The company updated its
Employee retirement accounts, mechanical repair claims, payment protection products and customer access to certain TruStage systems and support channels have all been disrupted, according to a credit union suing the company.
Bessemer System Federal Credit Union made those claims in an amended complaint July 31. Ten days before that filing, TruStage President and CEO Terrance Williams gave partners a sunnier account.
"Most" of the company's credit insurance and debt protection products were "up and running," he said in a
At least 14 proposed class actions are pending against the company in federal court in Wisconsin. One of those lawsuits also sues a TruStage customer — a credit union.
The credit union getting sued over the TruStage compromise
On July 20, MaryLou Peixoto of Lowell, Massachusetts,
Align is also based in Lowell; the case is in the Western District of Wisconsin because TruStage is based in that district.
The day before she sued the credit union, Peixoto's debit card got declined, according to her complaint. She found her account roughly $600 overdrawn and her most recent paycheck gone from it without her authorization.
This happened "as a direct and proximate result of the data breach," Peixoto alleged in the complaint, which asserts that financial account information was among what the intruders took from TruStage.
The complaint does not explain how information held by an insurance vendor turned into withdrawals from a checking account, and TruStage has not said what categories of member information sat on the systems the attackers reached.
Peixoto sued Align for negligence, breach of implied contract and unjust enrichment. She brought the same three counts against TruStage.
The complaint does not allege that Align's own systems got breached; it levels its negligence allegations at both defendants together, without naming anything the credit union did on its own.
Her theory is that she gave Align her information as a condition of membership, Align passed it to TruStage, and both owed her a duty of care over it, according to the complaint.
Every credit union that hands member information to a vendor does what the complaint says Align did.
An Align spokesperson did not immediately respond to a request for comment.
A TruStage spokesperson said in the July 21 statement that the company does not comment on pending litigation as a matter of policy. The company's statement Wednesday did not mention the lawsuits.
The other lawsuits against TruStage
TruStage faces at least 13 federal lawsuits in the Western District of Wisconsin, according to a
Five of those plaintiffs have
Bessemer System Federal Credit Union in Greenville, Pennsylvania,
Bessemer
Since the attack, the practice "has been unable to access or fund those retirement accounts," according to the amended complaint.
"Many" participants in defined contribution plans can now request an account balance over the phone, and "most" can request a loan or a withdrawal if their plan allows it, the TruStage spokesperson said Wednesday.
TruStage owes the court an answer to the Bessemer complaint on Sept. 24.
What TruStage has not said
TruStage has not identified an attacker, confirmed a ransom demand, or given a number for how many credit unions, businesses, or people the outage has touched. (American Banker asked the company for that number and did not get one.)
Bessemer's amended complaint alleges that intruders reached TruStage's systems "when a TruStage representative downloaded malware." The company's own account aligns with that.
TruStage believes "a member of our workforce may have inadvertently downloaded a malicious file while trying to install a legitimate utility," the spokesperson said Wednesday. Williams told partners the same in the video message.
TruStage has its cybersecurity partner Mandiant (a Google-owned firm) and its own teams investigating what the attackers reached, the company said in its July 31 update.
"While we do not yet know whether member data was accessed, if we determine that members' personal information is involved, we will let affected partners know first," TruStage said in that update.
It still has not made that determination. The investigation "remains ongoing and requires extensive analysis across multiple systems and sources," the spokesperson said Wednesday.
There will be things "we can't share in real time because the investigation is ongoing or because sharing too much detail could create legal, regulatory, security or operational risks," Williams told partners in the video message.
Regardless of whether the mid-August target holds, the credit unions, businesses and members suing over the outage face a long wait. TruStage does not have to answer the lead complaint until late next month, and no judge has yet ruled on whether the 14 cases will get combined.








