Overheated data center knocked 23 credit unions offline

Prudential Regulators Testify Before House Financial Services Committee
Kyle Hauptman, chairman of the National Credit Union Administration
Eric Lee/Bloomberg
  • What's at stake: Iberville Federal Credit Union in Plaquemine, Louisiana, the smallest institution among those identified, closed its doors during the outage.
  • Supporting data: American Banker identified 23 credit unions in 14 states that lost service, holding $2.56 billion in assets and roughly 200,000 members between them, using the NCUA's certified June 2026 call report data.
  • Forward look: Sharetec has not named the data center, and Ark Data Centers, whose network carries Sharetec's production systems, has not said whether one of its facilities lost cooling.

Overview bullets generated by AI with editorial review.

Processing Content

A data center cooling system failed last week, crippling credit unions in 14 states.

Some of the equipment affected by the overheating incident belonged to Sharetec, a Fort Wayne, Indiana, company that sells core processing systems to credit unions.

Sharetec told affected credit unions that the failure happened on Sept. 15 and that the company's backup systems did not have time to take over, according to notices those credit unions posted to their members.

Sharetec served more than 250 credit unions as of 2018, according to an American Banker brief from that year. The company has not said how many of its customers went dark last week.

Sharetec did not immediately respond to a request for comment.

American Banker identified 23 credit unions that lost service, based on notices they posted to members and local news reports. These credit unions experienced a variety of impacts; some could not tell members their balance, could not post transactions or, in at least one case last week, open at all.

Iberville Federal Credit Union in Plaquemine, Louisiana, closed its doors Sept. 18 because of the outage, according to WAFB, the CBS affiliate in Baton Rouge.

Iberville is among the smallest institutions affected, with $8.9 million in assets and 2,122 members. The NCUA also designates it a minority depository institution, a label for credit unions that serve mostly minority members.

The 23 credit unions American Banker identified collectively hold $2.56 billion in assets and have roughly 200,000 members between them, according to summer call report data from the National Credit Union Administration, or NCUA.

Which data center failed

Sharetec has not said which company operates the data center that failed, but its own public internet records point to one; the company's systems run on a network that belongs to Ark Data Centers, based in Cedar Rapids, Iowa.

Sharetec today is four companies merged into one; before 2020, Bradford-Scott Data of Fort Wayne, Data Systems of Texas, NDS-Sharetec of Maine and GBS-Sharetec of Ohio each sold and ran the same core system in its own region.

Evergreen Services Group, a private equity firm, bought all four and merged them into one between 2020 and 2022, according to Sharetec's website.

Online banking for each of the four still runs through its own front end, but all four sit on a single domain --- onlinecu.com. Sharetec holds the security certificate for that domain.

All four front ends resolve to one internet address, and that IP address falls in a range the American Registry for Internet Numbers (which hands out internet addresses in North America) assigns to Ark.

Sharetec's email routes through the same range, and the path that connects the company's network to the rest of the internet runs through Ark, according to public internet routing data.

Read more:

A spokesperson for Ark did not immediately respond to a request for comment.

Sharetec sits in an examination gap

Since 1962, the Bank Service Company Act has given the Office of the Comptroller of the Currency, the Federal Deposit Insurance Corporation and the Federal Reserve authority over bank technology vendors.

Specifically, that means any work a bank farms out is "subject to regulation and examination by such agency to the same extent as if such services were being performed by the depository institution itself," according to the statute.

In other words, bank regulators have the same authority to examine vendors that serve banks as they have to examine banks themselves.

The NCUA does not have the same authority, although it did for a brief time.

Congress gave the NCUA third-party examination power in 1998, in a law written to get financial institutions ready for the Year 2000 bug. However, unlike the bank regulators, the NCUA's authority to examine third-party vendors sunset on Dec. 31, 2001.

Since that expiration, the NCUA has advocated to get back third-party examination authority. As recently as 2024, the NCUA said in a report to Congress that a ransomware attack the previous year affecting 60 credit unions showed why it needed authority over vendors.

The NCUA appears to have since done an about-face and is no longer seeking authority to examine vendors.

Every year since 2015, the Financial Stability Oversight Council (the Treasury-chaired panel of federal financial regulators) has recommended that Congress grant third-party examination authority to the NCUA, the Federal Housing Finance Agency and other relevant agencies.

However, the council's most recent annual report, approved in December 2025, de-listed the NCUA from that recommendation.

The NCUA "has determined that it may have sufficient authority to monitor these risks through information sharing agreements," according to that report.

The change coincides with the launch of what the NCUA calls its Deregulation Project. Kyle Hauptman, the agency's chairman, described the project in written Senate testimony in February as capitalizing on "the opportunities created by the Trump Administration."

The agency has published nothing explaining which information-sharing agreements now suffice where they did not before.

A spokesperson for the NCUA did not immediately respond to questions about whether any of those agreements produced anything on the Sharetec outage.


For reprint and licensing requests for this article, click here.
Credit unions Regulation and compliance NCUA Core systems Risk management Vendor management Technology
MORE FROM AMERICAN BANKER
Load More