{"id":4330,"date":"2024-07-03T14:24:45","date_gmt":"2024-07-03T19:24:45","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/bay-area-credit-union-struggles-to-recover-after-ransomware-attack"},"modified":"2024-07-03T14:24:45","modified_gmt":"2024-07-03T19:24:45","slug":"bay-area-credit-union-struggles-to-recover-after-ransomware-attack","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/03\/bay-area-credit-union-struggles-to-recover-after-ransomware-attack\/","title":{"rendered":"Bay Area Credit Union Struggles to Recover After Ransomware Attack"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt7206e96d35e7dd70\/6685a8d6ff9e0e67638b95e2\/patelco%281800%29_Chiociolla_shutterstock-1.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/bay-area-credit-union-struggles-to-recover-after-ransomware-attack.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/bay-area-credit-union-struggles-to-recover-after-ransomware-attack.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Tens of thousands of customers of Bay Area credit union Patelco remain without access to their accounts, following a crippling ransomware attack on the 88-year-old financial institution.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The June 29 attack forced the credit union to shut down several of its key banking systems in a measure to contain damage and remediate the issue.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Restoration Could Take Days\">Restoration Could Take Days<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.patelco.org\/securityupdate\" rel=\"noopener\">In a July 2 update<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, CEO Erin Mendez said Patelco is currently working with third-party cybersecurity experts to restore affected systems expeditiously. During the process it is likely that customers could experience intermittent outages at Patelco&#8217;s ATMs as well. &#8220;This is normal and to be expected during our recovery process,&#8221; Mendez said. &#8220;Access to shared ATMs will not be interrupted as part of this process and they remain available for cash withdrawals and deposits.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Patelco boasts $9 billion in assets and 450,000 members nationwide, and ranks among the larger of the more than <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/ncua.gov\/newsroom\/press-release\/2023\/credit-union-assets-shares-and-deposits-grow-fourth-quarter#:~:text=The%20number%20of%20federally%20insured,%2C%20state%2Dchartered%20credit%20unions.\" rel=\"noopener\">4,500 federal insured credit unions<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in the US. Though it primarily serves communities in the Bay Area, San Jose, and Sacramento, Patelco&#8217;s customers includes employees of more than 1,100 businesses throughout the country.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The ransomware attack impacted the credit union&#8217;s online banking systems, and systems supporting its mobile app services and call center. Customers were left without access to core electronic transactions such as direct deposit, transfers, balance inquiries, and payments. &#8220;Our teams are working around the clock with top-tier cybersecurity experts to assess the situation and to restore service to you,&#8221; Patelco said. &#8220;Unfortunately, we are unable to provide an ETA on when those systems will be running as expected.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Common Pattern\">A Common Pattern<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Patelco&#8217;s travails \u2014 and the resulting impact on customers \u2014 are typical of major ransomware incidents. Numerous reports, including <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cigent.com\/resources\/blog\/ransomware-and-recovery-time-what-you-should-expect#:~:text=Ransomware%20attacks%20are%20not%20just,ransomware%20is%20about%2021%20days..\" rel=\"noopener\">one from Cigent<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.statista.com\/statistics\/1275029\/length-of-downtime-after-ransomware-attack-us\/\" rel=\"noopener\">another from Statista<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, have pegged the average duration of downtime after a ransomware attack as ranging from 21 to 24 days. That&#8217;s marginally better than a couple of years ago, when it <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/ransomware-crisis-deepens-data-recovery-stalls\" rel=\"noopener\">took ransomware victims an average of one month<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to recover from an attack. &#8220;Whether you pay the ransom and manage to decrypt your original data or restore from backup, recovery can be a lengthy process,&#8221; Cigent noted in its report. &#8220;They involve rebuilding systems, addressing security vulnerabilities, and regaining stakeholder trust, with recovery duration varying based on the attack\u2019s complexity, scope, and the affected organization&#8217;s preparedness.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Smaller organizations often tend to get hit much harder than large, better resourced organizations. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.orangecyberdefense.com\/global\/news\/research\/orange-cyberdefense-releases-cy-xplorer-2024\" rel=\"noopener\">A new study by Orange Cyberdefense<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> showed that organizations with fewer than 1,000 employees are four times more likely to experience a cyber-extortion attack compared to medium and large businesses. A lot of it simply has to do with the fact that there are many more small businesses than large ones. So, when attackers launch opportunistic attacks, more smaller organizations get hit than large ones, the study found.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Another complicating factor is the growing tendency among ransomware actors to try and extort victims by stealing data from them and threatening to expose it. Many extortion attacks these days in fact involve data theft only and not data encryption via ransomware. As the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.ncsc.gov.uk\/blog-post\/whats-happened-data\" rel=\"noopener\">UK National Cyber Security Centre (NCSC) recently noted<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, ransomware victims these days need to assume their data has been stolen as well.&nbsp;&#8220;In the &#8216;least-worse case&#8217; scenario, only system data (that is, data involved in the operation of a victim&#8217;s IT processes) will be stolen,&#8221; the NCSC said. &#8220;In the worst case, extremely sensitive personal information (such as medical or legal details) is exfiltrated.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A case in point is Memphis-based Evolve Bank &amp; Trust, which recently was the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/fintech-frenzy-affirm-and-others-emerge-as-victims-in-evolve-breach\" rel=\"noopener\">victim of an attack by the LockBit ransomware group<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. The threat actor encrypted some of Evolve&#8217;s systems and exfiltrated a customer database, which it then leaked when the bank refused to pay the demanded ransom.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Patelco has not disclosed the identity of the group behind the ransomware attack on its systems. And no threat actor has claimed responsibility for it thus far. So, it&#8217;s unclear if the credit union will need to deal with the prospect of having both customer and other sensitive data being leaked as well.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/bay-area-credit-union-struggles-to-recover-after-ransomware-attack\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Tens of thousands of customers of Bay Area credit union<\/p>\n","protected":false},"author":12,"featured_media":4331,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4330","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/bay-area-credit-union-struggles-to-recover-after-ransomware-attack.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/bay-area-credit-union-struggles-to-recover-after-ransomware-attack.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/bay-area-credit-union-struggles-to-recover-after-ransomware-attack.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/bay-area-credit-union-struggles-to-recover-after-ransomware-attack.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/bay-area-credit-union-struggles-to-recover-after-ransomware-attack.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/bay-area-credit-union-struggles-to-recover-after-ransomware-attack.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/bay-area-credit-union-struggles-to-recover-after-ransomware-attack.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/bay-area-credit-union-struggles-to-recover-after-ransomware-attack.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/bay-area-credit-union-struggles-to-recover-after-ransomware-attack.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/bay-area-credit-union-struggles-to-recover-after-ransomware-attack.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/bay-area-credit-union-struggles-to-recover-after-ransomware-attack.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4330","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4330"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4330\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4331"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4330"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4330"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4330"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}