Credit unions, vendors are potential targets for cyberattacks, NCUA warns

The NCUA on Thursday warned credit unions that the ongoing conflict in Ukraine has raised concerns about potential cyberattacks in the United States, including those against the financial services sector.

All credit unions and vendors, regardless of size, are potential targets for cyberattacks, like social engineering and phishing attacks, and must remain vigilant, the NCUA urged.

Phishing attacks
Phishing is a technique that uses email or malicious websites to solicit personal information or to get victims to download malicious software by posing as a trustworthy entity. Another variant of phishing, known as smishing, uses SMS or other text messaging applications to get victims to click on malicious links to achieve similar goals to email phishing.

Mitigation tips to avoid phishing attacks:

  • be suspicious of unsolicited phone calls, visits, or email messages from individuals asking about employees or other internal information;
  • do not reveal personal or financial information in email, and do not respond to email solicitations for this information (this includes clicking on or following links sent in email);
  • if you are unsure whether an email request is legitimate, try to verify it by contacting the entity directly, by another means, such as the phone;
  • install and maintain anti-virus software, firewalls, and email filters to reduce some of this traffic;
  • take advantage of any anti-phishing features offered by your email client and web browser; and
  • use and enforce the use of multi-factor authentication.

The NCUA is encouraging credit unions to review the Cybersecurity and Infrastructure Security Agency’s Shields-Up website, which provides information about cybersecurity threats, including several resources and mitigation strategies. In addition, the NCUA recently created the Automated Cybersecurity Evaluation Toolbox, or ACET, for federally insured credit unions to use when evaluating their levels of cybersecurity preparedness.

Credit unions should report any cyber incidents to the NCUA, their local FBI field office or the Internet Crime Complaint Center and the Cybersecurity and Infrastructure Security Agency.

Leave a Reply