Bay Area Credit Union Struggles to Recover After Ransomware Attack

Tens of thousands of customers of Bay Area credit union Patelco remain without access to their accounts, following a crippling ransomware attack on the 88-year-old financial institution.
The June 29 attack forced the credit union to shut down several of its key banking systems in a measure to contain damage and remediate the issue.
Restoration Could Take Days In a July 2 update, CEO Erin Mendez said Patelco is currently working with third-party cybersecurity experts to restore affected systems expeditiously.
During the process it is likely that customers could experience intermittent outages at Patelco's ATMs as well.
Patelco boasts $9 billion in assets and 450,000 members nationwide, and ranks among the larger of the more than 4,500 federal insured credit unions in the US. Though it primarily serves communities in the Bay Area, San Jose, and Sacramento, Patelco's customers includes employees of more than 1,100 businesses throughout the country.
The ransomware attack impacted the credit union's online banking systems, and systems supporting its mobile app services and call center.
Customers were left without access to core electronic transactions such as direct deposit, transfers, balance inquiries, and payments.
A Common Pattern Patelco's travails - and the resulting impact on customers - are typical of major ransomware incidents.
Numerous reports, including one from Cigent and another from Statista, have pegged the average duration of downtime after a ransomware attack as ranging from 21 to 24 days.
That's marginally better than a couple of years ago, when it took ransomware victims an average of one month to recover from an attack.
Smaller organizations often tend to get hit much harder than large, better resourced organizations.
A new study by Orange Cyberdefense showed that organizations with fewer than 1,000 employees are four times more likely to experience a cyber-extortion attack compared to medium and large businesses.
When attackers launch opportunistic attacks, more smaller organizations get hit than large ones, the study found.
Another complicating factor is the growing tendency among ransomware actors to try and extort victims by stealing data from them and threatening to expose it.
Many extortion attacks these days in fact involve data theft only and not data encryption via ransomware.
As the UK National Cyber Security Centre recently noted, ransomware victims these days need to assume their data has been stolen as well.
A case in point is Memphis-based Evolve Bank & Trust, which recently was the victim of an attack by the LockBit ransomware group.
The threat actor encrypted some of Evolve's systems and exfiltrated a customer database, which it then leaked when the bank refused to pay the demanded ransom.
Patelco has not disclosed the identity of the group behind the ransomware attack on its systems.
It's unclear if the credit union will need to deal with the prospect of having both customer and other sensitive data being leaked as well.


This Cyber News was published on www.darkreading.com. Publication date: Wed, 03 Jul 2024 19:50:06 +0000


Cyber News related to Bay Area Credit Union Struggles to Recover After Ransomware Attack

10 Best Ransomware Protection Tools - 2025 - It protects devices from ransomware and other cyber threats using advanced threat intelligence, behavioral analysis, and cloud-based technology. It monitors and prevents ransomware assaults on personal files and automatically restores encrypted ...
2 weeks ago Cybersecuritynews.com
Ransomware attack on Patelco Credit Union causes confusion ahead of holiday weekend - One of the largest credit unions on the West Coast continues to struggle with its operations following a ransomware attack that began on Saturday. Patelco Credit Union - one of the nation's oldest credit unions with more than $9 billion in assets - ...
8 months ago Therecord.media
Bay Area Credit Union Struggles to Recover After Ransomware Attack - Tens of thousands of customers of Bay Area credit union Patelco remain without access to their accounts, following a crippling ransomware attack on the 88-year-old financial institution. The June 29 attack forced the credit union to shut down several ...
8 months ago Darkreading.com LockBit
Patelco Credit Union data breach impacted over 1 million people - The ransomware attack on Patelco Credit Union this summer led to a data breach affecting over 1 million individuals, revealed the company. Patelco Credit Union now provides an update on the incident and discloses that the data breach impacted ...
5 months ago Securityaffairs.com Ransomhub
Credit union operations restored after tech supplier ransomware attack - The federal agency that oversees credit unions said operations at about 60 of the organizations have been restored following a ransomware attack last month. Ongoing Operations, a cloud services provider owned by credit union technology firm ...
1 year ago Therecord.media Lorenz
60 US credit unions offline after cloud ransomware infection The Register - A ransomware infection at a cloud IT provider has disrupted services for 60 or so credit unions across the US, all of which were relying on the attacked vendor. This is according to the National Credit Union Administration, which on Friday told The ...
1 year ago Go.theregister.com
How a Regional Credit Union Reinvented Email Security with Votiro Cloud - Located in the southeast U.S., this regional Credit Union boasts over a million members across 100+ branches and handles over $10 billion in assets. They provide a comprehensive range of financial services from basic banking to insurance. If you'd ...
1 year ago Securityboulevard.com
American Airlines pilot union hit by ransomware attack - Allied Pilots Association, a labor union representing 15,000 American Airlines pilots, disclosed a ransomware attack that hit its systems on Monday. The APA union was founded in 1963 and is currently the largest independent pilots' trade union in the ...
1 year ago Bleepingcomputer.com LockBit Black Basta
Hive Ransomware: A Detailed Analysis - This past week, on January 26th, to be exact, the FBI successfully shut down the Hive ransomware group and saved victims over a hundred million dollars in ransom payments and remediation costs. As ransomware continues to be a national security threat ...
2 years ago Heimdalsecurity.com LockBit
The Week in Ransomware - With it being the first week of the New Year and some still away on vacation, it has been slow with ransomware news, attacks, and new information. Last weekend, BleepingComputer tested a new decryptor for the Black Basta ransomware to show how it ...
1 year ago Bleepingcomputer.com Inc ransom Qilin Mallox Black Basta
The Top 10 Ransomware Groups of 2023 - This article takes an in-depth look at the rise in ransomware attacks over the past year and the criminal groups driving the surge in cyber extortion. LockBit has established itself as one of the most notorious ransomware operations since emerging on ...
1 year ago Securityboulevard.com TA505 8base LockBit BianLian Medusa Noescape Black Basta
Ransomware Roundup - The Ransomware Roundup report aims to provide readers with brief insights into the evolving ransomware landscape and the Fortinet solutions that protect against those variants. This edition of the Ransomware Roundup covers the 8base ransomware. 8base ...
1 year ago Feeds.fortinet.com 8base
Medusa Ransomware Turning Your Files into Stone - Unit 42 Threat Intelligence analysts have noticed an escalation in Medusa ransomware activities and a shift in tactics toward extortion, characterized by the introduction in early 2023 of their dedicated leak site called the Medusa Blog. The Unit 42 ...
1 year ago Unit42.paloaltonetworks.com Medusa
Patelco shuts down banking systems following ransomware attack - Patelco Credit Union has disclosed it experienced a ransomware attack that led to the proactive shutdown of several of its customer-facing banking systems to contain the incident's impact. Patelco is an American credit union with assets exceeding $9 ...
8 months ago Bleepingcomputer.com LockBit Ransomhub
The Week in Ransomware - An international law enforcement operation claims to have dismantled a ransomware affiliate operation in Ukraine, which was responsible for attacks on organizations in 71 countries. The threat actors are said to be affiliates of numerous ransomware ...
1 year ago Bleepingcomputer.com Qilin Cactus Black Basta
Dozens of countries will pledge to stop paying ransomware gangs - An alliance of 40 countries will sign a pledge during the third annual International Counter-Ransomware Initiative summit in Washington, D.C., to stop paying ransoms demanded by cybercriminal groups. Addressing reporters on Monday, Anne Neuberger, ...
1 year ago Bleepingcomputer.com
Waiting for the BlackCat rebrand - We saw another ransomware operation shut down this week after first getting breached by law enforcement and then targeting critical infrastructure, putting them further in the spotlight of the US government. While the Tor onion domain seizure was a ...
1 year ago Bleepingcomputer.com Medusa Cuba STORMOUS
The Week in Ransomware - Attacks on hospitals continued this week, with ransomware operations disrupting patient care as they force organization to respond to cyberattacks. While many, like LockBit, claim to have policies in place to avoid encryping hospitals, we continue to ...
1 year ago Bleepingcomputer.com LockBit Cactus
Ransomware trends and recovery strategies companies should know - Ransomware attacks can have severe consequences, causing financial losses, reputational damage, and operational disruptions. The methods used to deliver ransomware vary, including phishing emails, malicious websites, and exploiting vulnerabilities in ...
1 year ago Helpnetsecurity.com
The Week in Ransomware - Governments struck back this week against members of ransomware operations, imposing sanctions on one threat actor and sentencing another to prison. On Tuesday, the Australian, US, and UK governments announced sanctions against Aleksandr Gennadievich ...
1 year ago Bleepingcomputer.com LockBit BianLian Akira Cactus
Targeting homeowners' data - As these companies obtain a large amount of sensitive information from their customers, they become attractive targets for ransomware gangs to conduct double-extortion attacks. Finland is also warning of Akira ransomware increasingly targeting ...
1 year ago Bleepingcomputer.com LockBit Akira
Ransomware's Impact May Include Heart Attacks, Strokes & PTSD - First-order harms: Direct targets of ransomware attacks. The increasing convergence of IT and OT leave physical infrastructures more vulnerable to ransomware, even though most ransomware operators lack the capability to directly compromise OT or ...
1 year ago Techrepublic.com
The Week in Ransomware - Today's column brings you two weeks of information on the latest ransomware attacks and research after we skipped last week's article. BleepingComputer has learned that some of the BlackCat/ALPHV affiliates are not buying the explanation and have ...
1 year ago Bleepingcomputer.com LockBit Qilin Noescape
The Week in Ransomware - Earlier this month, the BlackCat/ALPHV ransomware operation suffered a five-day disruption to their Tor data leak and negotiation sites, rumored to be caused by a law enforcement action. The FBI revealed this week that they hacked the BlackCat/ALPHV ...
1 year ago Bleepingcomputer.com LockBit Akira Noescape
Ransomware Roundup - On a bi-weekly basis, FortiGuard Labs gathers data on ransomware variants of interest that have been gaining traction within our datasets and the OSINT community. The Ransomware Roundup report aims to provide readers with brief insights into the ...
11 months ago Feeds.fortinet.com

Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)