← All News

TruStage Plans Grants For Members Hurt By Cyberattack As CEO Says Company ‘Fell Down’

By CU Today Staff —

MADISON, Wis.— TruStage is developing a fund that would provide grants—not loans—to credit union members who suffered financial hardship because of its cyberattack, President and CEO Terrance Williams revealed Friday, while acknowledging the company has “fallen down” on its promise to policyholders and has not been the partner credit unions expected during the two-month disruption.

The disclosure was among several significant new details Williams provided in TruStage’s longest video communication to credit union partners since the July 11 attack. During a wide-ranging fireside chat with TruStage board member Mike Valentine, CEO of Baxter Credit Union, Williams also provided new recovery windows for several operations, said TruStage expects the incident to affect its financial results in both 2026 and 2027, and said investigators expect it will still take at least another two months to determine whether credit union member data was compromised.

Perhaps the most consequential new announcement for affected members was what Williams described as a still-developing “member assistance fund.”

“We are working on what we're calling kind of a member assistance fund,” Williams said. “This member assistance fund is really going to be meant to provide grants to those who are in need due to this incident.”

TruStage President and CEO Terrance Williams (L) sits down with TruStage Board Member Mike Valentine to discuss the latest developments in the company’s recovery from the July cyberattack and its impact on credit unions, customers and services.

Williams stressed the payments would be grants rather than loans or benefits provided under an insurance policy. The program is intended for members who can demonstrate hardship directly resulting from the cyberattack, although TruStage has not yet announced eligibility requirements, grant amounts or when the fund will become available.

The announcement comes after CUToday.info previously reported that consumers have experienced missed insurance payments, inaccessible retirement funds, delayed disability benefits and problems collecting life-insurance proceeds following deaths in their families. Credit unions have also been forced to field member complaints and develop manual workarounds while lacking control over TruStage's affected systems.

Williams offered some of his strongest acknowledgments yet of TruStage’s shortcomings during the incident.

“We sell a promise that during your time of need we will honor that promise with financial dollars,” Williams said. “And we've fallen down in that regard. We haven't been able to do that in many instances over the last several weeks.”

TruStage has resumed paying claims and has extended grace periods, is developing flexible payment arrangements and intends to provide refunds to customers who tried to cancel policies while systems were unavailable, according to Williams.

He also directly addressed criticism from credit unions over TruStage’s communications and its handling of the recovery.

“I'm disappointed in the fact that over the past several weeks we have not lived up to that standard about being a true partner,” Williams said, citing the manual work, workarounds and member calls that credit unions have been forced to handle. “I regret the fact that we haven't lived up to what I'll call system partner status over the last several weeks.”

Williams said TruStage has changed its communications strategy in response to criticism from credit union CEOs, including providing more regular operational updates. He said his own relative absence from industry events has resulted from concentrating on recovery, although he said he speaks with credit union CEOs nearly every day. TruStage is also balancing demands for transparency against regulatory and litigation risks, Williams said, noting the company received its first lawsuit within 48 hours of publicly acknowledging the attack.

Restoration Could Stretch For Months

Williams stopped short of providing a date for full recovery, but gave a clearer picture of how long different operations could remain affected.

He said many capabilities within TruStage’s credit union and lending businesses should make substantial progress over the next two weeks, 30 days and 60 days. Life insurance, however, remains a much more difficult restoration because of the complexity and interdependencies of its systems.

The attack damaged major portions of TruStage's operating environment and compromised some of the backup systems the company expected to use for recovery, forcing it to rebuild significant portions of its infrastructure in the cloud. CUToday.info previously reported that TruStage had accelerated a multiyear modernization program that was only in its first year when the attack occurred.

Williams acknowledged that the age of TruStage's technology has complicated that work, saying some systems were approaching or already beyond their expected useful lives. The company has decided against simply restoring those applications to their previous environment and instead is rebuilding them for cloud operation.

Digital Retirement Access Targeted

Williams also provided a more specific target for restoring digital access to retirement accounts, another area that has generated significant complaints.

Participants currently can call TruStage to obtain balances and conduct certain transactions, but Williams acknowledged that is only a workaround. TruStage is developing an interim digital capability that would allow participants to check balances, make transactions and move money online.

“Our current hope is that we have something in place digitally towards the end of this month, the early part of next month,” Williams said.

That follows CUToday.info’s Sept. 1 report that TruStage had reopened its Claims Contact Center and expected most life and AD&D claims that were pending before the July 11 attack to be paid shortly, although several policy-servicing and payment functions continued to require manual or offline processing.

There was less movement on perhaps the biggest unanswered question: whether member information was stolen.

Williams said outside experts continue reviewing the affected data and TruStage expects “very specific insights” in roughly another two months. He reiterated that credit unions whose member information was compromised will be notified before affected members.

“You will hear about that from us first,” Williams said.

TruStage is already developing an opt-in process under which it could handle member notifications on behalf of affected credit unions if the investigation determines information was compromised. The company is also discussing that approach with regulators, Williams said.

CUToday.info previously reported that Mandiant had confirmed TruStage established a clean, isolated operating environment and had found no evidence of continuing threat-actor activity since July 11. At that time, TruStage similarly cautioned that the data investigation could take another two to three months.

Williams also acknowledged for the first time in the discussion that the attack will have a financial impact extending beyond this year, although he said TruStage’s balance sheet remains strong.

“Will it impact our financials in '26 and '27? Yes,” Williams said, adding he does not expect the costs to create “significant challenges” to the company's balance sheet.

TruStage has brought in outside recovery specialists, an interim CIO and other experts alongside Mandiant, and Williams said he directed the organization that a lack of people or financial resources could not be allowed to slow the recovery.The CEO also acknowledged the company cannot promise another attack won't occur.

“I could almost guarantee the opposite—that we will be attacked again,” Williams said. The objective, he said, is to rebuild TruStage so that another successful attack does not produce anything resembling the prolonged recovery credit unions and their members are experiencing now.

Originally reported by CU Today.