← All News

Bessemer FCU Sues TruStage, Alleging Cybersecurity Failures After System Breach

By CU Today Staff —

GREENVILLE, Pa.—The $47.5-million Bessemer System Federal Credit Union has filed a proposed nationwide class action against TruStage Financial Group, alleging the company's cybersecurity practices were inadequate and that a July cyber incident disrupted critical services relied on by credit unions across the country. The complaint was filed July 17 in the U.S. District Court for the Western District of Wisconsin.

According to the complaint, TruStage failed to implement industry-standard safeguards despite marketing cybersecurity products and representing in its privacy policy that it maintained administrative, technical and physical protections for customer information. The suit alleges unauthorized third parties gained access to TruStage's systems, forcing the company to shut down portions of its network and disrupting access to services including Guaranteed Asset Protection (GAP), Mechanical Repair Coverage claims, Payment Protection products and certain customer support channels. The allegations have not been proven in court, and TruStage has not yet filed a response.

The complaint goes beyond alleging a data breach, asserting that TruStage's own published security and business continuity representations induced credit unions to entrust the company with sensitive member information and continue long-term contractual relationships. Bessemer alleges those representations were inaccurate, contending the company failed to maintain commercially reasonable security controls despite its role as a major provider of cybersecurity, insurance and lending protection services to credit unions. The lawsuit also claims the outage halted normal business operations for some institutions, including limiting access to employee retirement accounts and requiring credit unions to incur costs investigating potential fraud, protecting members and responding to the incident.

Bessemer seeks to represent a nationwide class of credit unions—and, according to the proposed class definition, affected credit union members—that provided confidential information to TruStage and were impacted by the incident. The suit asserts a negligence claim and seeks damages, reimbursement for breach-related expenses, litigation costs and other relief.

TruStage disclosed earlier this month it had experienced a cybersecurity incident, activated its incident response plan, retained outside cybersecurity experts and took systems offline to contain the event while an investigation continues.

As CUToday.info previously reported, in a message to its partners, TruStage stated:

“We are reaching out directly because we value our relationship and want to ensure you are hearing from us. We recently identified a cybersecurity incident affecting our environment and out of precaution, we proactively shut down our network to help to contain the issue and protect our environment. We also immediately activated our incident response and recovery efforts and engaged external cybersecurity experts to assist with containment, remediation, and recovery efforts. That work is ongoing.

“We understand that situations like this can raise questions and concerns. The trust you place in TruStage is important and respected by us. We are approaching this matter with care, attention, and urgency. At this stage, it would be premature to draw conclusions about the scope or impact of the incident, and we do not want to speculate or get ahead of the facts. As our understanding of the situation evolves, we will communicate appropriately.

“We wanted to ensure you heard directly from us.”

TruStage has updated its FAQs page regarding the incident.

Originally reported by CU Today.