Your Core Was Down Four Days and It Was Not a Cyber Incident. You May Still Owe NCUA a Report.
Resources/Blog

Your Core Was Down Four Days and It Was Not a Cyber Incident. You May Still Owe NCUA a Report.

Your Core Was Down Four Days and It Was Not a Cyber Incident. You May Still Owe NCUA a Report.
Compliance CISO
September 25 2026
7 min read

Your Core Was Down Four Days and It Was Not a Cyber Incident. You May Still Owe NCUA a Report.

Your Core Was Down Four Days and It Was Not a Cyber Incident. You May Still Owe NCUA a Report.

A cooling system failed at a third-party data center around midday on September 15, damaging equipment that supports Sharetec's core processing platform. Credit unions across the country lost access to member accounts. Some could not see balances in the lobby. At least two closed their doors.

Every credit union that spoke publicly said the same thing, and they were right to: no data breach, no unauthorized access, not a cyberattack.

That is where the coverage stopped. It is where the compliance question starts, because the rule that applies here is not the one most people reach for.

What happened

In a September 21 report, American Banker identified 23 credit unions in 14 states that lost service, holding $2.56 billion in assets and roughly 200,000 members, using NCUA's certified June 2026 call report data.

First Choice Federal Credit Union in Pennsylvania said technical teams had worked continuously for more than 56 hours and that roughly 100 credit unions had been restored. Iberville Federal Credit Union in Louisiana closed Friday. Corry Federal Credit Union in Pennsylvania closed Saturday while staff validated the system and posted transactions. Sharetec postponed its 2026 Users Conference.

Debit cards and direct deposits kept running at several credit unions while online and mobile banking went dark.

Why the cyber incident rule probably does not reach this

The reflex is 12 CFR 748.1(c), the 72-hour notification. Read the definitions and it is hard to land.

Start with the gate. A reportable cyber incident is any substantial cyber incident that leads to one of three listed results. The rule defines a cyber incident as an occurrence that actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information on an information system, or the system itself. A cooling failure jeopardizes nothing without lawful authority. It is an accident, not an intrusion. "Substantial" is not separately defined, so the gate rests on that definition.

The gate does the work, because prong (A) looks like it fits.

Prong (A) reaches a substantial loss of confidentiality, integrity, or availability of a network or member information system where one of three things is true: the loss results from unauthorized access to or exposure of sensitive data, it disrupts vital member services, or it seriously impacts the safety and resiliency of operational systems and processes. Those are alternatives, not conditions. A four-day outage that stops members seeing balances is a substantial loss of availability that disrupts vital member services. Read (A) by itself and you would report.

You cannot. Every prong sits downstream of the substantial cyber incident requirement, and that is where this event falls out.

Prong (B) requires a cyberattack or exploitation of vulnerabilities. There was neither.

Prong (C) is the one people assume catches third-party events. It covers disruption or unauthorized access caused by a compromise of a credit union service organization, cloud service provider, other third-party data hosting provider, or a supply chain compromise. But the rule defines compromise as unauthorized disclosure, modification, substitution, or use of sensitive data, or unauthorized modification of a security-related system to gain unauthorized access. Overheated equipment is not a compromise under that definition.

NCUA's own guidance supports that reading. Appendix B to Letter 23-CU-07 lists examples that likely would not qualify, including loss of availability from a physical event such as a natural disaster.

So on the text, this generally is not a reportable cyber incident. The correct answer to the wrong question.

Part 748 contains two reporting obligations, not one. The cyber incident report under 748.1(c) runs 72 hours to NCUA. The catastrophic act report under 748.1(b) runs five business days to your regional director. A vendor outage with no attacker behind it can miss the first and land inside the second. Different rule, different clock, different recipient, and the second is the one almost nobody drills.

What 748.1(b) actually says

The rule requires a federally insured credit union to notify the regional director within five business days of any catastrophic act that occurs at its offices.

A catastrophic act is any disaster, natural or otherwise, resulting in physical destruction or damage to the credit union, or causing an interruption in vital member services as defined in 12 CFR 749.1, projected to last more than two consecutive business days.

"Any disaster, natural or otherwise" is deliberately broad. A cooling failure that damages equipment is a disaster of the "otherwise" variety.

Vital member services under 749.1 means the essential financial services a credit union provides its members, and the definition names member account access and share withdrawal and deposit facilities. Members who could not see balances or transact for days lost exactly that.

"More than two consecutive business days" is a projection test, not a hindsight test. What matters is what you projected at the time, and many of these credit unions were past two days by Thursday.

One open question belongs with your regional director. The provision says a catastrophic act "that occurs at its office(s)," and the cooling failure occurred at a third-party data center. The definition's second prong turns on interruption of vital member services rather than location, and the interruption occurred at the credit union. But the 2007 rulemaking that shaped this language predates the era when a credit union's core lives somewhere else. Ask. Do not let ambiguity become a reason to do nothing.

A second obligation inside 748.1(b) gets missed even by credit unions that file the report. Within a reasonable time, you must prepare a record of the incident and keep it at your main office: where it happened, when, the amount of any loss, whether any operational or mechanical deficiency might have contributed, and what has been or will be done to correct it.

A cooling failure is a mechanical deficiency. The rule asks you to record what broke and what is being done about it, when the thing that broke belongs to someone else.

The pending proposal that touches all of this

NCUA proposed amending 748.1(b) on December 29, 2025 under RIN 3133-AF77, and it reaches nearly every element above. It would extend the deadline from five business days to 15 calendar days, change the recipient from the regional director to NCUA, and replace the prescriptive recordkeeping list with a requirement to maintain the basic facts of the event.

The definition of catastrophic act, including the two-business-day threshold and the vital member services cross-reference, is not proposed to change.

Comments closed February 27, 2026 and the proposal has not been finalized. The current text still carries the five-business-day deadline and the regional director. That is the rule in force today.

What to do now

Work out whether your interruption crossed two consecutive business days, and write down the answer with a date. If it did, the five-business-day clock may already be running. If it did not, document that too. An examiner will want to see the question was asked in real time.

Call your regional director rather than emailing a form. On the "at its office(s)" question, a documented conversation with your examiner beats a defensible reading you reached alone. If your reading is wrong, having asked is the difference between a finding and a footnote.

Start the 748.1(b) incident record while the facts are fresh. Time the outage began, time service was restored, what members could and could not do, what the vendor told you and when, and what it said about the cause. Reconstructing that in January is harder than capturing it now.

Separate availability from confidentiality in your incident response plan. Most are built around a breach. This event was pure availability and it still generated a regulatory question, member harm, and fee reimbursements. If your plan only triggers on suspected unauthorized access, it did not fire.

Ask your core provider where your production environment physically lives, in writing. Several credit unions here learned that from news coverage. While you are asking, pull what your agreement says about notification timing and service credits for an availability event.

Source note

This article is based on 12 CFR 748.1, including the catastrophic act report at paragraph (b) and the cyber incident report and definitions at paragraph (c), and on 12 CFR 749.1, both as published in the eCFR and current as of September 18, 2026; Appendix B to NCUA Letter to Credit Unions 23-CU-07, listing examples of incidents that likely would not qualify as reportable cyber incidents, last modified August 14, 2023; NCUA Letter to Credit Unions 25-CU-02, January 2025, which added the online Cyber Incident Credit Union Reporting System form without changing the definitions or appendices; NCUA's proposed rule on Catastrophic Act Reporting, RIN 3133-AF77, published at 90 FR 60591 on December 29, 2025; the 2007 rulemaking that established the current catastrophic act language at 72 FR 42271; and reporting by American Banker, CUToday.info, Credit Union Daily, and local outlets in Illinois, Pennsylvania, Louisiana, Indiana, Maine, and West Virginia. Statements attributed to Sharetec are as relayed by affected credit unions. Sharetec had not posted a broad public statement on its main website as of the most recent reporting and did not respond to American Banker.

Facts in this event are still developing. NCUA's Appendix B guidance addresses physical-event availability loss generally but does not address third-party data center failures as a distinct category, and the "at its office(s)" question described here is not resolved in published guidance. 748.1(b) is also the subject of a pending proposed rule. Verify with your regional office.

Disclaimer

This article is provided for general information and does not constitute legal advice. Regulatory requirements, compliance dates, examiner priorities, and enforcement posture change frequently. Verify current requirements against primary agency sources and your legal counsel before acting on anything described here.

Tags:

SharetecNCUACatastrophic Act ReportingVendor OutageCredit Union

Prepare Your Credit Union for Both Reporting Obligations

Compliance CISO brings Fortune 500 security expertise, including programs at Equifax, Capital One, and Visa, to fintech companies and credit unions building security and compliance programs. Schedule a free consultation at complianceciso.com/contact.

Recent Posts