Why Most Credit Union Cyber Incidents Start With a Vendor
Resources/Blog

Why Most Credit Union Cyber Incidents Start With a Vendor

Why Most Credit Union Cyber Incidents Start With a Vendor
Compliance CISO
June 21 2026
7 min read

Why Most Credit Union Cyber Incidents Start With a Vendor

Between September 2023 and May 2024, the first year the NCUA's cyber incident reporting rule was in effect, 73 percent of reported cyber incidents at credit unions traced back to third-party vendor involvement. That is not a statistic about sophisticated attacks on credit union networks. It is a statistic about how effectively attackers have learned to reach credit unions through the vendors those credit unions depend on.

A single 2024 core processor ransomware incident disrupted operations simultaneously at 60 small credit unions. None of those 60 credit unions were directly attacked. Their vendor was attacked, and the disruption cascaded through every institution that depended on that vendor for core technology. The NCUA highlighted this incident in its 2025 Annual Cybersecurity Report to Congress.

Why the NCUA Cannot Protect You From Your Vendors

One of the most significant structural vulnerabilities in credit union cybersecurity is a legislative gap that the NCUA has repeatedly flagged to Congress. The NCUA has no examination authority over credit union service organizations or core processors. The agency can examine credit unions. It cannot examine the vendors those credit unions use for core processing, digital banking, payments, and other critical functions.

This means that approximately 90 percent of the industry's assets are managed through third-party service providers that are outside the NCUA's direct supervisory reach. The responsibility for assessing those vendors' security posture, requiring appropriate contractual protections, and maintaining readiness to respond when a vendor is compromised sits entirely with the credit union.

The NCUA cannot examine your core processor. It can examine whether you have adequately assessed your core processor's security posture, required appropriate contractual protections, and prepared your credit union to respond when that vendor is compromised. That gap in regulatory authority is entirely your problem to manage.

What the 72-Hour Rule Means for Vendor Incidents

The NCUA's 72-hour cyber incident reporting obligation applies directly to vendor breaches. When a credit union receives notification from a third-party service provider that the provider has experienced a cyber incident that compromises the credit union's sensitive data or disrupts its business operations, the 72-hour reporting window begins at the moment of that notification.

This provision has significant operational implications that many credit unions have not fully internalized. A vendor breach notification that arrives on a Friday afternoon starts a clock that runs through the weekend. The NCUA does not pause reporting deadlines for business hours or reduced weekend staffing. The credit union's incident response process must begin immediately upon receiving the vendor notification, regardless of the day or time.

What MFA Deficiencies Have to Do With Vendor Risk

MFA deficiencies on administrative accounts were the second most common NCUA examination finding in 2024 and 2025. This is directly related to vendor risk because many of the administrative accounts that lack MFA are vendor-managed accounts used by core processor technicians, digital banking support staff, and other third parties who have privileged access to credit union systems.

Requiring your vendors to implement MFA at the same level the NCUA requires of your own staff is not just a best practice. The NCUA's guidance on third-party relationships expects credit unions to extend their security requirements to their vendors through contractual obligations. A credit union that has MFA on all internal administrative accounts but has not required the same of vendors with equivalent access has a significant gap.

What a Functioning Vendor Risk Program Looks Like

The credit unions best positioned to manage vendor cyber risk have several elements in place before a vendor incident occurs.

An annual vendor risk assessment for every critical vendor, which includes reviewing their SOC 2 Type 2 report if one exists, assessing their incident history, understanding what fourth-party relationships they rely on, and verifying that contractual security requirements are in place.

Vendor contracts should include breach notification requirements with a specific timeframe, ideally 24 to 48 hours after the vendor discovers an incident affecting the credit union's data or operations. They should also require notification to a named contact at the credit union, preserve audit rights, and provide termination rights if the vendor experiences a material security incident.

A vendor incident response playbook that specifies how vendor breach notifications are received and routed, who is responsible for assessing impact, how the 72-hour NCUA reporting obligation is triggered, and how the member notification analysis begins.

The credit unions that found themselves most exposed during the 2024 core processor incident were the ones that had no formal vendor risk assessment program, had accepted standard vendor contracts without negotiating security provisions, and had no vendor-specific incident response procedures. Building that foundation before the next incident is the only way to manage a risk that the NCUA cannot manage for you.

Tags:

Vendor RiskCredit UnionNCUAThird-Party RiskCyber Incident

Build a Vendor Risk Management Program for Your Credit Union

Compliance CISO brings Fortune 500 security expertise - including programs at Equifax, Capital One, and Visa - to credit unions building vendor risk management programs and incident response capabilities. Schedule a free consultation at complianceciso.com/contact.

Recent Posts