PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

Patelco Credit Union Faces More Blowback from Ransomware Attack

By Tom Nawrocki
February 6, 2025
in Analysts Coverage, Fraud & Security
0
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
infostealer breach

The fallout from last summer’s ransomware attack on California’s Patelco Credit Union continues. State regulators have fined Patelco $100,000 and ordered it to implement a new cybersecurity program, which includes hiring a security consultant and providing training for all employees.

But Patelco’s troubles don’t end there. The credit union is also facing a class-action civil lawsuit in state court, as well as a federal lawsuit filed by two of its members. Since news of the attack broke, Patelco’s membership has dropped by nearly 9,000, according to call reports filed with the NCUA.

The breach has also led to many instances of what Patelco describes as first-party fraud. In October, two members filed a lawsuit claiming they discovered 26 fraudulent transactions on their account, all made using the Apple Cash app, totaling more than $14,000.

According to court filings, Patelco denied that the transactions were fraudulent. The credit union said that the decline in membership following the attack was because of accounts it had closed for first-party fraud.

The attack, which began last June, disrupted Patelco’s online banking services for weeks and exposed the personal information of more than a million customers and employees.

Patelco says it did not pay a ransom to the hackers but reported losses of more than $39 million in Q3 2024, attributing them to covering overdrafts for its members after the attack.

Taking Precautions After the Fact

The consent decree, agreed to by both Patelco and California’s Commissioner of Financial Protection and Innovation, requires the credit union to designate a qualified individual to oversee its cybersecurity program. Patelco must also maintain a training program to ensure its employees understand the risk profile and compliance obligations.

In addition, Patelco is expected to hire a qualified, independent, and unaffiliated third-party compliance consultant to support its efforts to enhance the cybersecurity program and to maintain independent testing.

Cybersecurity experts agree that financial institutions should proactively address these incidents and implement the measures that Patelco is only now taking.

“Our main recommendation would be heightened education for credit union staff, about socially engineered schemes that come in via email and to the call center,” said Tracy (Kitten) Goldberg, Director of Fraud and Security at Javelin Strategy & Research. “Additionally, they should invest in cybersecurity insurance policies that cover ransomware attacks, ensuring that losses are covered.”

Often, after such attacks, weaknesses in the security apparatus become glaringly obvious. Following a cyberattack on Change Healthcare last year, its parent company, UnitedHealth, admitted that it hadn’t been using multi-factor authentication to secure its most critical systems.

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Tags: Apple CashCredit UnionFirst-party FraudPatelco Credit UnionRansomware

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    Cross-Border Payments

    How the U.S. Built Its Faster Payments Ecosystem

    April 3, 2026
    Young Latin woman applying powder on her face for beauty blog. Smiling woman sitting at table in cosy room holding powder box and brush looking at phone camera recording video. Make up and cosmetics blogging concept

    TikTok Aspires to Fintech Status with Payments, Credit Bids in Brazil

    April 2, 2026
    small business credit card

    What Banks Get Wrong About Small Business Credit Cards

    April 1, 2026
    embedded payments

    Embedding Payments for Growth: How ISVs Can Scale Through Vertical Focus and Partnerships

    March 31, 2026
    ACH fraud monitoring

    From a Checkbox to a Differentiator: Redefining ACH Fraud Monitoring

    March 30, 2026
    Digitization and Multi-Brand Cards: Prepaid Trends. Bancorp Bank prepaid card fees, Bitpay Prepaid Card, mobile prepaid debit cards, prepaid cards for councils

    Turning a Prepaid Card into a Long-Term Relationship

    March 27, 2026
    payments fraud, faster payments fraud, financial fraud

    The Emotional Toll of Financial Fraud

    March 26, 2026
    hyperliquid

    What Hyperliquid Reveals About the Future of Trading

    March 25, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2026 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result