TruStage, a major insurance and financial-services provider to credit unions, disclosed a cybersecurity incident and took portions of its network offline to contain it. As of the company’s public updates, the scope of the incident was still under investigation. Here is what has been confirmed and what you can do.
What Happened in the TruStage Cybersecurity Incident
A network shutdown to contain a security event
TruStage — formerly known as CUNA Mutual Group and headquartered in Madison, Wisconsin — provides insurance and financial-services products that many credit unions offer their members. In a public statement, TruStage said it had “recently identified a cybersecurity incident affecting its environment and immediately activated its incident response and recovery protocols.” The company first disclosed the incident on July 15, 2026, and posted an update on July 16, 2026.
TruStage stated that it proactively shut down portions of its network to contain the threat and protect its systems. That step temporarily disrupted some of the insurance services TruStage provides through credit union partners, reportedly including claims for certain GAP insurance, mechanical repair coverage, and payment protection products. The company said it engaged external cybersecurity experts to support containment, remediation, and recovery.
What Has and Has Not Been Confirmed
Important context about the scope of the incident
As of the company’s public updates, TruStage had not disclosed whether any member or credit union information was accessed, what specific types of information may have been involved, or how many individuals may be affected. The company described conclusions about the scope as premature and said it would “communicate appropriately as its understanding of the situation evolves.”
This is an important distinction. For many credit unions, the immediate effect was a service disruption rather than a confirmed data breach, and a disruption to TruStage products does not affect a credit union’s own deposits, cards, ATMs, or online banking. Members should treat anything beyond TruStage’s own statements as unconfirmed until the company or regulators provide more information. TruStage launched online resources, including an FAQ page and a claims-intake page, to help consumers find timely information.
Who May Be Affected
Understanding the potential reach
TruStage serves a large number of credit unions and their members nationwide. Because the incident and any potential data exposure were still under investigation, the population of affected individuals had not been defined at the time of the company’s public updates.
A class action lawsuit was filed against TruStage by a credit union following the incident, alleging that the company failed to implement and maintain adequate cybersecurity safeguards. That litigation reflects the significance of the disruption to credit unions, even before the scope of any data exposure has been confirmed. If you are a credit union member who uses TruStage products, staying informed through official channels is the best approach as more details emerge.
Steps You Can Take Now
Prudent precautions while the investigation continues
Even though the scope is not yet confirmed, it is reasonable to take general protective steps. Monitor your financial accounts and credit reports for unfamiliar activity, and be cautious of phishing messages that reference TruStage or the incident, as scammers often exploit news of security events. Rely on TruStage’s official FAQ and support channels for accurate information rather than secondhand reports.
If TruStage later confirms that your personal information was involved, you may have legal options. A legal professional can help you understand your rights as the situation develops and whether you may be entitled to compensation.
Frequently Asked Questions About the TruStage Data Breach
When did the TruStage cybersecurity incident happen?
TruStage first disclosed the incident on July 15, 2026, with an update on July 16, 2026, and reporting indicates it identified the incident in mid-July 2026.
What information was exposed in the TruStage incident?
As of the company’s public updates, TruStage had not disclosed whether any information was accessed or what specific types of information may have been involved. Conclusions about scope were described as premature.
How many people were affected?
TruStage had not confirmed how many individuals may be affected as of its public updates.
Does this affect my credit union accounts?
According to reporting, a disruption to TruStage products does not affect your credit union’s own deposits, cards, ATMs, or online banking. For many credit unions, the immediate effect was a service disruption.
Is there a lawsuit related to the TruStage incident?
Yes. A credit union filed a class action lawsuit against TruStage following the incident, alleging inadequate cybersecurity safeguards.
What should I do now?
Monitor your accounts, be alert to phishing, and rely on TruStage’s official channels for updates. If your information is later confirmed to be involved, consider speaking with a legal professional.
Contact Wilshire Law Firm About the TruStage Data Breach
If you are a credit union member concerned about the TruStage cybersecurity incident, Wilshire Law Firm’s nationally recognized, award-winning team can help you understand your rights as more information becomes available.
We offer free consultations and free case reviews with a legal professional, and we are available 24/7. There are no fees unless you get paid.
Contact Wilshire Law Firm today to schedule your free case review regarding the TruStage data breach.

