Desk live·
ForensicPost
Breaches/Third party/File 26-0127

Sixty Institutions, One Technology Provider

Dozens of credit unions confronted outages traced to ransomware at a shared technology provider. Small financial institutions pool their technology because they cannot each build it.

Constructed geometry · not a chart of case data
TargetCredit union technology provider
ActorUnattributed
D. Kennedy10 min readConfidence: medium2 sources reviewed

Around sixty credit unions faced outages traced to a ransomware attack on a shared technology provider, with member-facing services disrupted across institutions that were not themselves attacked.

Pooling Is How Small Institutions Exist At All

A credit union serving a few thousand members cannot build core banking, online access, card processing and fraud monitoring. It buys them, usually from providers specialising in exactly this market.

That pooling is what allows small, member-owned institutions to compete with national banks. It is a genuinely good arrangement, and it produces precisely the concentration this desk keeps filing — at KDDI in 26-0623, RevolutionParts in 26-0723, and the airport platforms in 26-0704.

The Member Sees Their Own Institution Fail

From the member’s side, their credit union’s services stopped working. The provider is invisible; the institution takes the reputational damage for a failure it did not cause and could not have prevented.

It also cannot fix it. The institution’s staff can only wait for the provider, which is an uncomfortable position for an organisation whose core proposition is local relationships and accountability.

Concentration Has No Obvious Remedy Here

Telling small institutions to diversify providers is telling them to abandon the economics that make them viable. Requiring them to assess provider security assumes capability they do not have — the same gap filed for school districts at 26-0228.

The tractable interventions are at the provider: treating a company serving sixty regulated institutions as systemically significant, and examining it accordingly, rather than as an ordinary vendor to each of them separately.

How we reported this

Compiled from public reporting, listed below. The provider and the attacking group are identified in some reporting; we describe the structural pattern rather than assessing any named party’s practices. Corrections: corrections@forensicpost.com.

Sources
  1. 60 credit unions facing outages due to ransomware attack on popular tech providerThe Record
  2. Dozens of credit unions confront outages linked to third-party ransomware attackCybersecurity Dive
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary