Around sixty credit unions faced outages traced to a ransomware attack on a shared technology provider, with member-facing services disrupted across institutions that were not themselves attacked.
Pooling Is How Small Institutions Exist At All
A credit union serving a few thousand members cannot build core banking, online access, card processing and fraud monitoring. It buys them, usually from providers specialising in exactly this market.
That pooling is what allows small, member-owned institutions to compete with national banks. It is a genuinely good arrangement, and it produces precisely the concentration this desk keeps filing — at KDDI in 26-0623, RevolutionParts in 26-0723, and the airport platforms in 26-0704.
The Member Sees Their Own Institution Fail
From the member’s side, their credit union’s services stopped working. The provider is invisible; the institution takes the reputational damage for a failure it did not cause and could not have prevented.
It also cannot fix it. The institution’s staff can only wait for the provider, which is an uncomfortable position for an organisation whose core proposition is local relationships and accountability.
Concentration Has No Obvious Remedy Here
Telling small institutions to diversify providers is telling them to abandon the economics that make them viable. Requiring them to assess provider security assumes capability they do not have — the same gap filed for school districts at 26-0228.
The tractable interventions are at the provider: treating a company serving sixty regulated institutions as systemically significant, and examining it accordingly, rather than as an ordinary vendor to each of them separately.
Compiled from public reporting, listed below. The provider and the attacking group are identified in some reporting; we describe the structural pattern rather than assessing any named party’s practices. Corrections: corrections@forensicpost.com.