Introduction
The Cybersecurity and Credit Union System Resilience Report details the measures taken to strengthen cybersecurity within credit unions and the National Credit Union Administration (NCUA), as required by the Consolidated Appropriations Act, 2021 (P.L. 116-260).1 This report:
- Outlines NCUA’s policies and procedures to address cybersecurity risks and activities;
- Discusses cybersecurity resilience within the credit union system, including NCUA’s key initiatives to enhance cybersecurity preparedness among credit unions, such as targeted examinations, risk assessments, and educational and outreach efforts;
- Describes current and emerging threats; and
- Highlights NCUA’s collaboration with other federal agencies, industry stakeholders, and cybersecurity experts to address emerging threats and promote a culture of cybersecurity awareness and resilience within the credit union industry.
The efforts represented by this report underscore NCUA’s ongoing commitment to protecting the financial well-being of credit union members and upholding the integrity of the broader financial system in the face of cybersecurity threats.
Credit unions are an essential provider of financial services to the American public. Together, credit unions and NCUA remain vigilant to the ever-present threat of cyberattacks.
1. Analysis of Policies and Procedures
Policies and Procedures
Agency Cybersecurity Program
NCUA maintains a low tolerance for Information Technology (IT) system risk, adhering to mandatory security standards for federal information and systems. The agency meets minimum information security requirements by using security and privacy controls recommended by the National Institute of Standards and Technology (NIST) and the Federal Information Security Modernization Act of 2014 (FISMA).2
NCUA applies relevant statutes, regulations, and standards including the NIST Risk Management Framework and Special Publication 800-53 − Security and Privacy Controls for Information Systems and Organizations.3 The agency also follows directives issued by the Cybersecurity and Infrastructure Agency (CISA), which address operational, emergency and cybersecurity coordination, assessment, and response measures.
NCUA is continuing to adopt a zero-trust security model emphasizing robust access controls with an approximate completion of 70 percent across a portfolio of 43 projects. As part of the federally mandated system authorization process, NCUA evaluates:
- Information types, assets, systems, and services;
- Identity verification and access enforcement;
- Device management policies for antivirus, antimalware, software updates, and hardware configuration changes;
- Roles and privileges of system administrators and developers;
- Systems and data interconnections; and
- Privacy Impact Assessments, Privacy Plans, and Systems of Records Notices.
NCUA selects and implements security controls to protect the confidentiality, integrity, and availability of systems and infrastructure. These security controls are documented, reviewed, and tested with automated and manual monitoring.
Information security is further supported by policies and procedures for data collection, encryption, retention, and destruction that comply with relevant laws or mandates from NIST, the Office of Management and Budget, CISA, or the National Archives and Records Administration.
Information Security and Cybersecurity Regulations
In February 2023, the NCUA Board approved a final rule requiring federally insured credit unions to notify NCUA within 72 hours of a significant cyber incident.
This rule supports early detection and response, enabling interagency response protocols if necessary. From May 1, 2025, through April 30, 2026, credit unions reported 588 cyber incidents, including ATM jackpotting, phishing, email compromises, ransomware, and third-party provider incidents. No systemic threats were identified or reported.
Information Security Examination Program
NCUA’s Information Security Examination (ISE) program is designed to evaluate cybersecurity resilience within the credit union industry by using a risk-focused, scalable approach tailored to each credit union’s business model.
During each examination, NCUA conducts an information security review through the ISE, which provides examiners the flexibility to address areas of current or potential material risk specific to each credit union.
The ISE program aligns with NCUA regulations 12 C.F.R. parts 748, Security Program, Suspicious Transactions, Catastrophic Acts, Cyber Incidents, and Bank Secrecy Act Compliance, and 749, Records Preservation Program and Appendices—Record Retention Guidelines, Catastrophic Act Preparedness Guidelines.
The ISE Toolbox application offers examiners access to industry security standards and frameworks from NIST, the Center for Internet Security, and CISA.
Automated Cybersecurity Evaluation Toolbox (ACET) Maturity Assessment
NCUA offers the ACET maturity assessment to help credit unions evaluate their cybersecurity programs. It aligns with NCUA’s ISE program and incorporates industry standards like the NIST Cybersecurity Framework for financial institutions, mapping statements to the Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook, and regulations.
Information Technology & Cybersecurity Alerts
In 2026, NCUA adopted a new messaging application to deliver cybersecurity alerts to credit unions. This new application enables authentication of messages through digital signatures.
Between May 2025 and April 2026, NCUA issued the following cybersecurity alerts and notices to inform federally insured credit unions about increased threats, available resources, and common vulnerabilities and exposures along with recommended mitigations:
- CISA Financial — Informed credit union subscribers of an FFIEC-hosted webinar regarding the retirement of the CAT tool and the introduction of alternative resources. The webinar specifically highlighted solutions offered by the Cyber Risk Institute, which provides a standardized, risk-based cybersecurity assessment framework tailored for the financial services industry. (7/23/2025)
- NCUA’s ACET Update is Available for Download — Notified credit unions that ACET had been updated to incorporate NIST‘s Cybersecurity Framework 2.0 content and was available at no cost for download. (9/16/2025)
- The U.S. Department of the Treasury Advises Increased Cyber Hygiene Due to Elevated Threat Levels — Communicated 11 recommended actions for credit unions in response to heightened threat levels related to geopolitical tensions. (4/1/2026)
- The Federal Bureau of Investigation (FBI) issued FLASH-2026 0219-001 addressing an Increase in Malware Enabled ATM Jackpotting Incidents — Advised credit unions to review the FBI’s guidance on addressing and mitigating ATM jackpotting incidents. (4/1/2026)
2. Activities to Ensure Effective Implementation of Policies and Procedures
Qualified Staff
NCUA employs highly qualified staff who focus on cybersecurity and privacy. Staff expertise includes cybersecurity operations experts, incident response specialists, cloud and application security architects, and network security engineers. In addition, the agency uses contract staff with specialized skills in areas such as:
- Computer forensics;
- Defensive cyber operations;
- Malware analysis and mitigation;
- Security information and event management;
- Configuration management;
- Threat hunting;
- Security awareness and education;
- Governance, risk, and compliance; and
- Incident handling and response.
NCUA Staff Training
All NCUA system users must complete mandatory privacy and security awareness training that covers proper information security practices, data and system access rules, responsibilities for safeguarding personally identifiable information, and ethics regarding unauthorized disclosures. Agency employees and contractors receive both general and role-based security and cybersecurity training at least annually. Training focuses on employees’ legal and ethical obligations to protect sensitive information. Training includes:
- Secure collection of information using appropriate methods tailored to each situation;
- Authorized transfer and storage of sensitive information according to agency guidelines; and
- Proper destruction or return of non-public sensitive or personally identifiable information after examinations or reviews, in accordance with laws.
Privileged Access — Staff with privileged system access or data management duties are required to take specialized, role-based security training.
Credit Union Examiners — NCUA provides examiners with training specific to the ISE program, equipping them with standards, tools, and practices to identify cybersecurity risks, threats, and vulnerabilities.
Specialized Examiners — Regional and national IT security examiners receive specialized training to develop and maintain the technical knowledge and skills required to perform thorough information security examinations at more complex institutions.
Credit Union Training and Support
NCUA’s Office of Credit Union Resources and Expansion offers free training for credit unions, which includes more than 300 courses on various subjects, including information security. The office also hosts webinars to keep credit union professionals informed about protecting credit unions and members.
Accountability Measures and Senior Leadership
NCUA Risk Management
NCUA’s Enterprise Risk Management Council, Cybersecurity Council, and IT Oversight Council are comprised of senior executives with varied IT and security expertise. These councils enhance oversight and accountability for agency cybersecurity. The Office of Examination and Insurance is responsible for the supervision and examination program of federally insured credit unions and focuses on delivering the tools and knowledge to enable examiners and credit unions to address cybersecurity risks. NCUA manages priorities and performance through its Annual Performance Plan.
Federal Managers' Financial Integrity Act
The Federal Managers’ Financial Integrity Act, P.L. 97–255, requires management to assess internal controls annually and submit a Statement of Assurance to the President and Congress on the effectiveness of those controls.
NCUA maintains strong internal controls through embedded risk management practices to meet strategic goals. In 2025, NCUA management reviewed and assessed controls to ensure operational efficiency, reliable reporting, compliance, and asset protection. No significant weaknesses were identified, and NCUA continues to strengthen internal controls and operations.
Deployment of Adequate Resources and Technologies
Annual Budget Resources
The NCUA Board determines the resources necessary to carry out NCUA’s responsibilities under the Federal Credit Union Act. Under Board leadership, the agency focused on efficiency, removing redundant processes, improving data quality, and realigning agency resources in developing the agency’s annual budget.
FISMA Audit
NCUA conducted its fiscal year 2025 independent evaluation of the effectiveness of its information security program and practices.4 As documented in the resulting audit report, the agency maintained Maturity Level 4, “Managed and Measurable.” The rating reflects an effective information security program and that NCUA substantially complied with information security and privacy policies and procedures.
Cyber Threat Information Sharing Audit
In 2025, NCUA’s Office of Inspector General (OIG) audited NCUA’s Cyber Threat Information Sharing practices. The audit looked at cyber threat information sharing, information processing, past industry events, and data management protocols. The audit resulted in eight recommendations due for completion by September 30, 2026. As of March 31, 2026, five of the eight OIG recommendations are already completed, implemented, or resolved, and the agency is on track to complete all recommendations by the September 30, 2026, deadline.
Industry Efforts
Credit union participation in the following initiatives reflects industry engagement with the broader information security community.
- Financial Information Sharing and Analysis Centers and Organizations — Credit unions can participate in the Financial Services Information Sharing and Analysis Center and the National Credit Union Information Sharing and Analysis Organization to share intelligence, knowledge, and practices, and to collaborate and coordinate to identify, protect, detect, respond to, and recover from threats and vulnerabilities.
- CISA Cyber Hygiene Services — CISA provides a cyber hygiene services program to help protect all 16 of the nation’s critical infrastructure sectors. For the financial services sector, more than 300 credit unions engaged with CISA for cyber hygiene services, taking advantage of vulnerability and web application scanning to help credit unions identify and mitigate cybersecurity threats.
lnteragency Coordination to Strengthen Cybersecurity
NCUA coordinates with other federal and state regulatory agencies to strengthen cybersecurity, including developing and disseminating best practices and sharing information. Examples include the following collaborative bodies:
FFIEC — NCUA participates in several FFIEC subcommittees dedicated to cybersecurity.
- IT Subcommittee. This group addresses information systems and technology policy, examination, and supervision issues as they relate to financial institutions and their technology service providers.
- Cybersecurity Critical Infrastructure Subcommittee. This group addresses policy and information sharing relating to cybersecurity, critical infrastructure security, and the resilience of financial institutions and technology service providers. Agency subcommittee members collaborate to develop interagency and joint statements and work products.
In July 2025, the FFIEC held its annual IT Conference for federal and state financial institution examiners. The conference consisted of 14 sessions over 4 days. In February 2026, the FFIEC, on behalf of its members, released updates to the FFIEC IT Handbook to remove references to reputational risk, consistent with Executive Order 14331 of August 7, 2025. The updates did not establish new requirements.
- Financial Stability Oversight Council (FSOC) — As agency principal, NCUA’s Chairman is actively involved as a voting member of the FSOC. In its 2025 annual report, the FSOC recommended that member agencies expand joint monitoring efforts with appropriate agencies and groups, including the Financial and Banking Information Infrastructure Committee (FBIIC), to assess cyber-related financial stability risks. The Council specifically encouraged continued engagement and coordination with the U.S. Department of the Treasury’s Office of Cybersecurity and Critical Infrastructure Protection (OCCIP).
- FBIIC — NCUA is one of the 18 FBIIC member organizations from across the financial regulatory community, both federal and state. Staff from NCUA and other FBIIC member organizations meet monthly to work on operational and tactical issues related to critical infrastructure matters, including cybersecurity. OCCIP works with the financial services sector to support development of cybersecurity exercises.
- Financial Services Sector Coordinating Council (FSSCC) — NCUA collaborates and coordinates with the private sector through the FSSCC. The FSSCC collaborates with key government agencies to protect the nation’s critical infrastructure from cybersecurity and physical threats.
- CISA — NCUA is part of CISA’s Vulnerability Disclosure Policy (VDP) Platform, which streamlines day-to-day operations associated with disclosing and managing cyber vulnerabilities. The platform serves as the primary point of entry for receiving, triaging, and routing vulnerabilities discovered and reported by public security researchers in support of Binding Operational Directive 20-01: Develop and Publish a VDP.
- OCCIP and CISA — As a federal agency, NCUA follows CISA and OCCIP’s joint direction during government-wide incident response activities. In addition, NCUA identifies potential, actual, and emerging threats, issues, or challenges to analyze underlying causes and develop innovative short- and long-term solutions. This analysis supports the shaping of NCUA’s internal policies and procedures related to cybersecurity, critical infrastructure protection, supply chain risks, national security, insider threats, counterintelligence, continuity of operations, and emergency response.
NCUA staff also participate in the following interagency initiatives:
- CISA security operations center information and collaboration sessions.
- OCCIP information and collaboration sessions.
- The Small Agency Chief Information Officer Council.
- The Small/Micro-Agency Chief Information Security Officers Council.
3. Current and Emerging Threats
The financial sector faces an increasingly sophisticated array of cybersecurity threats that demand vigilance. The rapid evolution of technology, coupled with escalating geopolitical tensions, has expanded the threat landscape. Cybersecurity risks grow as threats evolve, become more sophisticated, and cause greater damage. Financial institutions face increasing challenges due to system integration complexity, lack of service provider diversity, and vendor lock-in.
The evolving array of cybersecurity threats that require continued vigilance by credit unions include:
- Artificial Intelligence (AI) — AI continues to reshape the cybersecurity threat landscape. According to CrowdStrike’s 2026 Global Threat Report, attacks involving AI-enabled techniques increased by nearly 90 percent.5 Malicious actors are increasingly leveraging generative AI to accelerate the speed, precision, and sophistication of attacks against financial institutions. These tools allow threat actors to combine multiple data sources—including social media—to craft highly tailored phishing schemes aimed at compromising user workstations and accounts. Once an initial intrusion occurs, AI further amplifies the threat by rapidly analyzing internal and external data to map organizational relationships, often with the goal of facilitating financial fraud or extortion. Emerging agentic AI capabilities further reduce the need for human intervention, enabling attackers to operate at greater scale. Given the pace of these developments, it is critical for financial institutions to continually mature their cybersecurity programs, emphasizing continuous monitoring, robust third-party risk management, and comprehensive staff training to defend against AI-enhanced attack vectors.
- Business Email Compromise (BEC) — According to the FBI’s Internet Crime Complaint Center, BEC is one of the most financially damaging online crimes. It exploits the fact that most businesses rely on email to conduct business. While BEC is not unique to the financial services sector, it continues to be a prevalent means for intercepting payments. Forty known instances of Business Email Compromise were reported to NCUA by credit unions between May 1, 2025, and April 30, 2026, compared with 27 for the previous reporting period.
- Quantum Computing and Cryptographic Risks — The development and trajectory of quantum information technologies and products that could compromise existing encryption and other cybersecurity controls across critical infrastructure sectors remains a concern.
- Ransomware Attacks — Ransomware attacks continue across all critical infrastructure sectors, including the financial sector, and is an increasingly serious threat to credit unions. Ransomware attacks and payments are a lucrative enterprise for cyber criminals, which drives an increase in frequency, scope, and volume of the attacks. As a cybercrime business model, ransomware can also be a service provided by a ransomware group that sells its code or malware to other hackers, who then use it to carry out their own ransomware attacks. CISA’s StopRansomware campaign provides a whole-of-government approach to tackle ransomware more effectively and serves as one central location for ransomware resources and alerts.
- State-sponsored Cyber Activities — Over the past year, U.S. government organizations, including CISA, the National Security Agency (NSA), and the FBI continued to produce joint advisories to alert the public that state-sponsored cyber actors’ activities against critical infrastructure are a real threat. Along with CISA, NSA, and the FBI, NCUA has encouraged credit unions of all sizes to adopt a heightened state of awareness and to proactively hunt threats to defend against this risk. Additionally, NCUA provided guidance and resources to credit unions to assist in mitigating this threat.
- Third-party Risk — Financial institutions, including credit unions, rely on third-party service providers to deliver back-office operations and provide critical services to their members. The use of third-party service providers may mean that a credit union does not have visibility into vendor controls and cybersecurity posture, necessitating robust risk management practices.
The speed, quantity, and evolving nature of cybersecurity threats demand constant vigilance from financial services sector entities, agencies, and regulators.
Conclusion
As the digital landscape evolves, NCUA will continue adapting its cybersecurity approach to efficiently and effectively address emerging threats and challenges. NCUA is committed to strong cybersecurity resilience within the agency and the credit union system.
Appendix: Resources
Regulations
Letters to Credit Unions6
| Year | Letter | Letters to Credit Unions |
|---|---|---|
| 2026 | 26-CU-01 | NCUA’s 2026 Supervisory Priorities |
| 2025 | 25-CU-01 | NCUA's 2025 Supervisory Priorities |
| 2025 | 25-CU-02 | Cyber Incident Notification Reguirements UQdate to Letter 23-CU-07 |
| 2024 | 24-CU-02 | Board of Director Engagement in Cybersecurity Oversight |
| 2023 | 23-CU-07 | Cyber Incident Notification Requirements |
1 Pub. L. No. 116–260, 134 Stat. 2173 (Dec. 27, 2020).
2Federal Information Processing Standards Publication 199, Standards for Security Categorization of Federal Information, and Information Systems; Federal Information Processing Standards Publication 200, Minimum Security Requirements for Federal Information, and Information Systems.
3NCUA is also subject to the E-Government Act of 2002, the Privacy Act of 1974, and Office of Management and Budget policies and guidance on federal information management and privacy.
4FISMA 2014, Public Law 113-283, requires Inspectors General to perform annual independent evaluations to determine the effectiveness of agency information security programs and practices.
5Financial Stability Risks Mount as Artificial Intelligence Fuels Cyberattacks.
6Letters to Credit Unions and other guidance are available on NCUA’s website under Regulation & Supervision.