When 70% of reported cyber incidents involve third-party vendors, the question isn’t whether your partners pose risk. It’s whether anyone has the authority to examine them.
On June 29, 2024, members of Patelco Credit Union woke up to find their accounts inaccessible. Online banking was down. The mobile app wouldn’t load. Branch staff couldn’t provide balances. What members didn’t know yet was that attackers had been inside Patelco’s systems since May 23, moving through the network for over five weeks before deploying ransomware that would shut down the $9.4 billion credit union for more than two weeks.
The aftermath unfolded in stages. First came the operational chaos: 500,000 members locked out of their money during the July 4th holiday week. Then the disclosure: the data breach had exposed names, Social Security numbers, driver’s license numbers, dates of birth, and email addresses for over a million accounts. Then the financial reckoning: $39 million in losses reported that quarter, a $100,000 fine from California regulators, and a $7.25 million class action settlement. Membership dropped by 9,000 in the months that followed.
Patelco’s experience was severe but not unusual. When our threat research team analyzed NCUA incident data, we found that 70% of reported cyber incidents at credit unions involved third-party vendors. The pattern repeats across the industry: a credit union’s security posture matters less than the security posture of the vendors it depends on. And unlike bank regulators, the NCUA has no legal authority to examine those vendors directly.
The vendor examination gap
The regulatory gap is stark. When a bank relies on a technology vendor for core services, the OCC, FDIC, or Federal Reserve can examine that vendor’s cybersecurity practices, require corrective actions, and enforce compliance. When a credit union relies on the same vendor for the same services, the NCUA cannot.
This isn’t a new problem. The Government Accountability Office has published three reports since 1999 recommending that NCUA receive third-party vendor examination authority. The Financial Stability Oversight Council has included the same recommendation in every annual report since 2015. Congressional bills have been introduced repeatedly. None have passed.
NCUA Chairman Todd Harper has testified that the agency may only review third-party vendors with their consent, and that vendors often decline. When the NCUA does gain access and identifies security gaps, vendors can reject the agency’s recommendations for corrective action. There is no enforcement mechanism.
The result is a regulatory blind spot that grows more serious as credit unions outsource more critical functions. Core banking platforms, payment processing, loan origination, mobile banking, cybersecurity monitoring: the services that define a credit union’s operations increasingly run on infrastructure the credit union doesn’t control and its regulator cannot examine.
Why vendor risk keeps growing
Credit unions have always relied on vendors, but the nature of that reliance has shifted. Digital transformation has accelerated outsourcing of functions that were once handled internally. Cloud migration has moved sensitive data to third-party infrastructure. The concentration of critical services among a small number of large vendors has created shared risk across the industry: when one provider is compromised, dozens or hundreds of institutions may be affected at once.
The phishing and brand impersonation campaigns targeting credit unions exploit this reality. Attackers understand that vendor compromise offers leverage that direct attacks on individual credit unions do not. A successful breach of a core banking provider or payment processor can yield access to member data across the provider’s entire client base. The economics favor patience and precision over volume.
Meanwhile, the attack techniques themselves have advanced. The ransomware operation that hit Patelco, linked to a group called RansomHub, shows how organized cybercrime has become. These aren’t opportunistic attacks. They involve weeks of research, careful movement through networks, and strategic timing designed to maximize disruption. The five weeks attackers spent inside Patelco’s network before being discovered is consistent with patterns seen across the financial sector: attackers who take their time because they understand the value of what they’re accessing.
When vendors fail, credit unions pay
When a vendor breach becomes a credit union crisis, the credit union bears the consequences. Members don’t distinguish between their credit union and the vendor that processed their data. Regulators don’t either: California’s $100,000 fine went to Patelco, not to any third party. The class action settlement came from Patelco’s resources. The reputational damage fell on Patelco’s brand.
This dynamic creates a structural problem that standard vendor risk management can’t fully address. Due diligence questionnaires and contractual requirements provide some visibility, but they depend on vendor self-reporting. Periodic assessments capture a point-in-time snapshot that may not reflect current conditions. And even thorough vendor management can’t substitute for the examination authority that would allow regulators to verify security practices independently. Credit unions already operating with thin margins in high-stress markets have even less capacity to absorb these losses when they occur.
Credit unions face the consequences of vendor security failures without the regulatory infrastructure to prevent them. They inherit risk from relationships they can audit but not truly examine, governed by a regulator that can identify the problem but lacks the legal authority to address it.
What this means for credit union leaders
The regulatory gap isn’t going to close soon. Congressional action has been recommended for over two decades without result. In the meantime, credit unions operate in an environment where their largest risks may originate outside their direct control.
This reality shapes how leaders should think about vendor relationships, incident preparedness, and the broader attack surface their institutions face. The vendors processing member data, hosting core systems, and enabling digital services are extensions of the credit union’s security perimeter, whether or not regulators can examine them as such.
Questions worth asking include how current vendor due diligence practices would have performed in the scenarios that led to recent breaches, what visibility exists into the cybersecurity practices of critical vendors beyond what they self-report, and how incident response plans account for the possibility that a breach originates not from internal systems but from a vendor whose security the credit union cannot directly verify.
The Bottom Line
The Patelco case illustrates what happens when these questions go unanswered until after attackers have already found their way in. Vendor due diligence built on self-reported questionnaires was not designed for an environment where a single third-party compromise can produce $39 million in losses and weeks of degraded service. The visibility gap between what credit unions assume about their vendors and what those vendors actually practice is where the next crisis will originate.
Key Takeaways
Analysis of NCUA incident data shows that 70% of reported cyber incidents at credit unions involved third-party vendors. The pattern indicates that vendor security often matters more than internal security posture.
Unlike bank regulators (OCC, FDIC, Federal Reserve), the NCUA lacks legal authority to examine third-party vendors. Vendors can decline access and reject recommended corrective actions. GAO and FSOC have recommended Congress address this gap since 1999 and 2015 respectively.
Attackers accessed Patelco’s network in May 2024 and remained undetected for five weeks before deploying ransomware that shut down the $9.4 billion credit union for over two weeks. The incident resulted in $39 million in losses, regulatory fines, and a $7.25 million settlement.
Digital transformation has accelerated outsourcing of critical functions. Concentration among large vendors creates systemic exposure where one breach can affect many institutions. Attack techniques have professionalized, with ransomware groups conducting patient, strategic operations.
Enhance vendor due diligence beyond self-reported questionnaires, maintain visibility into critical vendor security practices, and ensure incident response plans account for vendor-originated breaches. The regulatory infrastructure to prevent these incidents doesn’t exist, so preparation for their consequences is essential.



