August 2026 credit union bulletin — print / PDF · association leave-behind

TX CU OAG list TX CU audit Free domain check

Cornerstone League · Texas / regional member contribution

August 2026 Credit Union IT & Cyber Bulletin

Texas credit-union breach and email-security watch, board talking points, and practical tips member CUs can use this week — plus a free domain self-check (QR below). Prepared by a College Station IT consultant focused on email and domain security.

EmailMeNow IT Consulting College Station · B/CS Chamber member
Bulletin date: August 4, 2026
(979) 472-3693
emailmenow.com

What to tell the board

  1. Texas peers (§2): Energy Capital CU (49,664) · MemberSource (22,308) · Travis County CU (2,996) — ~75k Texans across Houston and Austin OAG filings.
  2. MFA: Prefer app/hardware MFA for staff portals — SMS/phone OTP carries SIM-swap risk.
  3. This week: voice-callback on wire/ACH; backup every workstation; run free domain checks for members who ask.
  4. League value: free self-check at audit.emailmenow.com — no signup (QR at right).

Member benefit

EmailMeNow QR code linking to free domain self-check at audit.emailmenow.com

Scan for a free email / domain check

audit.emailmenow.com

No signup · 60 seconds

Stronger than SMS: authenticator app MFA on a phone next to a hardware security key on a laptop

Credit-union cyber watch · prefer app / hardware MFA over SMS · named Texas CU OAG incidents below

1. Why credit unions stay high-value targets

Credit unions concentrate member SSNs, account numbers, and trusted brand email — the same ingredients attackers use for ransomware extortion, BEC wire redirects, and account-takeover after SIM-swap. League and coalition messaging that pairs member protection with practical controls travels further than vendor fear alone.

Threat pattern Why it matters to CUs Control that works
Ransomware + unencrypted files Member PII becomes immediately usable after exfiltration Encryption at rest · tested offline / immutable backups on every machine
Spoofed CU / vendor email (BEC) Lookalike domains with live MX send “updated wiring” messages Enforced DMARC · voice-callback to a number already on file
SMS MFA / SIM-swap Phone OTP is stealable at the carrier; attackers then drain accounts Authenticator-app TOTP or hardware security keys for staff & high-risk members
Delayed breach notice Long forensic windows before letters go out — members stay exposed Documented IR plan · counsel + regulator notification checklist

2. Named Texas credit-union incidents (peer signal)

Three Texas-based credit unions on the Texas OAG portal (~75,000 Texans combined), sorted by Texans affected. Counts are portal totals — not proof of root cause. Same BEC / vendor-payment patterns hit Brazos Valley utilities and ESDs in 2025–26.

Credit union (Texas-based) Base Texans affected Published / notes
Energy Capital Credit Union Houston 49,664 Jan 5, 2026 OAG · network access Oct–Nov 2024 · SSN / DL / financial / DOB fields · FOG ransomware claim in secondary coverage
MemberSource Credit Union Houston 22,308 May 11, 2026 OAG · intrusion Jun 2025 · SafePay claim · unencrypted member data reported
Travis County Credit Union Austin 2,996 Jul 31, 2026 OAG · SSN / DL / financial / DOB · website notice + U.S. Mail

Also notified Texans (out-of-state HQ on Texas OAG list): Carter FCU (LA) 8,897 · Neighbors CU (MO) 2,564 · Fairmont FCU (WV) 1,206 · Connex (CT) 965 · Educational Employees CU (CA) 949 · and others.

Living tracker: Texas banks & credit unions OAG · MemberSource brief · Jul 31 week (Travis County CU). Ransomware “claims” are intelligence leads until the CU confirms. Source: Texas OAG Data Security Breach Reports.

3. Major Texas breaches members ask about — 2026 YTD

Through late July 2026, Texas OAG listings approached ~370 notices / ~29.7M Texans (OAG YTD tracker). Credit-union detail stays in §2; below is non-CU scale context only.

Incident Approx. when Scale / notes
Conduent Business Services 2026 YTD ~12.8 million Texans — largest published OAG report this year
DentaQuest, LLC 2026 YTD ~3.97 million Texans listed on OAG portal
Texas Parks & Wildlife license vendor Jun 2026 ~3.09 million Texans — DL / passport / contact fields

4. IT tips for CU / league operations

  • Treat lookalike domains as a brand issue — near-spellings with live MX can spoof “Member Services” or “Wire Desk.”
  • Lock wire / ACH workflows — written voice-callback for any change to payment instructions.
  • Ransomware backups for every machine — laptops and branch PCs, not just the core server; test restores.
  • Separate core banking from domain email trust — a solid core vendor does not fix SPF/DKIM/DMARC on the public domain.

5. Tips staff can use this week

  • Never trust Windows + R / Ctrl + V from a website “CAPTCHA.”
  • Wire / ACH changes only by voice callback to a number already on file.
  • Prefer authenticator-app or hardware MFA over SMS for email, VPN, and admin portals.
  • Free 60-second self-check: audit.emailmenow.com.

Reminder: app MFA and hardware security keys beat SMS codes — harder for SIM-swap thieves to steal (illustration above)

6. Tip cards (newsletters, member notes)

Tip - Member wire desk

BEC often starts with a spoofed CU or title-company “from” address. Enforced DMARC makes many forgeries fail in the inbox.

Tip - ACH callback

Change banking details only after a voice callback to a number already on file — never the number in the email.

Tip - Ransomware backups

Back up all machines — every laptop, desktop, and server. Keep at least one copy offline or immutable.

Tip - MFA stronger than SMS

Use an authenticator app or hardware security key for staff email and admin portals — not text-message codes alone.

Tip - Member education line

Add one line to member emails: “Run a free domain check at audit.emailmenow.com” — zero-cost hygiene nudge for small-business members.

Tip - Phishing CAPTCHA

Fake CAPTCHA pages that ask for keyboard shortcuts are malware. Use in staff security moments.

7. Related reading

8. How EmailMeNow can help (optional)

As a College Station IT consultant and B/CS Chamber member, we help leagues, coalitions, and credit-union IT / MSPs harden domain email trust — complementary to core processors and security vendors, not a replacement for them.

9. Glossary — tech terms used in this bulletin

TermPlain-language meaning
ACHAutomated Clearing House — U.S. bank network for electronic payments. Attackers often try to redirect ACH with fake “new account” emails.
BECBusiness email compromise — fraud that impersonates a trusted person or brand to trick someone into paying money or sharing data.
CAPTCHA“Prove you’re not a robot” check. Fake CAPTCHA pages that ask for keyboard shortcuts are malware lures.
DKIMDomainKeys Identified Mail — a digital signature on outgoing email proving the domain authorized the message.
DMARCDomain policy that tells receivers what to do with mail that fails SPF/DKIM. Enforced DMARC blocks many spoofed “from” addresses.
GLBAGramm-Leach-Bliley Act — U.S. law requiring financial institutions to safeguard customer information (with FTC Safeguards Rule standards).
MFAMulti-factor authentication — second check after the password. App or hardware MFA is stronger than SMS because of SIM-swap risk.
MSPManaged service provider — an outside IT company that supports systems day to day.
MXMail exchanger (DNS) — where email for a domain is delivered. A lookalike domain with live MX can send spoofed CU mail.
NCUANational Credit Union Administration — federal regulator / insurer for federally insured credit unions.
OAGOffice of the Attorney General (Texas) — publishes data security breach reports affecting Texans.
RansomwareMalware that encrypts files and demands payment. Recovery needs tested backups of every machine, including offline / immutable copies.
SIM-swapAttack that takes over a mobile number at the carrier so SMS one-time codes go to the attacker.
SPFSender Policy Framework — DNS list of servers allowed to send email for your domain.