Credit Union Coalition of Texas · Advocacy member contribution
August 2026 Credit Union IT & Cyber Bulletin
Texas credit-union breach and email-security watch, board talking points, and practical tips member CUs can use this week — plus a free domain self-check (QR below). Prepared by a College Station IT consultant focused on email and domain security.
| Audience | Credit Union Coalition of Texas leadership and member credit unions (shareable with compliance / IT or your MSP) |
|---|---|
| This month’s watch | Texas: Energy Capital · MemberSource · Travis County CU OAG filings · TX CU email-security gaps · wire/ACH · SIM-swap MFA |
| Coalition benefit | Free domain self-check at audit.emailmenow.com — no signup |
| Offer | Glad to spend 30 minutes with you or your IT team on domain email trust — no obligation |
What to tell the board
- Capitol-adjacent risk (§2): Three Texas-based CUs on OAG notices (~75k Texans) — Energy Capital (49,664) · MemberSource (22,308) · Travis County CU (2,996, Austin).
- Member harm path: spoofed CU “from” addresses + SMS MFA SIM-swap still drive account takeover and wire fraud.
- This week: voice-callback on payment changes; prefer app/hardware MFA; free domain self-check for members.
- Coalition value: free check at audit.emailmenow.com — no signup (QR at right).
Credit-union cyber watch · prefer app / hardware MFA over SMS · named Texas CU OAG incidents below
1. Why credit unions stay high-value targets
Credit unions concentrate member SSNs, account numbers, and trusted brand email — the same ingredients attackers use for ransomware extortion, BEC wire redirects, and account-takeover after SIM-swap. League and coalition messaging that pairs member protection with practical controls travels further than vendor fear alone.
| Threat pattern | Why it matters to CUs | Control that works |
|---|---|---|
| Ransomware + unencrypted files | Member PII becomes immediately usable after exfiltration | Encryption at rest · tested offline / immutable backups on every machine |
| Spoofed CU / vendor email (BEC) | Lookalike domains with live MX send “updated wiring” messages | Enforced DMARC · voice-callback to a number already on file |
| SMS MFA / SIM-swap | Phone OTP is stealable at the carrier; attackers then drain accounts | Authenticator-app TOTP or hardware security keys for staff & high-risk members |
| Delayed breach notice | Long forensic windows before letters go out — members stay exposed | Documented IR plan · counsel + regulator notification checklist |
2. Named Texas credit-union incidents (advocacy signal)
Three Texas-based credit unions on the Texas OAG portal (~75,000 Texans combined) — useful when briefing members or answering “does this happen in Texas?” Counts are portal totals — not proof of root cause.
| Credit union (Texas-based) | Base | Texans affected | Published / notes |
|---|---|---|---|
| Energy Capital Credit Union | Houston | 49,664 | Jan 5, 2026 OAG · network access Oct–Nov 2024 · SSN / DL / financial / DOB fields · FOG ransomware claim in secondary coverage |
| MemberSource Credit Union | Houston | 22,308 | May 11, 2026 OAG · intrusion Jun 2025 · SafePay claim · unencrypted member data reported |
| Travis County Credit Union | Austin | 2,996 | Jul 31, 2026 OAG · SSN / DL / financial / DOB · website notice + U.S. Mail |
Also notified Texans (out-of-state HQ on Texas OAG list): Carter FCU (LA) 8,897 · Neighbors CU (MO) 2,564 · Fairmont FCU (WV) 1,206 · Connex (CT) 965 · Educational Employees CU (CA) 949 · and others.
Living tracker: Texas banks & credit unions OAG · MemberSource brief · Jul 31 week (Travis County CU). Ransomware “claims” are intelligence leads until the CU confirms. Source: Texas OAG Data Security Breach Reports.
3. Major Texas breaches members ask about — 2026 YTD
Through late July 2026, Texas OAG listings approached ~370 notices / ~29.7M Texans (OAG YTD tracker). Credit-union detail stays in §2; below is non-CU scale context only.
| Incident | Approx. when | Scale / notes |
|---|---|---|
| Conduent Business Services | 2026 YTD | ~12.8 million Texans — largest published OAG report this year |
| DentaQuest, LLC | 2026 YTD | ~3.97 million Texans listed on OAG portal |
| Texas Parks & Wildlife license vendor | Jun 2026 | ~3.09 million Texans — DL / passport / contact fields |
4. IT tips for CU / league operations
- Treat lookalike domains as a brand issue — near-spellings with live MX can spoof “Member Services” or “Wire Desk.”
- Lock wire / ACH workflows — written voice-callback for any change to payment instructions.
- Ransomware backups for every machine — laptops and branch PCs, not just the core server; test restores.
- Separate core banking from domain email trust — a solid core vendor does not fix SPF/DKIM/DMARC on the public domain.
5. Tips staff can use this week
- Never trust Windows + R / Ctrl + V from a website “CAPTCHA.”
- Wire / ACH changes only by voice callback to a number already on file.
- Prefer authenticator-app or hardware MFA over SMS for email, VPN, and admin portals.
- Free 60-second self-check: audit.emailmenow.com.
Reminder: app MFA and hardware security keys beat SMS codes — harder for SIM-swap thieves to steal (illustration above)
6. Tip cards (newsletters, member notes)
BEC often starts with a spoofed CU or title-company “from” address. Enforced DMARC makes many forgeries fail in the inbox.
Change banking details only after a voice callback to a number already on file — never the number in the email.
Back up all machines — every laptop, desktop, and server. Keep at least one copy offline or immutable.
Use an authenticator app or hardware security key for staff email and admin portals — not text-message codes alone.
Add one line to member emails: “Run a free domain check at audit.emailmenow.com” — zero-cost hygiene nudge for small-business members.
Fake CAPTCHA pages that ask for keyboard shortcuts are malware. Use in staff security moments.
7. Related reading
8. How EmailMeNow can help (optional)
As a College Station IT consultant and B/CS Chamber member, we help leagues, coalitions, and credit-union IT / MSPs harden domain email trust — complementary to core processors and security vendors, not a replacement for them.
- Free CU self-check anytime: audit.emailmenow.com
- Glad to spend 30 minutes with you or your IT team on domain email trust — no obligation: book.emailmenow.com
9. Glossary — tech terms used in this bulletin
| Term | Plain-language meaning |
|---|---|
| ACH | Automated Clearing House — U.S. bank network for electronic payments. Attackers often try to redirect ACH with fake “new account” emails. |
| BEC | Business email compromise — fraud that impersonates a trusted person or brand to trick someone into paying money or sharing data. |
| CAPTCHA | “Prove you’re not a robot” check. Fake CAPTCHA pages that ask for keyboard shortcuts are malware lures. |
| DKIM | DomainKeys Identified Mail — a digital signature on outgoing email proving the domain authorized the message. |
| DMARC | Domain policy that tells receivers what to do with mail that fails SPF/DKIM. Enforced DMARC blocks many spoofed “from” addresses. |
| GLBA | Gramm-Leach-Bliley Act — U.S. law requiring financial institutions to safeguard customer information (with FTC Safeguards Rule standards). |
| MFA | Multi-factor authentication — second check after the password. App or hardware MFA is stronger than SMS because of SIM-swap risk. |
| MSP | Managed service provider — an outside IT company that supports systems day to day. |
| MX | Mail exchanger (DNS) — where email for a domain is delivered. A lookalike domain with live MX can send spoofed CU mail. |
| NCUA | National Credit Union Administration — federal regulator / insurer for federally insured credit unions. |
| OAG | Office of the Attorney General (Texas) — publishes data security breach reports affecting Texans. |
| Ransomware | Malware that encrypts files and demands payment. Recovery needs tested backups of every machine, including offline / immutable copies. |
| SIM-swap | Attack that takes over a mobile number at the carrier so SMS one-time codes go to the attacker. |
| SPF | Sender Policy Framework — DNS list of servers allowed to send email for your domain. |