Data Breach

Last Reviewed: May, 2018

News stories about data breaches are becoming more common. Credit unions are required to implement measures to safeguard members’ information. Credit unions also must have procedures in place to respond to data breaches at other organizations or corporations that compromise members’ information.

What does a credit union need to do in the event there is unauthorized access of member information?
The National Credit Union Administration (NCUA) amended its security program requirements (Part 748 of the Rules and Regulations) to include a response program to address instances of unauthorized or attempted unauthorized access to member information. The final rule requires that every federally insured credit union develop and implement an Information Security and Response Program (ISRP) designed to address incidents of unauthorized access to member information maintained by the credit union or its service provider.

In addition, most states have requirements for notification in case of a security breach, (see Security Breach Notification Laws in Related Links)

Background Information
The Gramm-Leach-Bliley Act required the NCUA and other banking agencies to establish standards for their financial institutions relating to administrative, technical and physical safeguards of consumer records and information. The NCUA amended Part 748 of its Rules and Regulations and added Appendix A, "Guidelines for Safeguarding Member Information". The safeguards are intended to:

  1. Insure the security and confidentiality of member records and information;
  2. Protect against any anticipated threats or hazards to the security or integrity of such records; and
  3. Protect against unauthorized access to or use of such records or information that could result in substantial harm or inconvenience to a member.

Over the past few years there has been an increase in the number of breaches or attempted breaches of member information that has resulted in identity theft. To address this situation, amended Part 748, requiring credit unions to add to their security programs a response program that addresses incidents of unauthorized access to or use of member information that could result in substantial harm or serious inconvenience to a member. The rule includes Appendix B, "Guidance on Response Programs for Unauthorized Access to Member Information and Member Notice", which provides details of what should be included in these response programs.

The Federal Financial Institution Examinations Council (FFIEC) has established criteria to be used to evaluate the credit union’s information security program. NCUA and state regulators use these guidelines to evaluate the program during annual IT examinations.

Definitions
Information security and response program (ISRP) - establishes a formalized process to prevent, detect, and respond to security vulnerabilities with respect to maintaining member data integrity and confidentiality.

Member information system – any method used to access, collect, store, use, transmit, protect or dispose of member information, including systems maintained by service providers.

Security incident – an adverse event, or the threat of one, that affects the credit union’s computer network and/or information system. Security incidents can occur in innumerable ways and include, but are not limited to:

Sensitive member information – a member’s name, address, or telephone number, in conjunction with the member’s social security number, driver’s license number, account number, credit or debit card number, or a personal identification number or password that would permit access to the member’s account. It also includes any combination of components of member information that would allow someone to log onto or access the member’s account, such as user name and password or password and account number.

Appendix B to Part 748 – Guidance on Response Programs for Unauthorized Access to Member Information and Member Notice
The guidance in Appendix B to NCUA’s Part 748 describes response programs, including member notification procedures, that credit unions should develop and implement to address unauthorized access to or use of member information that could result in substantial harm or inconvenience to the member.

Response Program Components
The credit union’s response program should contain procedures which allow the credit union to:

Where an incident of unauthorized access to member information involves the credit union’s member information systems maintained by a credit union’s third-party service providers, it is the responsibility of the credit union to notify its members and regulator. However, a credit union may authorize or contract with its service provider to notify members or regulators on its behalf.

FFIEC exam questions:

Member Notification
When a credit union becomes aware of an incident of unauthorized access to sensitive member information, it should conduct a reasonable investigation to promptly determine the likelihood that the information has been or will be misused. If the credit union determines that misuse of its information about a member has occurred or is reasonably possible, it should notify the affected member as soon as possible.

Notice may be delayed if an appropriate law enforcement agency determines that the notification will interfere with a criminal investigation and provides the credit union with a written request for the delay. The credit union should notify its members as soon as notification will no longer interfere with the investigation.

After its investigation, if a credit union can determine from its logs or other data precisely which member information has been improperly accessed, it may limit notification to those members with regard to whom the credit union determines that misuse of their information has occurred or is reasonably possible. There may be situations where the credit union determines that a group of files has been accessed improperly, but is unable to identify which specific member’s information has been accessed. If the circumstances of the unauthorized access lead the credit union to determine that misuse of the information is reasonably possible, it should notify all members in the group.

FFIEC exam questions:

Notice Content
The notice should be clear and conspicuous, and should be delivered in any manner designed to ensure that the member can reasonably be expected to receive it. The credit union may choose to contact all affected members by telephone, mail, or electronic mail for those members for whom it has a valid e-mail address and who have agreed to receive communications electronically.

The notice should include the following information:

  1. Description of the incident in general terms and the type of member information that was the subject of unauthorized access or use;
  2. General description of what the credit union has done to protect the members’ information from further unauthorized access;
  3. A telephone number that members can call for further information and assistance;
  4. A reminder of the need to remain vigilant over the next twelve to twenty-four months, and to promptly report incidents of suspected identity theft to the credit union;
  5. A recommendation that the member review account statements and immediately report any suspicious activity to the credit union;
  6. A description of fraud alerts and an explanation of how the member may place a fraud alert in his or her credit report to put creditors on notice that the member may be a victim of fraud;
  7. A recommendation that the member periodically obtain credit reports from each nationwide credit reporting agency (CRA) and have information relating to fraudulent transactions deleted;
  8. An explanation of how the member may obtain a credit report free of charge* (www.annualcreditreport.com); and
  9. Information about the availability of the Federal Trade Commission’s (FTC) online guidance regarding steps that can be taken to protect against identity theft. The notice should encourage the member to report any incidents of identity theft to the FTC, and should provide the FTC’s website address (www.ftc.gov/idtheft) and toll-free telephone number (1-877-IDTHEFT) that members may use to obtain the identity theft guidance and report suspected incidents of identity theft.

If a credit union provides contact information for CRAs, NCUA encourages the credit union to notify the CRAs prior to sending this information to a large number of members.

FFIEC exam questions:

Media Response Components
An effective media response plan will help positively reinforce the public perception of the credit union. Consider integrating a media response plan as a component of the credit union’s information security and response program. The media response plan should cover a broad range of scenarios, ranging from general press releases to full-scale media assaults.

Like the credit union’s overall ISRP, the media response plan procedures should be regularly reviewed, including any pre-written statements, by the credit union’s attorney and media relations specialist. Procedures should document such areas as:

Pre-Emptive Measures the Credit Union Should Take to Mitigate Risk
In an effort to ensure compliance and avoid potential exposure to fines and/or lawsuits, the credit union may want to consider implementing the follow information and security response program procedures: