Investigation

PAID ON FAITH: TRUSTAGE CYBERATTACK LEAVES PRENEED FUNERAL POLICIES IN LIMBO AS 14 SUITS PILE UP

A Houston funeral director cannot verify his two TruStage contracts exist. Missouri families fronted funeral costs. The insurer's first court answer is due Sept. 24.

Heidi MacomberSeptember 1, 20266 min read read

Joe Earthman holds two TruStage contracts at Joseph Earthman Generations, his Houston funeral home, and in late August he could verify neither. "We've got no idea when we're going to get paid," he told the trade publication ConnectingDirectors on Aug. 25. "We haven't even been able to verify that these policies even exist."

Those contracts are preneed policies, life insurance bought ahead of death to cover a planned funeral. TruStage, the insurer formerly known as CUNA Mutual Group, has underwritten what ConnectingDirectors calls "a huge share of the prearranged funeral policies sold through credit unions nationwide." Six weeks after the company took its own network offline to contain a cyberattack, funeral homes are still counting the cost.

The attack and the shutdown

TruStage said it identified the attack on July 11 and described it in a July 31 statement as "a particularly broad attack on our network and systems." A spokesperson told American Banker the company "proactively shut down our network" to respond and "disclosed the incident publicly on July 15." The statement said TruStage had rebuilt "parts of our infrastructure" and was "now bringing systems and applications back online."

It declared "the incident has been contained" and set a timeline: "we anticipate that the majority of our key processes will be operational by mid-August, with priority placed on the operations most critical to partners and their members."

Bessemer's amended complaint says the intrusion began "when a TruStage representative downloaded malware." A TruStage spokesperson told American Banker a worker "may have inadvertently downloaded a malicious file while trying to install a legitimate utility."

Fourteen suits, mostly consumers

At least 14 proposed class actions are pending against TruStage in the Western District of Wisconsin. The first came July 17 from Bessemer System Federal Credit Union of Greenville, Pennsylvania. A July 29 court order listed 13 case numbers, and a 14th suit arrived the same day, according to the CourtListener docket.

The plaintiff mix matters. Bessemer is "the only credit union plaintiff," and "twelve of the 13 are consumer suits," American Banker reported. KMOV counted the same total on Aug. 26: "it faces 14 class-action lawsuits."

Bessemer's suit alleges that TruStage "failed to implement and maintain adequate, industry-standard cybersecurity safeguards, culminating in the cybersecurity incident TruStage disclosed on July 15, 2026." It proposes a nationwide class and seeks damages and reimbursement of breach-related expenses.

Funerals fronted on faith

Mary Farmer, 71, died Aug. 8. Her body was held at Officer Funeral Home in East St. Louis while her brother fronted the costs, KMOV/First Alert 4 reported Aug. 26. TruStage told the station both referenced claims were "resolved favorably."

The Missouri Funeral Directors and Embalmers Association said two more Missouri homes performed funerals while awaiting TruStage payment. It also said a consumer could not update a funeral policy for a Medicaid application. In Mississippi, a funeral home warned of scammers posing as TruStage representatives. TruStage has said it is "not encouraging, facilitating, or participating in any effort to replace, surrender, or discontinue active insurance coverage related to this incident or our ongoing business recovery efforts."

ConnectingDirectors described homes as fronting services on faith that a policy is valid and collectible. Earthman's warning is about scale: "If you had 10 to 20 contracts, that could really affect your cash flow."

Claims payments resumed. A spokesperson told American Banker the week of Aug. 11 that the company had begun "processing and paying claims," including GAP and recurring debt protection benefits. The spokesperson would not confirm the mid-August target had been met; the status page still said "Investigating" as of Aug. 12. CU Today, cited by ConnectingDirectors, reported payments had restarted "including preplanning and funeral claims."

The gap that remains

TruStage confirmed to NAPA that the attack "did not impact annuity and retirement plan assets." Its Aug. 17 update still warned customers they "may experience difficulty accessing account information, completing transactions or submitting requests online."

What is missing is scale. Per American Banker, TruStage has not identified an attacker or confirmed a ransom demand. It also has not said how many credit unions, businesses, or people were affected. "While we do not yet know whether member data was accessed, if we determine that members' personal information is involved, we will let affected partners know first," the July 31 statement said. Mandiant and internal teams are "working diligently on that investigation," it added.

Who had to tell whom, and when

TruStage's disclosure duties sit with its home-state insurance regulator. As a Wisconsin insurer it falls under 2021 Wisconsin Act 73, the state's version of the NAIC Insurance Data Security Model Law, a framework other states have also adopted.

The Wisconsin law runs on a determination trigger. A licensee must tell the commissioner "as promptly as possible, but no later than 3 business days from the determination that the cybersecurity event occurred." As of late August, TruStage had not said it had determined member data was accessed. If that determination comes, the statute gives consumers their own clock: notice within a reasonable time, "not to exceed 45 days after the licensee learns of the acquisition" of their information. The company must also tell the producer of record, the agent who sold the policy, no later than the consumer notice. Law enforcement can ask that notice be delayed.

The credit-union side answers to different rules. Federal banking regulators give banks 36 hours to report a computer-security incident, under 12 CFR part 53. The NCUA gives federally insured credit unions 72 hours to report a cyber incident, and its rule reaches vendors: when the incident is at a third party, the clock can run from "being notified by a third-party, whichever is sooner."

A credit union that deemed the TruStage outage a reportable incident had 72 hours to tell the NCUA. TruStage has not said how many of the credit unions it serves made that call.

Both streams leave records that can be requested. NCUA incident reports fall under the Freedom of Information Act. Wisconsin makes licensees keep cybersecurity-event records for at least five years, and OCI's copies fall under the state's public-records law.

One gap sits outside both rulebooks. Insurers and credit unions operate under mandated security programs. The funeral homes that sold the same families preneed policies face no comparable data-security rule, and the intrusion itself began, per the complaint, when one employee downloaded one file.

What comes next

TruStage's answer to Bessemer is due Sept. 24. Five plaintiffs have moved to consolidate the cases into credit-union and business tracks and consumer tracks; no ruling has issued. Bessemer amended its complaint July 31 to add a Kitty Hawk, North Carolina medical practice that could not access or fund its 401(k)s. Watch for the Mandiant findings and any member notifications.

What This Means for You

One underwriter's outage became an industry problem. TruStage's own figures, cited by American Banker, cover 93% of credit unions and 42 million consumer relationships.
Payments resumed, funeral claims included, though homes were still verifying policies weeks into recovery.
The open questions are the ones families ask first: whether member data was accessed, and how many people are affected.

*Sources: TruStage newsroom statement, July 31, 2026; American Banker, August 2026; ConnectingDirectors, Aug. 25, 2026; KMOV/First Alert 4, Aug. 26, 2026; NAPA, Aug. 17, 2026; Bessemer System FCU federal complaint, July 17, 2026; U.S. District Court order, Western District of Wisconsin, July 29, 2026, via CourtListener; CU Today via ConnectingDirectors; Wis. Stat. § 601.954 (2021 Wis. Act 73); Wis. Stat. § 601.953(3); 12 CFR 53.1; 12 CFR 748.1(c).*

trustagecuna mutualpreneedcyberattackwisconsincredit unionsclass actiondata securityfuneral insurancefuneral homes
ShareXinf@

Get investigations like this in your inbox

Free. Every Tuesday.