news.cuna.org/articles/120491-cisa-issues-alerts-relating-to-russian-cyberthreats-ukraine-cyber-incidents
Cybersecurity Safeguards

CISA issues alerts relating to Russian cyberthreats, Ukraine cyber incidents

February 24, 2022

The U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) issued two alerts addressing risks from Russian State-Sponsored cyber threats and highlighting recent malicious cyber incidents suffered by public and private entities in Ukraine.

NCUA, along with CISA, the Federal Bureau of Investigation, and the National Security Agency encourage credit unions and their cybersecurity teams nationwide to adopt a heightened state of awareness and to conduct proactive threat hunting.

In addition, COVID-related supply chain disruptions may require management to reevaluate previously held assumptions for business continuity and disaster recovery plans.

Credit union leadership should be aware of critical cyber risks and take urgent steps to reduce the likelihood and impact of a potentially damaging compromise.

NCUA encourages credit unions to review the two CISA issuances and act on the applicable recommendations. 

The NCUA recently created the Automated Cybersecurity Evaluation Toolbox (ACET) for federally insured credit unions to evaluate their cybersecurity posture. For more information, please visit the NCUA’s cybersecurity resources website.

Credit unions that experience a cyber incident, should contact FBI’s 24/7 Cyber Watch at 855-292-3937 or by e-mail at CyWatch@fbi.gov. When available, please include the following information regarding the incident: date, time, and location of the incident; type of activity; number of people affected; type of equipment used for the activity; the name of the submitting company or organization; and a designated point of contact.

To request incident response resources or technical assistance related to these threats, contact CISA at CISAServiceDesk@cisa.dhs.gov or 888-282-0870. We also encourage credit unions to report identified cybersecurity incidents to their district examiner and EIMAIL@NCUA.GOV as soon as practicable.