Patelco Credit Union ransomware attack shuts down banking systems for weeks

Organization
Patelco Credit Union
Exploit
Ransomware
Industry
Financial Services

Patelco Credit Union, a member-owned, not-for-profit institution headquartered in Dublin, California, took its banking systems offline after detecting a ransomware attack on 29 June 2024. It confirmed the incident publicly on 1 July. Patelco serves close to half a million members through dozens of branches in Northern California and holds more than 9 billion dollars in assets.

The shutdown removed nearly every electronic service. Online and mobile banking, direct deposits, transfers, balance inquiries, monthly statements, online bill payment, Zelle, and debit and credit card transactions were all unavailable, and ATM withdrawals were capped at 500 dollars. Members queued at branches to move money, and some reported bounced payments and late fees while their accounts were inaccessible.

Chief executive Erin Mendez said the priority was the safe and secure restoration of banking systems and warned that the following days and weeks would present challenges for members. Patelco worked with outside cybersecurity specialists, and pledged to reimburse late fees and waive overdraft charges tied to the outage. Core functions remained degraded until roughly the middle of July.

The RansomHub group later claimed responsibility and posted Patelco to its leak site in August after negotiations failed. Investigators dated the initial intrusion to 23 May, with discovery on 29 June. Patelco first reported around 726,000 people affected in late August, then revised the total to 1,009,472, with exposed data including names, dates of birth, Social Security numbers, driver's licence numbers and email addresses. Two years of credit monitoring were offered.

Sources