TruStage Data Breach: Is There a Settlement? (August 2026 Status)
TruStage — the Madison, Wisconsin insurer formerly known as CUNA Mutual Group, which says it serves 93% of America's credit unions and 42 million consumer relationships — identified a broad cyberattack on July 11, 2026 and shut its own network down to contain it. The shutdown knocked out GAP claims, payment protection, and annuity services for credit unions nationwide for weeks. Fourteen class actions are already on file. But here's the honest status: no settlement exists, no claim form exists — and TruStage has not yet confirmed whether any member data was accessed at all.
Last reviewed: April 2026
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What Happened — and What the Lawsuits Allege
On July 11, 2026, TruStage identified what it calls a 'particularly broad attack' on its network and proactively shut down its systems to contain it. CEO Terrance Williams later said the likely cause was an employee inadvertently downloading a malicious file while trying to install a legitimate tool. No ransomware group has been publicly named, and TruStage has not attributed the attack. The shutdown disrupted the insurance plumbing thousands of credit unions rely on — GAP insurance claims, mechanical repair coverage, payment and debt protection, lending processes, annuity transactions, and life-insurance servicing — for weeks. The lawsuits allege TruStage failed to implement industry-standard cybersecurity safeguards and left credit unions and their members exposed and without services. Forensic specialists at Mandiant are still investigating whether data was taken.
Case Details
As of August 14, 2026, TruStage faces 14 proposed class actions in the U.S. District Court for the Western District of Wisconsin, filed by credit unions, individual consumers, and a medical practice. The first — Bessemer System Federal Credit Union v. TruStage Financial Group, Inc., No. 3:26-cv-00644 — was filed on July 17, 2026, just two days after disclosure. There is NO settlement administrator and NO official claims site for this incident — none exists. Law firms including Cafferty Clobes Meriwether & Sprengel, Shamis & Gentile, and Wilshire Law Firm are screening potentially affected credit union members.
Current Status
Who Is Affected?
The number of affected people has not been disclosed — in fact, TruStage has not yet confirmed that any personal data was accessed at all (as of August 14, 2026). Treat any site quoting a total with suspicion. What IS confirmed: TruStage says it serves 93% of America's credit unions and roughly 42 million consumer relationships, and the shutdown disrupted services at credit unions nationwide. You may have a TruStage connection without knowing it — if you bought GAP coverage, payment or debt protection, mechanical repair coverage, life insurance, or an annuity through your credit union, TruStage likely administers it and holds your information. If data exposure is confirmed, TruStage says credit union partners will be told first, and individual notification letters would follow.
Is There a Payout?
Timeline
- 1
July 11, 2026 — Attack Identified, Network Shut Down
TruStage identifies what it later calls a 'particularly broad attack' on its network and systems, and proactively shuts down large parts of its own network to contain it. The likely entry point, per CEO Terrance Williams: an employee inadvertently downloaded a malicious file while trying to install a legitimate tool.
- 2
July 15–16, 2026 — Public Disclosure, Nationwide Disruption
TruStage publicly discloses the cybersecurity incident. Credit unions across the country report disrupted services: GAP insurance claims, mechanical repair coverage, payment and debt protection, lending support, annuity transactions, and life-insurance servicing all run through TruStage's systems.
- 3
July 17, 2026 — First Class Action, Two Days After Disclosure
Bessemer System Federal Credit Union of Greenville, Pennsylvania files the first proposed class action (No. 3:26-cv-00644, W.D. Wis.), alleging TruStage failed to maintain industry-standard cybersecurity safeguards. It seeks to represent credit unions nationwide — and their affected members.
- 4
Late July 2026 — Rebuild Instead of Restart
Rather than simply switching systems back on, TruStage rebuilds parts of its infrastructure, refreshes employee laptops, and brings in forensic specialists at Mandiant. On July 31 it announces that the majority of key processes should be operational by mid-August — and that it still does not know whether member data was accessed.
- 5
August 2026 — 14 Lawsuits; the Data Question Stays Open
By August 12, TruStage faces 14 proposed class actions in the Western District of Wisconsin from credit unions, consumers, and a medical practice. Claims processing resumes roughly a month after the attack. The forensic investigation has still not confirmed whether member data was accessed; no notification letters have gone out.
- 6
Settlement — Not Yet
Before any settlement could exist, several things have to happen first: forensics confirming what (if anything) was taken, individual notifications, and consolidation of the 14 suits. When a settlement fund, administrator, and claim form actually exist, this page will be updated with the official links and deadlines. Until then: there is nothing to file.
Scam & Misinformation Warnings
A high-profile attack on a company connected to 42 million consumer relationships is a magnet for fraud — especially while official facts are scarce. Watch for these:
Fake 'TruStage settlement claim' sites
No claims portal exists — the lawsuits were just filed and no data theft has even been confirmed. Any page, ad, or social post offering a TruStage payout form today is a scam or clickbait. When a real settlement comes, the administrator's URL will appear in court filings — and on this page.
Impostor calls, texts, and emails 'from TruStage or your credit union'
Outage confusion is a phisher's best friend: fraudsters pose as TruStage or your credit union and ask you to 'verify' account details, Social Security numbers, or one-time codes. TruStage has said that if member data is involved, credit union partners will be informed first — official word reaches you through your credit union or a mailed letter, not an inbound call or text demanding information.
Fee-charging 'lawsuit sign-up' or 'breach protection' services
Nobody legitimate charges to 'add you' to a class action — if a class is ever certified, affected people are included automatically. Credit freezes at Equifax, Experian, and TransUnion are free by law; skip any paid 'breach protection' upsell.
Frequently Asked Questions
Is there a TruStage data breach settlement?
No. As of August 14, 2026 there is no settlement, no claims administrator, and no fund. What exists: 14 proposed class actions in federal court in Wisconsin — filed by credit unions, consumers, and a medical practice — and an ongoing forensic investigation that has not yet confirmed whether member data was accessed. If exposure is confirmed and litigation proceeds, a settlement would be a 1–3 year path. Bookmark this page; we update it when anything changes.
Was my data actually stolen?
Nobody knows yet — and that includes TruStage. The company says it does not yet know whether member data was accessed; forensic specialists at Mandiant are investigating. No notification letters have been mailed as of August 14, 2026. TruStage has committed to informing affected credit union partners first if member personal information turns out to be involved, with individual notifications to follow. If you receive a letter, keep it — it documents that you're in the affected group.
I've never heard of TruStage — why would they have my data?
TruStage is the Madison, Wisconsin company formerly known as CUNA Mutual Group, founded in 1935. It is the insurance engine behind much of the U.S. credit union movement — the company says it serves 93% of America's credit unions and about 42 million consumer relationships. If you bought GAP coverage, payment or debt protection, mechanical repair coverage, life insurance, or an annuity through a credit union, there's a good chance TruStage administers it and holds your personal information.
How much money will I get?
Honestly: $0 today — there is no fund, and no data theft has even been confirmed. For a realistic reference point IF exposure is confirmed and a settlement eventually happens: comparable financial-data breach settlements have paid documented out-of-pocket losses (often capped around $2,500–$10,000) plus small pro-rata cash payments (typically $50–$100). That is speculation until an actual settlement exists.
What should I do right now?
Three things cost nothing: (1) Freeze your credit at Equifax, Experian, and TransUnion — the strongest protection if your Social Security number was exposed. (2) Watch your credit union statements, GAP or payment-protection claims, and annuity accounts for activity you don't recognize. (3) Treat any call, text, or email about 'the TruStage breach' with suspicion — official word comes through your credit union or a mailed letter. If TruStage offers free credit monitoring later, enroll.
Do I need to sign up for the lawsuits?
No. If any of the 14 class actions is certified or settled, everyone fitting the class definition is included automatically. Law firms such as Cafferty Clobes Meriwether & Sprengel, Shamis & Gentile, and Wilshire Law Firm are screening credit union members — filling out their forms means volunteering as a potential client or named plaintiff, which is optional.
When will there be a settlement?
This case is at the very start of the cycle, with one unusual twist: the lawsuits arrived before any data theft was confirmed. The milestones to watch, in order: Mandiant's forensic conclusion on whether member data was accessed; individual notification letters (these typically follow weeks to months after a forensic confirmation); consolidation of the 14 Wisconsin suits; then motions, discovery, and — in 1–3 years, if at all — a settlement. We update this page at each milestone.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.
Related Consumer Brand Lawsuits
Quantum Health Breach (count not disclosed)
Vendor breach — same no-settlement-yet stage
Conduent Breach (62.2M affected)
Consolidated litigation, no settlement yet
Unlimited Technology Systems Breach
Early class actions filed — same stage
Data Breach Settlement Calculator
All breach trackers + payout estimator