SETTLED

California regulator settles cybersecurity case with Patelco Credit Union after 2024 ransomware attack

Patelco Credit Union State charter · CA ~$9.8 billion in assets

Cyber vendor Governance oversight Member harm

California's DFPI settled cybersecurity violations with Patelco Credit Union for $100,000 after a 2024 ransomware attack disrupted banking services for weeks and exposed member data.

What happened

Patelco Credit Union, a California state-chartered credit union based in Dublin with roughly 500,000 members and about $9.8 billion in assets, was hit by a ransomware attack that shut down its core banking systems from June 29 to July 15, 2024. During that period members could not use online banking, check balances, or complete most electronic transactions; the credit union allowed limited $500-per-day withdrawals at ATMs and branches while systems were down.

In August 2024, Patelco disclosed to members that files taken during the attack included personal identifying information — names, Social Security numbers, driver’s license numbers, dates of birth, and email addresses — and offered affected members two years of complimentary credit monitoring. Trade press reporting citing Patelco’s own regulatory call-report filings put the credit union’s third-quarter 2024 losses connected to the incident, including overdraft costs it absorbed on members’ behalf, at more than $39 million.

California’s Department of Financial Protection and Innovation (DFPI), which licenses and examines Patelco as a state-chartered credit union, opened an investigation into Patelco’s cybersecurity systems and processes following the attack. That investigation resulted in a Consent Order, executed February 4, 2025. In it, DFPI ordered Patelco to cease and desist from what the order calls “unsafe and unsound acts” in its cybersecurity program, required Patelco to strengthen that program across six areas — risk management practices, IT risk-assessment processes, board reporting, the security control environment, business continuity management, and internal audit — and required Patelco to engage an independent compliance consultant to verify the work. Patelco also agreed to pay a $100,000 penalty. The order states explicitly that Patelco entered into it without admitting or denying DFPI’s findings or conclusions.

Separately, Patelco is a defendant in a consolidated member class action filed in Alameda County Superior Court (Case No. 24CV082095), alleging the credit union failed to reasonably protect members’ personal information. This page does not name the individual plaintiffs, consistent with this site’s policy of never identifying a credit union member — even where a name appears in a public case caption. Press coverage reports a proposed $7.25 million settlement, covering roughly one million current and former members, that does not require Patelco to admit wrongdoing.

Where it stands

The DFPI matter is resolved as a settlement: the Consent Order became final and binding when signed, and its terms — the $100,000 penalty, the cease-and-desist directive, and the compliance-consultant and reporting requirements — are now in effect. DFPI’s findings were not admitted by Patelco, and the order itself states it creates no private right of action for third parties and is not an admission with respect to any third party, including the pending civil litigation.

The class action settlement’s exact procedural timeline is harder to pin down from public trade-press reporting alone: coverage from mid-2025 describes a proposed settlement moving toward court approval, and later coverage describes preliminary court approval being granted on February 26, 2026, with a final approval hearing calendared for July 1, 2026. This page could not confirm, from a primary court document, the precise sequence of those steps or whether final approval has since been granted. That will be updated once confirmed from the court record or the settlement administrator’s own materials.

Questions this raises for your committee

The specific corrective-action areas DFPI required — business continuity, board reporting, independent testing, vendor due diligence, and IT risk assessment — map closely onto categories any supervisory committee can ask about at its own credit union, regardless of size or charter type. See the control lessons above.

Timeline

  1. 2024-06-29 A ransomware attack shut down core Patelco banking systems. Members lost access to online banking, balance information, and most electronic transactions; ATM and in-branch withdrawals were capped at $500 per day. Systems remained down through July 15, 2024.
  2. 2024-07-02 A class action lawsuit was filed against Patelco in Alameda County Superior Court on behalf of affected members, shortly after the outage began. [8]
  3. 2024-08-20 Patelco told members that files taken during the attack included personal identifying information such as Social Security numbers, driver's license numbers, dates of birth, and email addresses, and offered two years of complimentary credit monitoring. [4]
  4. 2024-11-05 Trade press reporting, citing Patelco's regulatory call report filings, put the credit union's third-quarter losses tied to the incident (including overdraft costs absorbed for members) at more than $39 million. [5]
  5. 2024-11-14 DFPI communicated the corrective-action requirements from its examination to Patelco, covering risk management, IT risk assessment, board reporting, the security control environment, business continuity, and internal audit.
  6. 2025-02-04 DFPI and Patelco executed a Consent Order directing Patelco to cease and desist from unsafe and unsound practices in its cybersecurity program, paying a $100,000 penalty and agreeing to engage an independent compliance consultant. Patelco entered the order without admitting or denying DFPI's findings.
  7. 2025-06-15 Reporting on the consolidated member class action (Alameda County Superior Court, Case No. 24CV082095) described a proposed $7.25 million settlement moving toward preliminary court approval; coverage states the settlement does not require Patelco to admit or deny wrongdoing. [8]
  8. 2026-02-26 Later reporting states the Alameda County Superior Court granted preliminary approval of the class settlement on this date. This page could not fully reconcile the exact procedural sequence between mid-2025 and early-2026 court filings from secondary sources alone; the core facts (a ~$7.25 million settlement, no admission of wrongdoing, and a claims process) are corroborated across multiple sources. [7]
  9. 2026-07-01 A final approval hearing for the class settlement was scheduled for this date. This page has not been able to confirm the outcome of that hearing from a primary source; see 'Where it stands' below. [7]

Questions this raises for your committee

If your core system or online banking platform went down for two weeks, does your credit union have a tested plan for verifying member balances, processing essential transactions, and communicating with members in the meantime?

Patelco's DFPI consent order required a strengthened business continuity program as one of six corrective-action areas. Regardless of what happened at any one institution, business continuity plans that exist only on paper are a common gap examiners and auditors flag.

Does your board or supervisory committee receive a documented, at least annual report on the state of the credit union's cybersecurity program, including risk assessment results and incident response testing, or is cybersecurity treated as purely a management/IT matter?

The consent order specifically required board-level reporting on the cybersecurity program. NCUA guidance to credit union boards likewise frames cybersecurity oversight as a board-level responsibility, not something to delegate entirely to IT staff.

What due diligence does your credit union perform on the cybersecurity and incident-response commitments of its core processor and other key service providers, and who reviews that due diligence?

NCUA's own supervisory priorities describe ongoing due diligence of critical service providers as the credit union's responsibility — NCUA does not have direct examination authority over most core processors, cloud providers, or fintech vendors. That makes the credit union's own due diligence the primary layer of oversight for vendor-related risk.

When was the last time an independent party — internal audit or an outside assessor — tested your credit union's cybersecurity controls and incident response plan, and did the results reach your committee directly, or only a management summary?

Independent testing of the cybersecurity program was one of the specific areas DFPI required Patelco to strengthen. A summary from management is not the same as visibility into what an independent test actually found.

Sources

  1. primary Consent Order, In the Matter of Patelco Credit Union — California Department of Financial Protection and Innovation (DFPI), 2025-02-04
  2. primary DFPI Takes Action Against Patelco Credit Union for Cybersecurity Violations — California Department of Financial Protection and Innovation (DFPI), 2025-02-04
  3. secondary Ransomware attack on Patelco Credit Union causes confusion ahead of holiday weekend — The Record (Recorded Future News), 2024-07-03
  4. secondary Patelco Credit Union says personal information of customers, employees exposed in June data breach — CBS News San Francisco, 2024-08-21
  5. secondary Patelco Loses $39 Million During Last Summer's Hack — Credit Union Times, 2024-11-05
  6. secondary California financial watchdogs hit Patelco with $100,000 fine — American Banker, 2025-02-04
  7. secondary $7.25M Patelco Credit Union Settlement Ends Class Action Lawsuit Over Data Breach Discovered June 2024 — ClassAction.org, 2026-03-31
  8. secondary Patelco agrees to settle class-action lawsuit over cyberattack for $7.25M — Pleasanton Weekly, 2025-06-15

Update log

First published 2026-07-23 · Last reviewed 2026-07-23

This is not legal, accounting, or compliance advice. Verify against the official source and your own professional advisors.