Fraud Alerts
TruStage Update
Forge Credit Union has been in communication with TruStage Insurance regarding the cybersecurity incident they are actively working to resolve. As part of their response, TruStage has proactively taken their systems offline to conduct a thorough review of their environment. They have also engaged an external cybersecurity firm to support containment, remediation, and recovery efforts.
At this time, TruStage has not indicated whether any member information was accessed or compromised. As always, we encourage you to monitor your accounts and stay alert to unsolicited calls, emails, or text messages. Never share personal information with anyone you don’t know, and when in doubt, contact companies using the phone numbers listed on their official websites.
While TruStage core systems are offline, members can begin claims here: New Claim Submission Page
We understand how important clear information is during situations like this. Unfortunately, this is all the detail currently available to Forge Credit Union. TruStage has launched an information hub for members and will continue to update it as more information becomes available.
The new hub is their central source for information and includes:
- General updates and information
- Forms and resources
- The ability to start a claim
- Answers to common questions
TruStage Outage Information Hub for Members
Forge Credit Union systems are not affected and remain fully operational. Online and Mobile Banking continue to be safe, secure, and available.
The New “Social” Trap: Why Your Next Party Invite Might Be a Cyberattack
In the world of digital security, we are used to frantic emails about locked bank accounts or “urgent” tax penalties. Now, a more sophisticated and emotional tactic is on the rise: the fake social invitation.
By mimicking popular digital invitation platforms like Paperless Post or Evite, scammers are moving away from fear and toward our desire for connection. These fake invitations appear to come from a friend or former colleague, inviting you to a dinner, birthday, or holiday gathering. Because the sender’s name is familiar, our natural instinct is excitement – not skepticism.
How the Scam Works
There are typically two ways these attacks compromise your security:
- The Silent Infection: You click a link that appears “broken.” While nothing seems to happen, the click triggers a malware download in the background that quietly harvests your passwords and personal data.
- The Credential Theft: The link directs you to a fake login page. If you enter your email and password to “view the invite,” hackers gain full access to your accounts, allowing them to reset bank passwords or steal your identity.
How to Protect Yourself
- Check the Details: Generic invites for a “party” or “celebration” are red flags. Real invitations usually include specific details like a book club title or a specific occasion.
- Inspect the Sender: Hover over the “From” address. If it doesn’t match the official domain of the service (e.g., @paperlesspost.com), delete it.
- Verify Offline: If an invite feels unexpected, send a quick text to your friend to confirm they actually sent it.
- Use MFA: Always enable Multi-Factor Authentication (MFA) on your email. Even if a scammer steals your password, they won’t be able to log in without that secondary code.
- NEVER click or tap a link in a text or email until you have verified it is legit and the sender is who you think it is.
Taking just a few extra minutes to verify the identity of the person who sent the text could save you a lot of time, money and headaches from someone hijacking your accounts.
How Can We Help You?
Contact us with your questions!