Please ensure Javascript is enabled for purposes of website accessibility

Cybersecurity risks for credit unions: What MD customers should know

The 25,700 square-foot building at 1215 York Road in Lutherville-Timonium was owned and occupied by First Financial of Maryland Federal Credit Union. (File photo)

The 25,700 square-foot building at 1215 York Road in Lutherville-Timonium was owned and occupied by First Financial of Maryland Federal Credit Union. (File photo)

Cybersecurity risks for credit unions: What MD customers should know

Listen to this article

Although offer a more personal, community-based alternative to large, national banks, they have just as many responsibilities to their users to maintain protocols as those institutions. Smaller and mid-sized credit unions face many of the same threats as major financial institutions, often with fewer staff and fewer resources.

In August, a data breach of Marquis, a provider of marketing and compliance solutions for credit unions and banks, affected hundreds of thousands of people, including in Maryland.

“Marquis experienced a cybersecurity incident in which an unauthorized party gained access to portions of their data environment impacting hundreds of financial institutions,” reads a post from Bel Air’s Freedom Federal Credit Union, which was affected.

The credit union noted that its own internal systems, servers and data were not compromised in the Marquis breach that compromised basic contact information and, in some cases, Social Security numbers or dates of birth, according to Freedom Federal.

RELATED: Commercial lending by credit unions: What MD businesses should know

Maintaining strong cybersecurity measures has grown more challenging in recent years as more members use mobile banking, digital payments and online account services.

According to a 2024 survey conducted by the American Bankers Association, more than 55% of bank users, including credit union members, use mobile apps or phones as their primary method of managing their financials.

Although online and mobile tools can improve convenience, they also expand the number of potential entry points for cyberattacks. Each new feature must be secured, monitored and maintained, which increases the complexity of cybersecurity operations.

According to the National Credit Union Administration, risks such as phishing, ransomware and email hacks affect institutions of all sizes. These attacks often target human behavior rather than technical systems, making them especially dangerous for smaller organizations. Training staff and educating members becomes just as critical as maintaining secure networks.

RELATED: Credit unions partner with fintech to compete with big banks

To address these risks, Maryland’s maintains a security center that gives members practical guidance on phishing, identity theft, suspicious texts and fraudulent phone calls. It tells members that it will never contact them by phone, email or text to ask for personal information, and directs victims of fraud or identity theft to report problems immediately.

MECU also places scam reminders prominently on its homepage, showing that cybersecurity is not treated as a hidden matter but as part of regular member communication.

This direct-to-consumer approach factors in that many of today’s most common attacks are not highly technical attacks on networks. Instead, they are social engineering attacks aimed at people.

A phishing email, spoofed text message or fake phone call can be enough to trick a member into revealing a password, one-time code or card information. MECU has also published fraud-prevention guidance in its blog, including checklists on how members can recognize and avoid current scams.

Similarly, First Financial Federal Credit Union emphasizes member awareness as a key cybersecurity strategy. Its website also includes a dedicated security center and fraud protection resource that warn members about scams, impersonation attempts, suspicious calls and card verification schemes.

The credit union also provides guidance on recognizing common scam tactics and offers fraud alerts tied to card activity, helping members detect and respond to unauthorized transactions quickly. One tip that First Financial also highlights to their members on its website is adding multiple levels of verification, such as adding a verbal password to an account for extra protection.

Securityplus Federal Credit Union takes a similar approach, combining member education with protective tools. Its security center highlights phishing and spoofing risks, warning that scammers could attempt to imitate the credit union’s phone number or request sensitive information such as passwords or one-time passcodes. In addition, Securityplus promotes digital banking features like credit monitoring alerts and identity theft prevention tools.

RELATED: APG Federal Credit Union to open first Baltimore location

In addition to the safety concern of the reliance on digital banking, another major concern is cost. Large financial institutions can invest heavily in advanced cybersecurity infrastructures and dedicated security teams. Smaller credit unions must prioritize their spending and focus on the most effective protections.

Resources from the Cybersecurity and Infrastructure Security Agency highlight practical steps that smaller organizations can take, such as implementing multifactor authentication, keeping systems updated, maintaining secure backups and developing incident response plans.

But these measures are not always enough, with many institutions using third-party vendors to manage their secure information. These third-party companies are also targets of cybersecurity attacks, like in the case of Marquis.

Choosing a smaller credit union can still be a safe and reliable option, but it is important to pay attention to how the institution approaches cybersecurity. Features such as account alerts, card controls, fraud monitoring and clear communication about scams are strong indicators that a credit union is taking security seriously.