TruStage Data Breach Lawsuit: First Class Action Filed
Data Breach · Lawsuit Filed

TruStage Data Breach Class Action Lawsuit (2026 Cybersecurity Incident)

Published July 21, 2026

TruStage, the insurer and financial-services provider behind the GAP, payment-protection, and insurance products sold through credit unions nationwide, took its network offline in mid-July 2026 after a cybersecurity incident. A credit union has now filed the first class action — but it is an early-stage complaint, and there is nothing to claim.

A financial-institution and data-security illustration representing the July 2026 TruStage cybersecurity incident and the resulting class action lawsuit
Bessemer System Federal Credit Union filed the first class action over TruStage's July 2026 cybersecurity incident in the U.S. District Court for the Western District of Wisconsin. Whether any personal data was accessed remains under investigation.
Allegations Only · No Settlement Yet

This article describes a class action complaint. The plaintiff's statements are unproven allegations. TruStage has not been found liable, there is no certified class, and there is nothing to claim at this time. Whether any personal or member data was accessed in the incident has not been confirmed and remains under investigation. This page is informational and is not legal advice.

What Is This About?

TruStage Financial Group, Inc. — the Madison, Wisconsin insurer and financial-services company formerly known as CUNA Mutual Group — is facing a proposed class action over a cybersecurity incident it disclosed in July 2026. TruStage sells insurance, lending, and financial-services products to credit unions and their members across the country, from Guaranteed Asset Protection (GAP) on auto loans to payment-protection and consumer insurance.

The case is Bessemer System Federal Credit Union v. TruStage Financial Group, Inc., No. 3:26-cv-00644-amb, filed July 17, 2026 in the U.S. District Court for the Western District of Wisconsin. The named plaintiff is a federally chartered credit union that says it entrusted TruStage with confidential information, including data about its members. The complaint brings a single claim — negligence — and asks the court to certify a nationwide class. TruStage has not been found liable, and the plaintiff's claims are unproven allegations at this stage.

Status Complaint Filed — In Litigation W.D. Wis. · No. 3:26-cv-00644-amb · filed July 17, 2026 · single negligence count · no class certified
What Happened Network taken offline after a cyber incident GAP, Mechanical Repair & Payment Protection claims disrupted · whether personal data was accessed is still under investigation
Can I Claim? No — nothing to claim yet Complaint stage · no settlement, fund, or deadline · proposed class is credit unions & their members

What Happened at TruStage

In mid-July 2026, TruStage identified a cybersecurity incident affecting its technology environment and proactively took its network offline as a precaution. In a public statement on July 15, 2026, the company said it "recently identified a cybersecurity incident affecting its environment and immediately activated its incident response and recovery protocols," and that it "has engaged external cybersecurity experts to support containment, remediation and recovery efforts."

The shutdown disrupted services that credit unions and their members rely on. Credit unions reported problems with access to certain TruStage systems and support channels, Guaranteed Asset Protection (GAP) claims, Mechanical Repair Coverage claims, and Payment Protection products, and some members reported difficulty accessing account information while the network was down.

Importantly, key facts remain unknown. As of publication, TruStage has not said whether any personal or member data was accessed or taken, how its systems were compromised, when the incident began, or whether ransomware was involved. The lawsuit alleges, "on information and belief," that unauthorized third parties accessed TruStage's systems — but that is an allegation in the complaint, not a confirmed finding. Reporting on the incident has described it as a cybersecurity incident and network outage; a data breach affecting individuals' information has not been confirmed by TruStage.

What the Lawsuit Alleges

The complaint alleges that TruStage — a company that itself sells cybersecurity and risk-management products to credit unions — failed to implement and maintain adequate, industry-standard safeguards to protect the confidential information entrusted to it. It points to TruStage's own privacy policy and its 2025 security materials for credit-union clients, which state that the company protects information through administrative, physical, and technical safeguards, and argues that those assurances were not accurate when made.

On that basis, the plaintiff brings a negligence claim, contending that TruStage owed a duty to safeguard the information, breached that duty, and thereby caused the incident and the resulting harm. The complaint seeks damages, recovery of payments the credit unions made for services it alleges were deficient, reimbursement of expenses incurred responding to the incident, indemnification or contribution where applicable, and attorneys' fees and costs. It invokes federal jurisdiction under the Class Action Fairness Act, alleging more than $5 million in aggregate controversy. Every one of these points is an unproven allegation; TruStage has not responded to the complaint or been found liable, and it has not admitted any wrongdoing.

Who Is in the Proposed Class

The complaint proposes a nationwide class defined as all credit unions in the United States (including credit union members) that provided confidential information to TruStage and were impacted by the incident. In practice, the driving plaintiff here is an institution — a credit union — and the harms it describes are largely institutional: the cost of investigating, remediating, and protecting members after a vendor outage.

That is worth being clear about for individual readers: this is not a consumer settlement, and it is not a page where you file for a payout. No class has been certified, so no court has yet defined who is or isn't a class member. If you are a credit union member who uses a TruStage product, the most useful thing to know is simply what the incident affected and how to protect yourself — covered below.

Is There a Settlement or a Claim to File?

No. This is litigation, not a settlement.

There is no class settlement, no fund, no claim form, and no deadline. The case was filed on July 17, 2026 and is at the earliest pleading stage. Because nothing about a claims process exists yet, treat any website offering a "TruStage breach claim form" or "settlement payout" as illegitimate. If the case ever reaches a certified class or a settlement, an official claims process, deadlines, and a court-appointed administrator would be announced, and this page would be updated.

What Credit Unions and Members Can Do

While there is no court claim to file, there are sensible precautions to take after any incident like this:

• Be skeptical of anyone contacting you claiming to be from TruStage or your credit union and asking for account credentials, one-time passcodes, card numbers, or a payment — incidents like this are commonly followed by impersonation scams.
• Monitor your account statements and transactions, and report anything unfamiliar to your credit union through its official channels.
• Consider placing a free fraud alert or a credit freeze with the three major credit bureaus if you are concerned about your information.
• Keep any breach or incident notice you receive; it may matter later if a claims process is ever established.
• Watch your credit union's official website and communications for verified updates, rather than relying on unofficial sources.

For data-breach settlements that are actually open and claimable right now, see OCA's data breach settlements tracker.

Frequently Asked Questions

Is there a TruStage settlement or claim to file?

No. This is a newly filed class action complaint, not a settlement. There is no certified class, no fund, no claim form, and no deadline. If a class is later certified or a settlement is reached, a claims process would be announced separately.

Was my personal information stolen in the TruStage incident?

That is not confirmed. TruStage said it identified a cybersecurity incident and took its network offline as a precaution, and it engaged outside experts. It has not stated whether personal or member data was accessed, how the systems were compromised, or whether ransomware was involved. The lawsuit alleges unauthorized access "on information and belief," which is an unproven allegation.

Who does the lawsuit cover?

The complaint proposes a nationwide class of credit unions (including credit union members) that provided confidential information to TruStage and were impacted. The named plaintiff is a credit union, and the alleged harms are largely institutional. No class has been certified, so membership is not yet defined by any court.

What did the incident disrupt?

Credit unions reported disruptions to access to certain TruStage systems and support, Guaranteed Asset Protection (GAP) claims, Mechanical Repair Coverage claims, and Payment Protection products, with some members unable to access account information while the network was offline.

Sources

• TruStage — official statement on the cybersecurity incident: TruStage Cybersecurity Incident Update
• Credit Union Times — "TruStage Investigating Cybersecurity Incident After Proactively Shutting Down Network" (July 14, 2026): CU Times Report
• Coverager — "TruStage shuts down network following cybersecurity incident": Coverager Report
• U.S. District Court, Western District of Wisconsin — Bessemer System Federal Credit Union v. TruStage Financial Group, Inc., No. 3:26-cv-00644-amb (complaint filed July 17, 2026).


For more class actions keep scrolling below.
Status Complaint Filed — In Litigation (no settlement)
Case Bessemer System Federal Credit Union v. TruStage Financial Group, Inc.
Case Number No. 3:26-cv-00644-amb
Court U.S. District Court, W.D. Wisconsin
Date Filed July 17, 2026

Related Data Breach Cases & Settlements