TruStage Data Breach Lawsuits: Consumer Class Action Filed
Data Breach · Lawsuit Filed

TruStage Data Breach Class Action Lawsuit (2026 Cybersecurity Incident)

Published July 21, 2026
Updated July 27, 2026

TruStage, the insurer and financial-services provider behind the GAP, payment-protection, and insurance products sold through credit unions nationwide, took its network offline in mid-July 2026 after a cybersecurity incident. It now faces two proposed class actions — a credit-union suit and a new consumer suit alleging Social Security numbers were exposed — but both are early-stage complaints, and there is nothing to claim.

A financial-institution and data-security illustration representing the July 2026 TruStage cybersecurity incident and the resulting class action lawsuits
TruStage faces two proposed class actions over its July 2026 cybersecurity incident in the U.S. District Court for the Western District of Wisconsin — one from a credit union, one from a consumer. Whether any personal data was accessed has not been confirmed by TruStage.
Allegations Only · No Settlement Yet

This article describes a class action complaint. The plaintiff's statements are unproven allegations. TruStage has not been found liable, there is no certified class, and there is nothing to claim at this time. Whether any personal or member data was accessed in the incident has not been confirmed and remains under investigation. This page is informational and is not legal advice.

What Is This About?

TruStage Financial Group, Inc. — the Madison, Wisconsin insurer and financial-services company formerly known as CUNA Mutual Group — is facing a proposed class action over a cybersecurity incident it disclosed in July 2026. TruStage sells insurance, lending, and financial-services products to credit unions and their members across the country, from Guaranteed Asset Protection (GAP) on auto loans to payment-protection and consumer insurance.

Two proposed class actions are now pending, both in the U.S. District Court for the Western District of Wisconsin. The first, Bessemer System Federal Credit Union v. TruStage Financial Group, Inc., No. 3:26-cv-00644-amb, was filed July 17, 2026 by a federally chartered credit union that says it entrusted TruStage with confidential information, including data about its members. The second, Brown v. TruStage Financial Group, Inc., No. 3:26-cv-00672, was filed July 23, 2026 by a consumer — a customer of one of TruStage's credit-union clients — on behalf of everyone whose personal information was allegedly impacted in the breach. TruStage has not been found liable in either case, and the plaintiffs' claims are unproven allegations at this stage.

Status Two Complaints Filed — In Litigation W.D. Wis. · credit-union suit No. 3:26-cv-00644 (July 17) + consumer suit No. 3:26-cv-00672 (July 23) · no class certified
What Happened Network taken offline after a cyber incident GAP, Mechanical Repair & Payment Protection claims disrupted · whether personal data was accessed is still under investigation
Can I Claim? No — nothing to claim yet Complaint stage · no settlement, fund, or deadline · proposed classes now cover credit unions and individual consumers

What Happened at TruStage

In mid-July 2026, TruStage identified a cybersecurity incident affecting its technology environment and proactively took its network offline as a precaution. In a public statement on July 15, 2026, the company said it "recently identified a cybersecurity incident affecting its environment and immediately activated its incident response and recovery protocols," and that it "has engaged external cybersecurity experts to support containment, remediation and recovery efforts."

The shutdown disrupted services that credit unions and their members rely on. Credit unions reported problems with access to certain TruStage systems and support channels, Guaranteed Asset Protection (GAP) claims, Mechanical Repair Coverage claims, and Payment Protection products, and some members reported difficulty accessing account information while the network was down.

Importantly, key facts remain unknown. As of publication, TruStage has not said whether any personal or member data was accessed or taken, how its systems were compromised, when the incident began, or whether ransomware was involved. The lawsuit alleges, "on information and belief," that unauthorized third parties accessed TruStage's systems — but that is an allegation in the complaint, not a confirmed finding. Reporting on the incident has described it as a cybersecurity incident and network outage; a data breach affecting individuals' information has not been confirmed by TruStage.

Update: First Consumer Class Action Filed (July 23, 2026)

On July 23, 2026, a consumer filed the first individual class action over the incident: Brown v. TruStage Financial Group, Inc., No. 3:26-cv-00672 (W.D. Wis.). The named plaintiff is a California resident and a customer of one of TruStage's credit-union clients whose personal information was, according to the complaint, indirectly entrusted to TruStage through that relationship.

Where the Bessemer suit focuses on institutional harms to credit unions, the Brown complaint puts individuals at the center. It alleges — upon information and belief, based on the nature of TruStage's business — that an unauthorized actor accessed TruStage's network and exfiltrated private information including names, demographic information, Social Security numbers, and financial account information, and that the stolen data is available on the dark web. TruStage has not confirmed any of that: its public statements say only that it identified a cybersecurity incident and has not said whether personal data was accessed or taken. The complaint brings claims for negligence, negligence per se, breach of third-party beneficiary contract, and violation of the California Consumer Privacy Act (for a California subclass), and seeks damages, statutory penalties, restitution, and injunctive relief. All of these are unproven allegations that TruStage will have the opportunity to contest.

What the Lawsuits Allege

The Bessemer complaint alleges that TruStage — a company that itself sells cybersecurity and risk-management products to credit unions — failed to implement and maintain adequate, industry-standard safeguards to protect the confidential information entrusted to it. It points to TruStage's own privacy policy and its 2025 security materials for credit-union clients, which state that the company protects information through administrative, physical, and technical safeguards, and argues that those assurances were not accurate when made.

On that basis, the credit union brings a negligence claim, contending that TruStage owed a duty to safeguard the information, breached that duty, and thereby caused the incident and the resulting harm. The complaint seeks damages, recovery of payments the credit unions made for services it alleges were deficient, reimbursement of expenses incurred responding to the incident, indemnification or contribution where applicable, and attorneys' fees and costs. It invokes federal jurisdiction under the Class Action Fairness Act, alleging more than $5 million in aggregate controversy. Every one of these points is an unproven allegation; TruStage has not responded to the complaint or been found liable, and it has not admitted any wrongdoing.

Who Is in the Proposed Classes

The Bessemer complaint proposes a nationwide class defined as all credit unions in the United States (including credit union members) that provided confidential information to TruStage and were impacted by the incident — the harms it describes are largely institutional: the cost of investigating, remediating, and protecting members after a vendor outage.

The Brown complaint proposes a broader consumer class: all persons residing in the United States whose private information was impacted by the breach TruStage announced on July 15, 2026, plus a California subclass of California residents. That definition would reach individual consumers whose data flowed to TruStage through its bank and credit-union clients.

That said, this is still not a consumer settlement, and it is not a page where you file for a payout. No class has been certified in either case, so no court has yet defined who is or isn't a class member. If you are a credit union member who uses a TruStage product, the most useful thing to know is simply what the incident affected and how to protect yourself — covered below.

Is There a Settlement or a Claim to File?

No. This is litigation, not a settlement.

There is no class settlement, no fund, no claim form, and no deadline. Both cases are at the earliest pleading stage. Because nothing about a claims process exists yet, treat any website offering a "TruStage breach claim form" or "settlement payout" as illegitimate. If either case ever reaches a certified class or a settlement, an official claims process, deadlines, and a court-appointed administrator would be announced, and this page would be updated.

What Credit Unions and Members Can Do

While there is no court claim to file, there are sensible precautions to take after any incident like this:

• Be skeptical of anyone contacting you claiming to be from TruStage or your credit union and asking for account credentials, one-time passcodes, card numbers, or a payment — incidents like this are commonly followed by impersonation scams.
• Monitor your account statements and transactions, and report anything unfamiliar to your credit union through its official channels.
• Consider placing a free fraud alert or a credit freeze with the three major credit bureaus if you are concerned about your information.
• Keep any breach or incident notice you receive; it may matter later if a claims process is ever established.
• Watch your credit union's official website and communications for verified updates, rather than relying on unofficial sources.

For data-breach settlements that are actually open and claimable right now, see OCA's data breach settlements tracker.

Frequently Asked Questions

Is there a TruStage settlement or claim to file?

No. These are newly filed class action complaints, not settlements. There is no certified class, no fund, no claim form, and no deadline in either case. If a class is later certified or a settlement is reached, a claims process would be announced separately.

Was my personal information stolen in the TruStage incident?

That is not confirmed by TruStage. The company said it identified a cybersecurity incident and took its network offline as a precaution, and it engaged outside experts; it has not stated whether personal or member data was accessed. The consumer complaint alleges "on information and belief" that names, Social Security numbers, and financial account information were exfiltrated and are available on the dark web — unproven allegations while the investigation is ongoing.

Who do the lawsuits cover?

The credit-union suit proposes a nationwide class of credit unions (including credit union members) that provided confidential information to TruStage. The consumer suit proposes a nationwide class of all U.S. residents whose private information was impacted by the breach, plus a California subclass. No class has been certified in either case, so membership is not yet defined by any court.

What did the incident disrupt?

Credit unions reported disruptions to access to certain TruStage systems and support, Guaranteed Asset Protection (GAP) claims, Mechanical Repair Coverage claims, and Payment Protection products, with some members unable to access account information while the network was offline.

Sources

• TruStage — official statement on the cybersecurity incident: TruStage Cybersecurity Incident Update
• Credit Union Times — "TruStage Investigating Cybersecurity Incident After Proactively Shutting Down Network" (July 14, 2026): CU Times Report
• Coverager — "TruStage shuts down network following cybersecurity incident": Coverager Report
• U.S. District Court, Western District of Wisconsin — Bessemer System Federal Credit Union v. TruStage Financial Group, Inc., No. 3:26-cv-00644-amb (complaint filed July 17, 2026).
• U.S. District Court, Western District of Wisconsin — Brown v. TruStage Financial Group, Inc., No. 3:26-cv-00672 (class action complaint filed July 23, 2026).


For more class actions keep scrolling below.
Status Two Complaints Filed — In Litigation (no settlement)
Credit Union Case Bessemer System FCU v. TruStage Financial Group, No. 3:26-cv-00644-amb (filed July 17, 2026)
Consumer Case Brown v. TruStage Financial Group, No. 3:26-cv-00672 (filed July 23, 2026)
Court U.S. District Court, W.D. Wisconsin

Related Data Breach Cases & Settlements