A Q2 2026 Cyber Resilience Review: Navigating the New Era of AI-Driven Fraud and Identity Exploitation

Over the second quarter of 2026, the credit union ecosystem faced increasingly sophisticated and multi-layered threats. Data compiled by the NCU-ISAO across April, May, and June reveals a profound shift in how threat actors compromise systems. 

This overview breaks down the key trends from the past 90 days and outlines critical, actionable takeaways for credit union leadership to protect their institutions, infrastructure, and members:

1. Identity at Risk: How Attackers Are Exploiting Device Code Flows

Identity theft remains the number one method attackers use against financial institutions. But over the last quarter, their methods have evolved:

  • Using Trusted Systems for Attacks: In April and May, there was a sharp rise in phishing scams targeting Microsoft logins. Attackers misused a security feature called the OAuth device code flow, allowing them to break in using legitimate company systems. This made it harder for usual security tools to spot these attacks in real time.
 
  • Attack Preferences Are Shifting: By June, regular phishing attacks started to drop off. Instead, criminals increasingly turned to device code flow methods as their preferred way of getting long-term access to corporate computers and networks. Device code flow is a way for users to sign in on devices with limited keyboards (like smart TVs) by entering a code on their phone or computer instead.
 

2. Artificial Intelligence: Firmly Embedded in Cybercriminal Attacks

Over the past three months, artificial intelligence has become operationally mature within the cybercriminal world:

  • Faster Attacks: As early as April, reports confirmed that criminals used AI to speed up the time between when a software flaw is discovered and when it is actually exploited.
 
  • Automated Scams: By May, criminal groups were selling AI-based fraud services such as ATHR (a cybercrime software tool that automates AI voice phishing and telephone scams). This platform can run complex crimes with little to no human involvement.
 
  • Deepfakes and API Key Theft: In June, it was found that scammers are using sophisticated tools — like fake AI voices, internet phone services, and everyday web browser features — to trick credit union members into handing over their one-time login passcodes. Because of this, teaching members how to spot these advanced scams is imperative.
 

3. Ongoing Risk from Supply Chain Attacks

Credit unions often depend on outside software, making them a big target if that supply chain is compromised. The open-source software world saw many cybersecurity attacks during this quarter, including:

  • The Shai-Hulud Malware Incident: In June, hackers used a type of malware called Shai-Hulud to break into two major software app stores that developers use (npm and PyPI). They stole login passwords and security keys, which could then allow them to sneak malicious code into real applications.
 
  • RubyGems: Attackers uploaded a large number of fake or harmful software packages to a platform called RubyGems. These fake programs were designed to steal usernames and passwords.
 

4. More Focus from Regulators

Regulators are tightening their oversight to keep up with these new risks. AI-powered fraud is pushing financial institutions to update their fraud prevention and vendor management systems at a rapid pace.

5. Physical Security: Crowd-Driven Risks and ATM Trends

While digital infrastructure demands constant monitoring, physical security trends require equal diligence. Over the past 90 days, ATM crime trends shifted heavily toward physical theft and high-impact, structural attacks.

While digital “jackpotting” and traditional skimming have become more scarce and regionally concentrated, physical vandalism remains a threat.

Action Plan for Credit Union Leaders

To stay protected, credit union leaders should take these important steps:

  1. Control Device Code Flows: Use conditional access policies in Microsoft Azure/Entra ID to completely block device code flow logins, unless it’s absolutely needed for a specific, limited job function.
 
  1. Require More Than One Admin for Sensitive Changes: After several prominent breaches (like the Stryker incident traced to the Iranian group in Handala), it’s crucial to require multiple administrators to approve major changes or device resets in management tools. This prevents one person from doing too much damage by mistake or under duress.
 
  1. Connect Cybersecurity and Fraud Teams: Cyber and fraud teams must work together, not separately. Clearly define incident response procedures so everyone — including operations and front-line staff — knows who owns each type of incident and how it should be escalated.

Key Cybersecurity Questions for For Credit Union Executives to Consider:

  • Are ownership and escalation paths clearly defined?
  • How will our credit union handle the increased need to patch software quickly, now that criminals are using AI to find and exploit system vulnerabilities almost in real time?
  • How can we educate members on current cybersecurity threats?
 

About CBS

Cooperative Business Services (CBS) is a Credit Union Service Organization (CUSO) that provides credit unions with a full-suite of commercial lending support. We help 150+ credit unions nationwide lend with confidence from origination through servicing (and beyond through detailed loan reporting). 

Recent Posts
A Q2 2026 Cyber Resilience Review: Navigating the New Era of AI-Driven Fraud and Identity Exploitation
Employee Spotlight - Leslie
Employee Spotlight: Leslie A. Biskner, CCIM
Credit
Why Credit Unions Are Prime Targets for Cybercriminals

Commercial Lending Solutions

You Can Count On