In the early hours of July 15, 2026, TruStage Financial Group’s network went dark, leaving more than 90 % of the credit unions that rely on its platform scrambling to access life‑insurance, auto‑insurance, and 401(k) services. Two days later, on July 17, Bessemer System Federal Credit Union—an institution headquartered in Greenville, Pennsylvania—filed a proposed class‑action lawsuit against the vendor, demanding compensation for the disruption.

The suit, filed in federal court, hinges on the claim that TruStage’s security performance fell short of the assurances it offered to its credit‑union customers. According to the complaint, the company’s own “2025 security practices” document promises regular data backups and annual recovery‑process tests. The plaintiffs allege that at least one of those promises was false when it was made.

Bessemer’s attorneys, led by Charles Nerko, argue that the outage caused tangible financial harm. Credit‑union members were unable to view or manage retirement balances, and the institution’s day‑to‑day operations stalled. The lawsuit seeks damages for lost services, reimbursement of costs incurred during the outage, and repayment of fees paid for services that were not delivered. Importantly, the claim is framed as a negligence action rather than a breach‑of‑contract claim.

TruStage’s public response has been measured. In a July 15 press release, the company said it had identified a cybersecurity incident, activated its incident‑response protocols, and hired external experts to help contain and recover from the breach. No threat actor, ransom demand, or specific intrusion method has been disclosed.

The timing of the lawsuit is notable. No evidence of data theft has yet been confirmed, and the complaint relies solely on the fact that credit‑union members were locked out of their accounts and that the outage inflicted operational losses. The absence of stolen data or a named attacker means the case will largely rest on the alleged negligence of TruStage’s security measures.

Legal analysts point out that proving negligence against a vendor is challenging, especially when contractual agreements govern the relationship. However, institutional plaintiffs such as credit unions may have a stronger footing than individual consumers because they can point to concrete financial losses—lost transaction revenue, remediation costs, and fees paid for unrendered services.

Bessemer is no stranger to litigation against technology vendors. In 2019, the credit union sued Fiserv over security lapses and billing errors; that dispute settled in 2024 on confidential terms, after which Bessemer paid a one‑time dividend to its members.

The outage’s ripple effects are wide. Credit unions have reported disruptions in insurance claims processing, auto‑loan gap coverage, mechanical‑repair coverage, and payment‑protection products sold through TruStage. The lawsuit is still in its infancy; Bessemer’s counsel says the firm is continuing its investigation and expects to file an amended complaint as more information surfaces. Other credit unions have also reported similar disruptions.

The case could set a precedent for how credit unions hold their technology vendors financially accountable when security performance falls short of contractual promises. If a court allows the negligence claim to proceed, it may compel vendors to tighten their security postures and provide more robust contractual safeguards.

At present, TruStage remains focused on restoring its systems. No timeline for full service restoration has been announced, and no data breach has been confirmed. The lawsuit will likely proceed in federal court, with both parties open to settlement before a trial.

Ultimately, this litigation underscores the growing scrutiny of third‑party vendors that supply critical services to financial institutions. Credit unions, which serve millions of members, depend on vendors like TruStage to deliver insurance, retirement, and other financial products. The outcome of Bessemer’s lawsuit could influence how credit unions evaluate vendor security and contractual protections in the future.