Engagements

Investigated 90,000-attempt cyberattack on credit union platform

Data infecting a finger print identity on a screen to illustrate hacking and cyber crime

The challenge

In February 2025, multiple Canadian credit unions reported unexpected user lockouts from their payment processing application. The application was operated by a joint venture providing automated funds transfer services. An initial investigation revealed suspicious login attempts tied to a compromised multi-factor authentication (MFA) credential, creating the risk of regulatory scrutiny and potential damage to relationships with member credit unions.

CRA’s approach

Retained under privilege by legal counsel, CRA’s Forensic Services team conducted a digital forensic investigation to validate the client’s preliminary findings and determine whether the threat actor had accessed or exfiltrated sensitive information.

Our team preserved and analyzed forensic evidence from servers, web application firewall logs, SQL database logs, MFA authentication logs, and application transaction data spanning five months. To establish a defensible timeline for legal and regulatory purposes, we analyzed available log data and determined that the threat actor exploited a gap between MFA verification and application password synchronization to conduct a password spray attack.

The attack included more than 90,000 authentication attempts, resulting in the compromise of 86 user accounts and creating potential data exposure across 10,672 entities at 30 credit unions. We also evaluated the client’s containment measures and validated remediation controls, including:

  • MFA binding between the application and authentication gateway
  • Web application firewall filtering to block typosquatted domains
  • Improved session management controls
  • Automated alerting for high-volume authentication attempts

The impact

Our investigation delivered a critical finding: despite the scale and sophistication of the coordinated attack, the threat actor did not gain access to underlying infrastructure, execute fraudulent transactions, or exfiltrate data.

This definitive evidence provided the client and its legal counsel with the validated findings needed to address regulatory inquiries, manage stakeholder communications, and assure both the Board and member credit unions that the incident had been successfully contained.