- TruStage Newsroom
- Recovery and restoration update
TruStage recovery and restoration progress update
TruStage continues to make progress in its recovery and restoration efforts following the cybersecurity attack identified on July 11. Because this was a particularly broad attack on our network and systems, we have rebuilt parts of our infrastructure so systems can be brought back safely, rather than simply turned back on.
The incident has been contained, and as we rebuild, we are ensuring there is no malicious code or bad actor in our systems or network. With key infrastructure rebuilt, we are now bringing systems and applications back online through a deliberate process designed to protect employees, partners, members, customers, and the organization.
Progress on safe system restoration
Our goal is for us, and for the organizations we serve, to have confidence that systems are protected, safe, and stable as they come back online.
To help ensure our environment remains safe, we have refreshed laptops and updated security measures for our teams. That work is close to completion and is a necessary step as teams begin to re-engage with systems.
Operational momentum across the business
Restoration momentum continues to be promising. Based on what we know right now, we anticipate that the majority of our key processes will be operational by mid-August, with priority placed on the operations most critical to partners and their members.
Some systems may come online before they are fully operational or fully back to normal. We recognize this process feels slower than anyone would like, and our teams continue to create processes, workarounds, and alternate paths to reach functional, operational levels while restoration continues.
Ongoing data investigation
The data investigation remains ongoing. Forensic investigations of this nature take time, as investigators work to determine whether anything was accessed, confirm what was not accessed, and, if information was accessed, identify what kind of information it was and where it came from.
Our expert cybersecurity partner, Mandiant, and our internal teams are working diligently on that investigation. We know partners want answers for their members. While we do not yet know whether member data was accessed, if we determine that members’ personal information is involved, we will let affected partners know first and will work with them to support any notification or reporting process.
What partners can expect next
Our teams remain focused on restoring operations and serving partners, members, and customers safely and securely. We are committed to sharing email updates multiple times a week and will continue to communicate what we can, when we can, while protecting the integrity of the investigation and the security of our environment.
We know partners and their teams are fielding questions and having difficult conversations every day, and we appreciate their partnership, patience, and continued support as we move forward.