America’s Credit Unions launched its Cybersecurity, Fraud, and Vendor Risk Resources hub this week, timed to Cybersecurity Awareness Month. The trade group, which says credit unions serve 146 million Americans, describes the hub as an ongoing resource, not a one-month campaign. Meghan Small, the group’s chief communications and marketing officer, said its focus is “supporting our membership with timely information and guidance.”
That sounds like a compliance story. Most of what’s in the hub is actually marketing work: member emails, social posts, lobby posters, fraud alerts, and the scripts your frontline staff use when a member calls asking whether a text is real. If your team doesn’t pick it up, nobody else at the credit union will.
The Hub Is Live and Free to Browse. Some of the Promises Are Still Just Promises.
The hub page is public and sorts resources into three areas: protecting members, preparing teams, and shaping policy. What you can verify on the page today: two free toolkits from the American Association of Credit Union Leagues (AACUL), one for Cybersecurity Awareness Month and one for elder financial exploitation; compliance blog posts on data breach response, SAR confidentiality, the 314(b) information-sharing safe harbor, and vendor due diligence; four on-demand webinars; and policy handouts on check fraud and reporting thresholds.
Two pieces are announcements, not things you can check yet. ACU told the trade press it will promote the resources through targeted emails and social posts through the end of the year. It also says member credit unions can reach its compliance team on federal compliance questions, usually within one business day. That second claim matters for the steps below. If it holds up, it’s a faster second opinion than many smaller credit unions get from outside counsel. Test it with a real question before you build a deadline around it.
The Hub Is a Library. The Campaign Inside It Is Already Half Over.
The asset that does the most work for a marketing team isn’t new. AACUL’s Cybersecurity Awareness Toolkit came out in August, and the hub links to it. It’s a complete October campaign under one identity, “Think Before You Click.” It includes four member emails, four newsletter articles, ten social graphic sets with post copy already written, four 22-by-28-inch lobby posters, website buttons, three community one-sheets, and a press release template for local media. Every asset is editable, and each printable one-sheet comes in a version with a blank footer for your logo.
The calendar runs one theme per week: IDENTIFY (October 1–5), PROTECT (October 6–12), PREVENT (October 13–19), and SHOP SMART (October 20–31). Today is October 9, so a credit union starting from zero has already missed the first theme and most of the second. That isn’t a reason to skip the campaign. PREVENT covers identity theft warning signs, public Wi-Fi, and device updates. SHOP SMART covers QR code scams and AI-written phishing just as holiday spending picks up. Those are the two weeks most worth running anyway, and a one-person marketing department can still get them through approvals by Monday if it starts today.
If you market a bank, the toolkit is branded for credit unions and distributed through the leagues. The structure still transfers: one campaign identity, a weekly theme, and each theme matched to a specific email, post, and branch piece. That’s what turns a folder of fraud tips into a schedule your team can actually ship.
The Numbers in the Toolkit Are a Year Old. Use the New Ones.
The toolkit’s statistics come from the FBI’s 2024 Internet Crime Report: 859,532 complaints and more than $16 billion in reported losses. The 2025 report, released in April, is worse. The FBI’s Internet Crime Complaint Center received 1,008,597 complaints, and reported losses reached $20.9 billion, up 26% from 2024.
Change the numbers before anything goes out. A member who sees a 2024 figure in an October 2026 email will assume the rest of the content is just as stale, and so will a compliance reviewer who checks the citation.
The age data is the figure to build around. People 60 and older filed 201,266 complaints in 2025 and reported $7.7 billion in losses, more than any other age group. For most credit unions, that’s the same member segment holding the largest share of share certificates and money market balances. A scam that empties one of those accounts is a member loss, a reputational hit in a small market, and deposits leaving the balance sheet at once, often with no warning to anyone on your team. We made the deposit side of this case in The Great Wealth Transfer. Fraud education aimed at older members protects the same balances your retention campaigns are trying to keep.
The 2025 report also added artificial intelligence as a tracked category for the first time: 22,364 complaints and nearly $893 million in losses. The hub’s post on deepfakes and voice-clone scams is the right source material for your SHOP SMART week, when the toolkit’s own AI messaging lands.
The Fraud Alert Template Is Worth More Than the October Campaign
The toolkit includes a “Fraud Alert in a Box”: a fraud alert notice formatted for email, blog, and web, an alert email header, social buttons in three sizes, staff talking points, and a four-step member checklist for suspected identity theft (contact the credit union, change passwords and turn on multifactor authentication, place a fraud alert or credit freeze with the three bureaus, report to the FTC).
This is the piece to get approved in October and keep on the shelf all year. When a scam starts hitting your members, usually a spoofed text using your name or a fake fraud-department call, the delay in warning them rarely comes from a lack of urgency. It comes from writing, designing, reviewing, and approving a message from scratch while the scam keeps working. A pre-approved template with blanks for the scam details cuts that from days to hours. Every hour matters, because the members who get the warning after they’ve already responded are the ones who lose money.
Run the template past compliance now, not during an incident. Ask them three specific questions. Does the alert language avoid implying that the credit union will cover losses, which creates UDAAP exposure if it doesn’t hold? Does anything in the alert workflow risk revealing that a SAR was filed? The hub’s post on SAR confidentiality and member communications covers exactly this. And if you plan to send alerts by text, does your consent record cover it under TCPA?
Your Frontline Scripts Are Marketing Content, Too
The toolkit’s staff talking points branch by situation: a member who isn’t sure something is a scam, one who received it but didn’t act, one who clicked the link, and one who already handed over personal information. Tellers and contact center agents get those questions first, and what they say is the member experience in that moment.
Marketing usually writes the campaign and leaves the branch scripts to operations. That split produces a member who gets a calm, branded email about phishing and then a confused answer at the teller line. Hand the four scenarios to whoever owns frontline training and ask them to adapt the language to your actual escalation process: who gets the call, which account holds go on, which number the member calls back. ACU’s Councils is running a roundtable on October 16 called Fraud in the Real World: Protecting Members Without Breaking the Experience. That’s the tension your scripts have to resolve, and it’s worth sending someone.
Your Martech Stack Is a Vendor Risk Problem
The “vendor risk” in the hub’s name is easy for marketers to skip. Don’t. Your email service provider, your CRM, your digital ad agency, and the vendor running your account-opening forms all touch member data. A breach at any of them reads to members as a breach at the credit union, and the incident response comes back to your team as a communications problem.
The hub’s Vendor Management Basics webinar is taught by Kati Tarquini of California Credit Union and runs 45 minutes. It covers risk assessment, due diligence, contract terms, and ongoing monitoring. Pair it with the hub’s vendor due diligence post, then pull your marketing vendor list and ask your vendor management owner one question: which of these vendors hold member data, and which have breach notification terms in their contracts? If marketing has signed agreements that never went through the credit union’s vendor review, this is the month to fix that.
What to Do Before October 13
- Download the toolkit today (marketing lead). Pull the PREVENT and SHOP SMART assets from AACUL or your league, add your logo to the blank-footer versions, and replace every 2024 FBI figure with the 2025 numbers above.
- Submit the October 13–31 assets to compliance by Monday (marketing lead). Bundle the emails, social posts, and newsletter articles into one review package. If a federal compliance question stalls it, test ACU’s one-business-day compliance line.
- Get the Fraud Alert in a Box pre-approved (marketing and compliance). Use the three questions above. Store the approved version where whoever is on call for incidents can reach it without you.
- Hand the staff talking points to frontline training (marketing to operations). Ask for an adapted version tied to your actual escalation path before the SHOP SMART week starts October 20.
- Pitch local media (marketing or communications). The toolkit’s press release template names four topics your credit union can offer for expert comment. October is when local outlets are looking for that story.
- Run the martech vendor check (marketing and vendor management, by October 31). Confirm which marketing vendors hold member data and whether they’ve gone through formal review.
- Register for the Fraud & Security Virtual Conference (fraud and marketing leads). It runs December 1–3, and early-bird pricing ends October 30.
Measure It Like a Campaign, Because It Is One
Fraud education rarely gets measured, which is why it rarely gets budget. Track it the way you’d track any other campaign. Watch email open and click rates on the four fraud emails against your normal member newsletters. Ask the contact center to tag “is this a scam?” calls for October and November so you have a baseline. Log the time it takes to publish your first real fraud alert using the pre-approved template, and compare it with how long your last one took.
None of those numbers will show up directly in a funded-accounts report. They will give your board deck something concrete when someone asks what the credit union did about fraud this year, and they help close the gap we described in The Measurement Gap between what marketing does and what it can prove.


