The Risk Is Real, Documented, and Now a Fiduciary Issue
Taft-Hartley benefit funds operate in one of the most targeted data environments in existence. Here is what the evidence actually shows.
We Don't Use Fear to Start Conversations. We Use Evidence.
The statistics on this page come from the U.S. Department of Labor, the Department of Health and Human Services, Verizon's annual breach investigation report, IBM's cost-of-breach research, the FBI, and leading cyber insurance carriers. None of it is speculation. All of it is directly relevant to how Taft-Hartley benefit funds operate.
Cybersecurity Is Now an ERISA Governance Issue
For years, cybersecurity was treated as an IT concern: something the administrator or outside vendor handled, separate from trustee governance. That framing is no longer accurate, and regulators have made it explicit.
ERISA imposes fiduciary duties on plan trustees and administrators that extend to how participant data is protected, how vendors are overseen, and how the fund would respond to an incident. The Department of Labor has clarified that its cybersecurity guidance applies to all ERISA plans, including Taft-Hartley health and welfare funds. This means the expectations around controls, vendor oversight, participant data protection, and incident response now apply directly to the organizations responsible for processing eligibility, claims, and benefit distributions.
In January 2026, EBSA identified cybersecurity alongside protecting benefit distributions as an active enforcement priority. Weak administrative controls and inadequate vendor oversight are now on the same examination list as more traditional fiduciary concerns. Under ERISA, trustees who failed to maintain adequate cybersecurity controls can face personal liability following a breach, just as they would for any other failure of fiduciary duty.
This is not a future concern. It is the current regulatory environment.
The numbers every ERISA-governed fund trustee should know
Business Email Compromise: The Most Underestimated Risk
Business email compromise is not a ransomware attack. It doesn't encrypt files or shut down systems. It redirects money. The FBI's 2025 Internet Crime Complaint Center report recorded 24,768 BEC complaints resulting in $3.05 billion in losses. Coalition's 2025 cyber claims data found that BEC and funds transfer fraud made up 60% of all claims, with BEC severity increasing 23% year over year. 29% of BEC events led directly to funds transfer fraud. For Taft-Hartley benefit funds that process contributions, vendor payments, disbursements, and benefit payments, often under time pressure with lean staff, this is not a hypothetical risk.
Ransomware: Operational Disruption, Not Just Encrypted Files
The real damage from a ransomware attack on a benefit office isn't the ransom demand. It's the loss of operational continuity: the inability to process eligibility, run claims administration, reconcile contributions, communicate with participants, or make benefit payments while the attack is being contained and systems are being restored. Verizon's 2025 Data Breach Investigations Report found that for small and midsize organizations in healthcare-adjacent environments, 88% of breaches involved ransomware. The number of large healthcare breaches caused by ransomware increased 102% over the five-year period from 2018 to 2023.
Third-Party Risk: Your Vendors Are Part of Your Exposure
Taft-Hartley funds typically depend on a network of outside parties: TPAs, consultants, custodians, claims administrators, technology vendors, and portal providers. Each of those relationships extends your operational and security perimeter. Verizon found that third-party involvement in healthcare breaches doubled in a single year, from 15% to 30%. When a vendor holds participant data, processes claims, or supports disbursement workflows, their security posture is your security posture. This is also a fiduciary issue. Trustees are responsible for overseeing service providers.
Stolen Credentials: The Entry Point for Most Attacks
Many of the most damaging attacks on organizations like yours don't start with sophisticated exploits. They start with a username and password. Verizon found that 88% of Basic Web Application Attacks involved stolen credentials. Among ransomware victims identified by threat actors, 54% had domains present in credential dumps and 40% had corporate email addresses in compromised credential sources. This is why identity controls such as multi-factor authentication, privileged access management, and credential monitoring are foundational requirements, not optional upgrades.
The Cost When It Happens
IBM's 2025 Cost of a Data Breach report found that the average healthcare data breach cost $7.42 million. The average U.S. data breach across all industries cost $10.22 million. Those figures include breach response, notification obligations, regulatory inquiries, legal costs, operational disruption, and reputational damage. They do not include the downstream consequences for trustees who were found to have inadequate controls in place before the event.
The Funds We Work With Have Already Worked Through This
The organizations that work with Revolt Fund Guard have moved from uncertainty to confidence, not because the risk disappeared, but because they built the controls, oversight, and resilience to address it on their terms. If you want to understand where your fund office actually stands, a fund office baseline review is where that conversation starts.
Baseline Review
No pitch deck. No follow-up sequence.