On January 15, 2026, the Employee Benefits Security Administration (EBSA) quietly but decisively restructured its national enforcement program. While the change didn’t dominate headlines, its implications are immediate and far-reaching. For the first time, cybersecurity is elevated to a top-tier enforcement priority, standing alongside criminal abuse and benefit distribution failures.
For fund trustees and administrators, this is not a minor regulatory adjustment. More to the point, while fund counsel may have been decrying the DOL cyber guidelines as sub-regulatory, it’s clear that EBSA is not treating them as an afterthought. This change is a clear signal about where examiner attention is heading and how fiduciary responsibility itself is being effectively redefined.
For years, EBSA enforcement often revolved around technical compliance. Investigations focused on whether disclosures were made, whether procedures were followed, and whether documentation existed. Fiduciaries who could demonstrate adherence to established processes were often able to resolve issues, even when underlying risks remained insufficiently addressed. That framework is now shifting.

The agency’s emphasis on what it calls “serious misconduct” reflects a move away from checklist-based oversight toward a more substantive evaluation of conduct, judgment, and outcomes. This shift is particularly significant in the context of cybersecurity. Unlike traditional compliance obligations, cybersecurity cannot be reduced to a static checklist. It requires ongoing vigilance, real-time judgment, and the ability to recognize and respond to evolving threats. By elevating cybersecurity to a primary enforcement priority, EBSA is signaling that failures in this area will no longer be treated as technical gaps. They will be evaluated as potential fiduciary breaches.
A recently filed federal complaint in the District Court in Alabama illustrates what this looks like in practice. In that case, a cybercriminal impersonated a plan administrator and successfully orchestrated the transfer of millions of dollars in plan assets through a series of fraudulent communications. What makes the case particularly instructive is not just the existence of the fraud, but the sequence of missed overt warning signs that enabled it.
According to the complaint, the fraudulent emails contained multiple indicators that are widely recognized as hallmarks of phishing attempts. These included inconsistent email signatures, altered contact information, typographical errors, and even system-generated warnings flagging the messages as suspicious. Despite these signals, the parties involved failed to detect or act on them. At several points, wiring instructions were changed via email without independent verification, even though such changes are commonly understood to be high-risk and require confirmation through trusted channels.
The situation escalated as additional red flags emerged. The fraudulent transaction forms differed from original documentation, lacked proper signatures, and directed funds to entirely new banking institutions. Even when an attempted transfer was initially rejected due to mismatched account information, the discrepancy did not trigger a meaningful reassessment of the situation. Instead, revised instructions were accepted and ultimately executed, resulting in the successful transfer of more than $2.5 million in plan assets to an unauthorized account. A significant portion of those funds remains unrecovered. What stands out in this case is not the sophistication of the attack, but the accumulation of overlooked signals and failure of even general oversight. The complaint repeatedly emphasizes that the indicators present were “commonly known, understood, and recognized signs of phishing,” and that governmental guidance had already identified these exact warning signs and recommended specific countermeasures, including verification procedures and employee training. In other words, the failure was not a lack of rules. It was a failure to apply them in practice and the implementation of meaningful oversight.
This is precisely the kind of fact pattern that EBSA’s new enforcement posture is designed to address. Under a checklist-driven regime, an organization might point to the existence of cybersecurity policies or general procedures as evidence of compliance. Under a misconduct-focused approach, the analysis shifts. Regulators will examine whether fiduciaries recognized the risk, whether they followed prudent verification practices, and whether their actions, or rather inaction, directly contributed to participant harm.
The implications for vendor oversight are particularly significant. In the case described, multiple service providers were involved in processing and executing transactions, yet responsibility did not dissipate across those relationships. Instead, the failures were cumulative. The absence of effective verification protocols, the lack of training, and the failure to escalate obvious warning signs created a chain of breakdowns that ultimately enabled the loss. This aligns closely with EBSA’s evolving view that delegation does not eliminate fiduciary responsibility.
The complaint highlights the absence of effective cybersecurity training and procedures, but more importantly, it underscores the failure to follow even basic verification steps that are widely recognized as standard practice. This distinction is critical. A written policy that requires confirmation of wiring instructions carries little weight if, in practice, no confirmation occurs, or oversight is minimized. Under the new enforcement framework, regulators are likely to focus on whether controls are operational, not merely whether they exist.
The consequences of this shift are substantial. The case demonstrates how quickly cybersecurity failures can translate into direct financial harm for plan participants. It also illustrates how those failures can give rise to claims of negligence, wanton conduct, and breach of fiduciary duty under ERISA, not to mention subpoenas for sworn testimony from managers and decision-makers alike.
In an enforcement environment that prioritizes “serious misconduct,” similar fact patterns are likely to attract regulatory scrutiny in addition to private litigation. More broadly, EBSA’s January 2026 restructuring signals a transition from procedural compliance to risk-based accountability. Cybersecurity is no longer a peripheral concern delegated to IT departments or third-party vendors. It is a core component of fiduciary governance.
Fiduciaries are expected to understand the risks their plans face, to implement controls that address those risks, and to ensure that those controls function effectively in practice.

In fact, it is an all-too-familiar mistake for organizations to reflexively delegate and classify the bulk of cybersecurity responsibilities as a tech problem when it really requires collaborative legal input, especially in the immediate aftermath of a cyber incident, to strategize long term over how to best mitigate far-reaching issues like liability, costs, and in many cases protracted complex litigation.
The lesson is not simply that cyber threats are increasing. It’s that regulatory expectations have changed, and greater statutory enforcement actions are being realized with increasingly consequential fines and penalties. When warning signs are visible, guidance is available, and harm is foreseeable, failure to act may now be viewed as a breach of duty rather than an operational oversight, leading to costs that create broader implications directly affecting an organization’s management structure and possibly its operational stability.
In sum, the rules did not just change. But the standard did.

The Department of Labor emphasizes the importance of cybersecurity for those responsible for plan-related IT systems and data.
Don't leave your cybersecurity to chance. Ensure best practices with a comprehensive solution tailored for unions.