Categories
Blog Business Fraud & Security

Fraud alert: What you need to know

Criminals take advantage of every situation and our health crisis is no exception.

Recently, the cybercriminal group, FIN7, known for targeting US businesses through phishing emails, deployed an additional tactic of mailing USB devices via the United States Postal Service (USPS). The mailed packages sometimes include items like teddy bears or gift cards to employees of target companies working in the Human Resources (HR), Information Technology (IT), or Executive Management (EM) roles. The enclosed USB device is a commercially available tool known as a “BadUSB” or “Bad Beetle USB” device. After the USB device is plugged into a target system, the USB device automatically injects a series of keystrokes in order to download and execute a unique malware payload commonly known as the GRIFFON malware, which is also a payload observed in several variations of FIN7 phishing emails.

Please do not plug an unknown USB device into any computer system. And always be wary of packages coming from someone unknown to you or of a package coming from someone that seems out of the normal routine. Call to verify before inserting anything in your computer system.

Educating your cardholders on phishing

Early indications are that fraudsters may be increasing phishing attacks in an effort to exploit the current COVID-19 pandemic. The Risk Office has observed fraudster emails and voice mails sent directly to cardholders asking for personally identifiable information (PII) and impersonating the Financial Institutions (FI), health groups, and federal government agencies.

Additionally, criminals in possession of card details and other forms of PII are spoofing the phone number from financial institutions to fool cardholders into thinking that text messages and phone calls are actually from the fraud department of their financial institution.

It makes a difference when you and your cardholders remain vigilant. If something sounds suspicious, question it. As a reminder to your cardholders, it’s important that they remain diligent in reviewing their accounts daily and quickly report any unauthorized activity.

Please remind your cardholders that there is a lot that they can do to protect their own financial accounts and information in order to avoid compromising their own information. Here are some of the points you can make to help educate your cardholders:

Neither Vallant Bank nor the fraud department will ever ask over the phone for PIN, CV2 codes or Expiration Dates.

 

A text alert warning of suspicious activity on a card will NEVER include:

    • A link to be clicked. Cardholders should never click on a link in a text message that is supposedly from us.
    • Vague reference to a “Merchant” transaction; details should be included
    • Requests for cardholder data such as card numbers, PINs, CV2 Codes, Expiration Date
    • A text alert from us will always be from a 5-digit number and NOT a 10-digit number resembling a phone number.

A VALID notification will provide information about the suspicious transaction and ask the cardholder to reply to the text message with answers such as ‘yes,’ ‘no,’ ‘help,’ or ‘stop.’ 

    • A phone call from one of our Call Center agents will only include a request for the cardholder zip code, and no other personal information, unless the cardholder confirms that a transaction is fraudulent.
    • Only then will the cardholder be transferred to an agent, who will ask questions to confirm the cardholder’s identity before going through the transaction history. If at any point the cardholder is uncertain about questions being asked or the call itself, they should hang up and call us directly.
    • If a call is received by the cardholder claiming to be your Call Center and asking to verify transactions, no information should have to be provided by the cardholder other than their zip code, and a ‘yes’ or ‘no’ to the transactions provided.
Categories
Blog Business Fraud & Security

Protect your business from cybersecurity threats

Just because you own a small business doesn’t mean you’re immune to a cyberattack. No matter the size of your company, if you conduct any business online, you’re at risk of an attack. However, there are many things you can do to protect your business and customer data.

  1. Train employees on security practices and policies. Your employees should know and understand your company’s Internet use guidelines, penalties for violating company cybersecurity policies, and how to handle and protect customer information and other vital data.
  1. Keep your computers clean. Install the latest security software, web browser, and operating system on all your company computers and laptops. Also, make sure you set a time to scan for anti-virus and anti-malware software regularly.
  1. Provide firewall security for your Internet connection. A firewall keeps your network protected from outside intrusions. It’s essential to keep it updated and enabled at all times. If employees work from home, make sure they have a firewall protecting their home system(s) as well.
  1. Secure your Wi-Fi network. If you offer Wi-Fi at your workplace, make sure it’s secure, encrypted, and hidden from outside intruders. Ask your technology expert to help you find ways to keep your Wi-Fi network hidden and protect access to your router as well.
  1. Create back-up copies of all essential data. Regularly back up all critical data on your computers, including documents, electronic spreadsheets, databases, financial files, human resource files, and other account information. It’s best to back up data automatically at least weekly and store copies offsite or in the cloud (protected by a password).
  1. Manage the security of mobile devices. If you use mobile devices to hold or manage confidential information, it’s critical you require users to password-protect their devices, encrypt their data, and install any security app to prevent criminals from stealing data. Additionally, make sure your employees understand how to report a lost or stolen mobile device.
  1. Limit physical access to your computers. Create a user account for each employee and be sure all computers and laptops lock automatically when unattended. Require employees to use strong passwords to access computers and to change them often — experts recommend changing your passwords at least every three months (at a minimum). Additionally, only allow administrative access to key personnel.

While this is not a complete list, it’s a great way to start protecting your business. And your diligence in protecting your business and customer data today will help you limit your chances of a cybersecurity attack in the future.