Categories
Blog Business Fraud & Security

Fraud alert: What you need to know

Criminals take advantage of every situation and our health crisis is no exception.

Recently, the cybercriminal group, FIN7, known for targeting US businesses through phishing emails, deployed an additional tactic of mailing USB devices via the United States Postal Service (USPS). The mailed packages sometimes include items like teddy bears or gift cards to employees of target companies working in the Human Resources (HR), Information Technology (IT), or Executive Management (EM) roles. The enclosed USB device is a commercially available tool known as a “BadUSB” or “Bad Beetle USB” device. After the USB device is plugged into a target system, the USB device automatically injects a series of keystrokes in order to download and execute a unique malware payload commonly known as the GRIFFON malware, which is also a payload observed in several variations of FIN7 phishing emails.

Please do not plug an unknown USB device into any computer system. And always be wary of packages coming from someone unknown to you or of a package coming from someone that seems out of the normal routine. Call to verify before inserting anything in your computer system.

Educating your cardholders on phishing

Early indications are that fraudsters may be increasing phishing attacks in an effort to exploit the current COVID-19 pandemic. The Risk Office has observed fraudster emails and voice mails sent directly to cardholders asking for personally identifiable information (PII) and impersonating the Financial Institutions (FI), health groups, and federal government agencies.

Additionally, criminals in possession of card details and other forms of PII are spoofing the phone number from financial institutions to fool cardholders into thinking that text messages and phone calls are actually from the fraud department of their financial institution.

It makes a difference when you and your cardholders remain vigilant. If something sounds suspicious, question it. As a reminder to your cardholders, it’s important that they remain diligent in reviewing their accounts daily and quickly report any unauthorized activity.

Please remind your cardholders that there is a lot that they can do to protect their own financial accounts and information in order to avoid compromising their own information. Here are some of the points you can make to help educate your cardholders:

Neither Vallant Bank nor the fraud department will ever ask over the phone for PIN, CV2 codes or Expiration Dates.

 

A text alert warning of suspicious activity on a card will NEVER include:

    • A link to be clicked. Cardholders should never click on a link in a text message that is supposedly from us.
    • Vague reference to a “Merchant” transaction; details should be included
    • Requests for cardholder data such as card numbers, PINs, CV2 Codes, Expiration Date
    • A text alert from us will always be from a 5-digit number and NOT a 10-digit number resembling a phone number.

A VALID notification will provide information about the suspicious transaction and ask the cardholder to reply to the text message with answers such as ‘yes,’ ‘no,’ ‘help,’ or ‘stop.’ 

    • A phone call from one of our Call Center agents will only include a request for the cardholder zip code, and no other personal information, unless the cardholder confirms that a transaction is fraudulent.
    • Only then will the cardholder be transferred to an agent, who will ask questions to confirm the cardholder’s identity before going through the transaction history. If at any point the cardholder is uncertain about questions being asked or the call itself, they should hang up and call us directly.
    • If a call is received by the cardholder claiming to be your Call Center and asking to verify transactions, no information should have to be provided by the cardholder other than their zip code, and a ‘yes’ or ‘no’ to the transactions provided.
Categories
Blog Business Fraud & Security

Protect your business from cybersecurity threats

Just because you own a small business doesn’t mean you’re immune to a cyberattack. No matter the size of your company, if you conduct any business online, you’re at risk of an attack. However, there are many things you can do to protect your business and customer data.

  1. Train employees on security practices and policies. Your employees should know and understand your company’s Internet use guidelines, penalties for violating company cybersecurity policies, and how to handle and protect customer information and other vital data.
  1. Keep your computers clean. Install the latest security software, web browser, and operating system on all your company computers and laptops. Also, make sure you set a time to scan for anti-virus and anti-malware software regularly.
  1. Provide firewall security for your Internet connection. A firewall keeps your network protected from outside intrusions. It’s essential to keep it updated and enabled at all times. If employees work from home, make sure they have a firewall protecting their home system(s) as well.
  1. Secure your Wi-Fi network. If you offer Wi-Fi at your workplace, make sure it’s secure, encrypted, and hidden from outside intruders. Ask your technology expert to help you find ways to keep your Wi-Fi network hidden and protect access to your router as well.
  1. Create back-up copies of all essential data. Regularly back up all critical data on your computers, including documents, electronic spreadsheets, databases, financial files, human resource files, and other account information. It’s best to back up data automatically at least weekly and store copies offsite or in the cloud (protected by a password).
  1. Manage the security of mobile devices. If you use mobile devices to hold or manage confidential information, it’s critical you require users to password-protect their devices, encrypt their data, and install any security app to prevent criminals from stealing data. Additionally, make sure your employees understand how to report a lost or stolen mobile device.
  1. Limit physical access to your computers. Create a user account for each employee and be sure all computers and laptops lock automatically when unattended. Require employees to use strong passwords to access computers and to change them often — experts recommend changing your passwords at least every three months (at a minimum). Additionally, only allow administrative access to key personnel.

While this is not a complete list, it’s a great way to start protecting your business. And your diligence in protecting your business and customer data today will help you limit your chances of a cybersecurity attack in the future.

Categories
Business Fraud & Security

Five ways to protect your business from mobile payment fraud

Most people expect their mobile devices to do everything they need – from watching television and ordering food to making purchases online or in person. If your business accepts mobile payments in your store or online through an app or website, there are ways to reduce your chance of becoming a victim of mobile payment fraud.

  1. Use secure a Wi-Fi network. One of the most effective ways to keep your data safe from intrusion is to use a secure Wi-Fi network. And, if you encrypt your network, any information taken will be useless. Talk to your computer expert (if it’s not you) to build a strong password for your router and a unique SSID name for your wireless network. Additionally, turn on the most recent and secure encryption within your router.
  2. Build-in biometric detection. Today’s devices come with many different biometric features (fingerprint scanning and voice or facial recognition) to confirm a person’s identity and deter fraudsters from using someone else’s phone to make purchases. Of course, not every customer uses the latest device. To protect any purchases made through your app, install biometric feature detection software to weed out fraudulent purchases.
  3. Verify your customer’s identity. Implement a two-factor authentication method for all mobile and online purchases to ensure your customers are who they say they are. This is where you send a verification code to the customer’s email address or phone number (via text or call) associated with the account. The customer must then use the code provided to complete the transaction.
  4. Require a CVV code. When your customers use a credit or debit card to make mobile transactions, require them to use the CVV (or three-digit) code on the back of the card. The use of the CVV code will reduce your chances of “card not present” fraud as the customer must have access to the physical card to complete the transaction.
  5. Use browser detection for online purchases. If your business accepts mobile payments for online shopping, using a browser detection protocol will prevent users from completing transactions through insecure browsers. You can then direct them to make purchases through your app or another approved, secure browser.

Don’t be afraid to offer mobile payments because of fraud – find ways to combat it. By implementing one or more of these tips, you’ll be on your way to protecting your business from mobile fraud and be able to offer customers an easy way to pay for your products and services.

Categories
Blog Business Fraud & Security Personal Safety & Security

Are you a target for identity theft?

Did you know that your social media habits could put you at risk for identity theft? It’s essential to understand how to protect yourself and how to avoid catching a thief’s attention.

Weak passwords

Is your password ‘password,’ your name, or something equally easy to guess? It’s time to change it up! Your passwords should be reasonably complicated with a mix of numbers, upper and lowercase letters, and special characters.

Do you have one password or a few passwords that you use for everything? Danger! Using the same password across multiple channels makes your account easy to hack. If you have trouble remembering lots of passwords, then consider getting a password manager.

Clicking on unfamiliar links

Here’s a good rule to follow: don’t click on links that are fishy in email, text, or on social media. But how to decide if something is questionable or not?

In email, text, and on social media:

  • Verify the sender as someone you know and/or are expecting a message from, such as a business
  • Verify the security token by checking to see if the URL begins with “https.”
  • Are there lots of grammatical errors or misspelled words? Don’t trust it!
  • Move your cursor over the link. Does the URL and displayed name match?

Finally, when in doubt, don’t click! No link is worth your identity being stolen.

Sharing too much

Some things are better kept private online. Don’t publicly share your home address, phone number, email, etc. With this basic information, an identity thief can dig up enough information on you to set up a fraudulent credit card account.   

It’s also wise to turn off geolocation tags on social media. It’s fine to tag a photo as being in a particular city, but some tags will actually show your home address! Check your social accounts, and be sure your location data is turned off.

Birthday celebration – for identity thieves

It’s so much fun to get birthday wishes online, but it can be an invitation for identity thieves to ‘party’ with your information. Want to get the well-wishes without the risk? Make sure you aren’t using your birthday in any of your passwords. You can also place a partial birthday – day and month only, leaving the year of your birth out – on most social media platforms.

Checking in too often

Checking in at the places and businesses you frequent the most gives identity thieves too much information into your personal life. Identity thieves are talented at taking lots of seemingly useless information and putting it all together to steal your money. Don’t make it easy for them by telling the world where you bank, shop, etc.

Know your friends

It’s fun to have lots of friends online, but it’s best to know who they really are. Identity thieves set up fake accounts which are then used for fraud attempts or scams. When you get a friend request from someone you don’t know, it’s best to decline.

The above tips will help you to keep your information safe from identity thieves. By being proactive now, you can save yourself from a lot of grief later.

Categories
Blog Business Fraud & Security Personal Safety & Security

How to spot an online dating scam

People looking for love have all the typical concerns: will he/she like me? Do we have the same interests, etc.? As if finding a partner isn’t hard enough, now, those who use online dating services also have to worry about being scammed out of money. 

There are hundreds of thousands of profiles on dating sites. How can you tell who is the real person also looking for love, and the fake profile looking to deplete your bank account?

How to quickly spot an online dating scam

They ask you for money

This one is simple. If someone on an online dating service asks you for money, it’s a scam.

They ask you to leave the site

Online dating websites can spot and dismiss members who are scammers or those who demonstrate other problematic behaviors. So, it is in the con artist’s best interest to get you to text or email with them, or even speak to them on the phone rather than communicate via the website. The most common excuse that a scammer will use is that their membership is almost up. It’s best to stay on the original site to communicate with other members. It’s an added layer of protection for you, and if the person you are speaking to does turn out to be a troll, you can report them to the dating site for abuse.

They won’t meet you in person

It’s a big red flag if the person you’re speaking to online says that they live in the same city as you, but they are working or stationed overseas, have an emergency far away, are always traveling, etc. Of course, it is possible that someone you are speaking to online travels a lot, but if they always have an excuse for why they can’t meet you in person, beware.

They show off how wealthy they are

Why would they need money from you when they are so wealthy? Their photographs show off fancy cars, mansions, etc. Why would a scammer do this? This illusion of wealth means that initially, you’re not worried that they are going to ask you for money. After earning your trust, they will ask you to ‘loan’ them money and give you a contrived excuse as to why they don’t currently have access to their own funds. To repeat the first warning in this list: if someone asks you for money in connection with an online dating site, it is a scam.

They don’t have a grasp of common grammar

Be suspicious if someone online claims to be college educated and live in your town, but they can’t write coherently. Weird word choices, lousy grammar, and sentences that don’t make any sense are all indicators that the person you’re speaking to is not who they seem to be.

Their life is one calamity after another

Your online friend contacts you in a panic. He’s lost his wallet, his son is in the hospital in another country, and he is desperate for help. He needs money for a hotel, airfare, etc. This is just one of the many stories that scammers tell. They may even resort to sending you heartbreaking photos of young children ill in a hospital. This scam is widespread, and you should never send money.

How to avoid being scammed

It’s easy to read the above with a clear head and think, “I would never be taken in by an online dating scam.” But when emotions are involved, and when a scammer has worked very hard to gain your trust, it’s not easy. So how can you protect yourself?

    • Don’t send money. Don’t wire money, send a gift card, or use an app to send money. You will never see the money again.
    • Talk to a trusted friend. Your friend is not emotionally involved in the online relationship. They will be able to spot that something isn’t right more quickly than you will.
    • Already sent money? Contact your bank and tell them you believe you have given money to a con artist.
    • Report the scammer! You can help others from being taken in by reporting your experience to the dating site you were on as well as the Federal Trade Commission (link https://www.ftccomplaintassistant.gov) and the FBI (link: https://www.ic3.gov/default.aspx)
Categories
Business Fraud & Security

12 Tips for protecting your mobile devices

As consumer use of mobile devices continues to climb, cyber criminals are targeting those gadgets more frequently. According to a report by the Federal Reserve, 43 percent of smartphone users say they have used mobile banking in the past 12 months. Vallant Bank is highlighting 12 ways consumers can take extra precaution to protect the data on their mobile device.

“We use gold-standard safeguards to protect customer information, but it’s also important for users to keep safety measures in place to prevent sensitive data from being compromised,” said L. Jackson McConnell, Jr., Vallant CEO.“It’s easy to forget that your mobile device can be vulnerable, but any device used to connect to the internet is at risk.”

Vallant Bank suggests following these 12 steps to protect your mobile device:

Use the passcode lock on your smartphone and other devices – This will make it more difficult for thieves to access your information if your device is lost or stolen.

Log out completely – when you finish a mobile banking session.

Protect your phone from viruses – and malicious software, or malware, just like you do for your computer by installing mobile security software.

Use caution when downloading apps – Apps can contain malicious software, worms, and viruses. Beware of apps that ask for unnecessary “permissions.”

Download the updates – for your phone and mobile apps.

Avoid storing sensitive information – like passwords or a social security number on your mobile device.

Tell your financial institution immediately if you change your phone number – or lose your mobile device.

Be aware of shoulder surfers – The most basic form of information theft is observation. Be aware of your surroundings especially when you’re punching in sensitive information.

Wipe your mobile device before you donate, sell or trade it using specialized software or using the manufacturer’s recommended technique. Some software allows you to wipe your device remotely if it is lost or stolen.

Beware of mobile phishing – Avoid opening links and attachments in emails and texts, especially from senders you don’t know. And be wary of ads (not from your security provider) claiming that your device is infected.

Watch out for public Wi-Fi – Public connections aren’t very secure, so don’t perform banking transactions on a public network. If you need to access your account, try disabling the Wi-Fi and switching to your mobile network. Consider using a Virtual Private Network (VPN) app to secure and encrypt your communications when connecting to a public Wi-Fi network. (See the Federal Trade Commission’s tips for selecting a VPN app.)

Report any suspected fraud to your bank immediately.

Categories
Blog Business Fraud & Security

Fight ID fraud online

Nearly three decades after the internet was introduced, the web continues to transform the lives of many users, revolutionizing the way consumers shop, pay bills, and transfer money online. As these advancements make common tasks hassle-free, consumers are urged to take extra precautions, allowing them to navigate the web safely and avoid online crime.

Here are eight ways you can safeguard your information and navigate the web safely:

    1. Keep your computers and mobile devices up to date. Having the latest security software, web browser, and operating system are the best defenses against viruses, malware, and other online threats. Turn on automatic updates so you receive the newest fixes as they become available.
    2. Set strong passwords. A strong password is at least eight characters in length and includes a mix of upper and lowercase letters, numbers, and special characters.
    3. Watch out for phishing scams. Phishing scams use fraudulent emails and websites to trick users into disclosing private account or login information. Do not click on links or open any attachments or pop-up screens from unfamiliar sources. Forward phishing emails to the Federal Trade Commission (FTC) at spam@uce.gov – and to the organization impersonated in the email.
    4. Keep personal information personal. Hackers can use social media profiles to figure out your passwords and answer those security questions in the password reset tools. Lock down your privacy settings and avoid posting things such birthdays, addresses, mother’s maiden name, etc. Be wary of requests to connect from people you do not know.
    5. Secure your internet connection. Always protect your home wireless network with a password. When connecting to public Wi-Fi networks, be cautious about what information you are sending over it. Consider using a Virtual Private Network (VPN) app to secure and encrypt your communications when connecting to a public Wi-Fi network.
    6. Be careful in the cloud. While using the cloud makes it easier to store and share large amounts of files, understand that it also opens other avenues for attack.
    7. Shop safely. Before shopping online, make sure the website uses secure technology. When you are at the checkout screen, verify that the web address begins with https. Also, check to see if a tiny locked padlock symbol appears on the page.
    8. Read the site’s privacy policies. Though long and complex, privacy policies tell you how the site protects the personal information it collects.
    9. Report any suspected fraud to Vallant Bank immediately.
Categories
Blog Business Fraud & Security Safety & Security

Is it really the IRS contacting you?

From the Internal Revenue Service

Scammers impersonating IRS officials are a growing issue. It is happening in person, over the phone, and via email. Your best defense is being informed and knowing the IRS protocol for contacting taxpayers. The IRS initiates most contact through regular mail. Taxpayers generally receive several notices/letters before they are called or visited.

The IRS does not:

    • Call to demand immediate payment
    • Demand that you pay taxes without question or appeal
    • Threaten to contact local police, immigration officers or other law enforcement

The IRS does:

    • Provide two forms of credentials if you are visited in person
    • Provide you with a dedicated IRS phone number for verification

For more information about avoiding these scams and what to do if you are scammed, click here.

Categories
Blog Business Fraud & Security Personal Safety & Security

Protect your “cyber home” with a solid foundation

From an original article by the Federal Deposit Insurance Corporation

As we all do more tasks such as shopping and banking on our computers, tablets, and smartphones, the need to keep our devices and networks secured has never been more important. Just as your home has locks to deter criminals from stealing your personal belongings, your electronic assets need to be properly protected to prevent theft. Otherwise, it’s like leaving your front door wide open.

Here are tips for cybersecurity:

Use a firewall program – A firewall is a combination of hardware and software that establishes a barrier between your personal computer and an external network, such as the internet, and then monitors and controls incoming and outgoing network traffic.

Keep software up to date – Software manufacturers continually update their products to fix vulnerabilities or security weaknesses when they find them. This includes everything from your operating system and word processing software to your internet browsers and digital photography software.

Use security products from reputable companies – Some anti-virus software and firewalls can be purchased while others are free. Either way, it’s a good idea to check out these products by reading reviews from computer and consumer publications. Use products that have high ratings for detecting problems and providing support if your computer becomes infected.

Plan for a lengthy retirement – The good news is people are living longer. The bad news is many aren’t saving enough for retirement to match their life expectancy. According to the Social Security Administration, men and women who reach the age of 65 can expect to live until ages 84.3 and 86.6, respectively.

This only a fraction of the steps you can take to secure your electronic assets and home network. For the complete list, click here.

Categories
Blog Business Fraud & Security

How safe are your business checks?

With all of the headlines about data breaches and online security, it’s easy for some people to forget about the threat of check fraud. We haven’t. If you are a business checking customer at Pinnacle Bank and order your checks through Harland Clarke, you are automatically protected by CheckArmor® Check Fraud Recovery.

If check fraud ever occurs, a certified fraud resolution specialist will guide you through the recovery process, replace your check, and if necessary, advance funds for any losses from the affected checking account.

Fraudulent Acts Covered by CheckArmor:

    • Forged signature – a legitimate blank check that is forged with the business signature
    • Forged endorsement – a legitimate check that is endorsed and cashed or deposited by a person other than the designated payee based upon a fraudulent endorsement
    • Altered check – a legitimate check that is fraudulently altered as to the designated payee, check amount, or otherwise to benefit the person altering the check
    • Counterfeit check – fraud in the form of check reproduction on unauthorized check stock

When you receive a new order of checks from Harland Clarke, look for the enclosed CheckArmor information card. Keep it handy for future reference should check fraud occur. At Vallant Bank, we are dedicated to helping your business thrive. That includes keeping your information and finances safe. It’s a responsibility we take seriously.