How to Recognize Spam & Phishing
Social engineering attacks, widely known as phishing, are delivered in many different ways:
- Phishing = emails
- Smishing = text messaging
- Vishing = voice scams or phone calls
Scammers use these methods to try to steal your passwords, account numbers, Social Security numbers, and more. If they get that information, they could get access to your email, bank, or other accounts. Or they could sell your information to other scammers. Scammers launch thousands of phishing attacks like these every day — and they’re often successful. No matter the delivery, there are common clues you can spot!
- Urgency: Any message that creates a tremendous sense of urgency in which attackers are trying to rush you into taking quick action and making a mistake. An example is a message claiming to be from the government, stating your taxes are overdue and if you don’t pay right away you will end up in jail.
- Pressure: Any message that pressures an employee to ignore or bypass company security policies and procedures.
- Curiosity: Any message that generates a tremendous amount of curiosity or seems too good to be true, such as an undelivered UPS package or a notice that you are receiving an Amazon refund.
- Tone: Any message that appears to be coming from someone you know such as a coworker, but the wording does not sound like them, or the overall tone or signature is wrong.
- Sensitive Information: Any message requesting highly sensitive information, such as your password or credit card.
- Generic: A message coming from a trusted organization but using a generic salutation such as “Dear Customer”. If Amazon has a package for you or your phone service has a billing issue, they know your name.
- Personal Email Address: Any email that appears to come from a legitimate organization, vendor, or co-worker, but is using a personal email address like @gmail.com or @hotmail.com.
Phishing emails and text messages often tell a story to trick you into clicking on a link or opening an attachment. You might get an unexpected email, text message, or phone call that appears to be coming from a company you know or trust, like a bank or a credit card or utility company. Or maybe it’s from an online payment website or app. The message could be from a scammer, who might
- say they’ve noticed some suspicious activity or log-in attempts — they haven’t
- claim there’s a problem with your account or your payment information — there isn’t
- say you need to confirm some personal or financial information — you don’t
- include an invoice you don’t recognize — it’s fake
- want you to click on a link to make a payment — but the link has malware
- say you’re eligible to register for a government refund — it’s a scam
- offer a coupon for free stuff — it’s not real
Scammers often update their tactics to keep up with the latest news or trends so it's best to stay informed!
What First Atlantic Will Never Ask You
Please remember that we'll never initiate a call, email, or text asking you for:
- Your debit/credit card number, PIN, or CVV.
- Your member number, account number, full social security information, or any other security passcodes.
- Your online or mobile banking login information.
- Your passwords.
You should never share any of this information with anyone and remember that while our employees may contact you to verify suspicious debit or credit card transactions, they'll never ask you for the info above.
If you receive one of these calls or texts or you have supplied personal information via email, phone, social media, or other means to someone you suspect is scamming you, please contact us immediately at 732-380-3600 or call the number on the back of your card.
Always monitor your account and if you see fraudulent transactions, notify us right away. You can protect yourself by registering for real-time text fraud alerts for your First Atlantic credit and debit cards. Once registered, you'll receive a text and/or pre-recorded voice call when there's a suspicious transaction on your card.
Four Ways to Protect Yourself from Phishing
1. Protect your computer by using security software. Set the software to update automatically so it will deal with any new security threats.
2. Protect your cell phone by setting software to update automatically. These updates could give you critical protection against security threats.
3. Protect your accounts by using multi-factor authentication. Some accounts offer extra security by requiring two or more credentials to log in to your account. This is called multi-factor authentication. The extra credentials you need to log in to your account fall into three categories:
- something you know — like a passcode, a PIN, or the answer to a security question.
- something you have — like a one-time verification passcode you get by text, email, or from an authenticator app, or a security key
- something you are — like a scan of your fingerprint, your retina, or your face
Multi-factor authentication makes it harder for scammers to log in to your accounts if they do get your username and password.
4. Protect your data by backing it up. Back up the data on your computer to an external hard drive or in the cloud. Back up the data on your phone, too.