Bank Impersonation Scams Are Evolving. Watch for These Red Flags.
Key Takeaways:
- There are multiple forms of bank impersonation fraud, and each poses a risk to consumers.
- Malvertising, SMS phishing, fake phone calls, and even fraudulent bank employees on social media can trick consumers into submitting their account credentials.
- Understanding the red flags and knowing how to identify legitimate bank communications and websites can help you avoid scams.
By Kevin Novak, Old National Bank Chief Information Security Officer
Bank impersonation fraud is becoming increasingly common, with scammers finding new ways to trick consumers into believing they’re logging in to or communicating with their bank. But in reality, they’re stealing people’s personal information and often gaining access to their financial accounts.
At Old National Bank, helping our customers understand common scams used by fraudsters is a critical part of our cybersecurity strategy. You can protect yourself and your financial assets by watching out for the following bank impersonation schemes:
Customer Service Scams: In this scheme, the fraudster impersonates your bank's customer support or fraud team and tries to convince you to transfer funds or reveal your personal account information. They may claim there's an urgent problem with your account or suspicious activity that needs to be addressed immediately. They offer to mitigate the issue and try to convince you to reveal your personal account information, provide login credentials, or authentication, MFA, or verification codes. To reduce your risk, be on alert to these red flags:
- Anyone who asks for your password, PIN, MFA credentials, or verification code
- A caller that requests you to transfer money to a "safe" or temporary account
- A conveyed or implied sense of urgency or pressure to act immediately
- Anyone who asks you to download software or give them remote access to your device
Malvertising: The term is shorthand for malicious advertising. With this scheme, fraudsters place real ads, often on legitimate websites, that direct people to fraudulent sites. You may see an advertisement for your bank, but when you click on it, you’re sent to a fake website. The scammers' goal is either to collect your username and login credentials to access your account or to install malware on your device that then collects personal and financial information. You can inadvertently download such malware just by clicking on an ad. To reduce your risk, avoid the following:
- Pop-up ads that demand you take an action now
- Any ad that prompts a virus warning or security alert
- Anything that begins downloading without your permission
- Ads that redirect you to a different website
SMS phishing, or smishing: refers to scammers sending fake texts, such as those that pretend to be from a bank, to try to collect personal data, download malicious content, or direct you to malicious sites, or call a malicious threat actor. For example, they might suggest there’s suspicious activity on your account or say your account is locked. The messages then contain a link to a fake website with a login page, allowing the scammers to steal your username and password and access your account. To reduce your risk of smishing:
- Call your bank to confirm alerts of suspicious activity
- Don’t click on website links provided by texts
- Don’t provide passwords or other authentication credentials via SMS
- Don’t call a number provided via the SMS, call a known good number
- Always access your account from your bank's mobile app, or the bank’s full URL, such as https://www.oldnational.com (note: your bank won’t send you a link to a login page)
Fraudulent calls and emails: Similar to smishing, fraudsters often attempt to contact potential victims via fraudulent phone calls (vishing) and emails (phishing). This may also be under the pretense of alerting you to suspicious activity or to your account being locked. Again, the emails may send you to a webpage, while callers often ask for your information over the phone. The caller ID is often spoofed as well, showing a number that says it’s your bank. The endgame remains the same—to steal your login information and gain access to your account. To avoid fake calls and emails:
- Hang up if a caller says they’re your bank, and then call your bank back at a known good number
- Ignore email links, and don’t click on anything sent to you
- Pay attention to URLs and make sure they match the URL you know your bank uses; paying particularly close attention to the TOP LEVEL DOMAIN (TLD), or the name immediately preceding the dot (.). For Old National our TLD is oldnational.com. Fraudsters will often include a legitimate bank name as a subdomain with a malicious TLD such as co.com (such as bankname.co.com).
Fake bank employees on social media: Not only are scammers spoofing websites, text messages, voice calls, and emails, they’re also spoofing people on other mediums like social media sites. In this emerging cyberfraud scheme, scammers create fake social media profiles of bank employees, complete with bank logos, titles, bios, and more. They then monitor the legitimate social media pages of banks and jump into the conversation when a customer has a question, diverting them to—you guessed it—a fake bank website or login page. Warning signs that an employee may be a scammer include:
- They ask you to direct message (DM) them private information such as account usernames and passwords or card numbers
- Their social media account isn’t verified with a blue check mark
If the person you’re communicating with seems suspicious, hang up and call your bank at a known good number and ask for them directly.
Malicious Redirect Chains: Fraudsters manipulate search engine results to redirect you through multiple different domains until landing you on a malicious site. The scammer's goal is to evade takedown measures and eventually lead you to a fake banking site designed to look legitimate. To reduce your risk, watch for these common traps:
- Search engine results that look authentic, but direct you to a website that is not
- Links that send you through multiple websites, or include unexpected redirects
- Pages that ask you to login after being redirected
- Browser security warnings or pop-ups
- Any downloads that begin without your permission
How to Stay a Step Ahead
In the vast majority of bank impersonation schemes, the fraudsters are using some form of contact to redirect you to a fake website. In addition to the tips above, knowing how to identify a potentially fraudulent website or landing page is also helpful. Consider the following:
- Don’t search for your financial institution, type your bank's official URL and make it a favorite in your browser. So instead of searching for Old National Bank via a search engine or URL bar, type the website address—https://www.oldnational.com—into your URL and save it. That way, you can easily navigate to the official website whenever you need.
- If you do receive a link to a purported Old National Bank site, examine the address. With exception to sites directly linked from our website (https://www.oldnational.com), web pages related to Old National Bank will always end with oldnational.com or oldnational.olbanking.com. Malicious sites will be a variation of that, but not exact. Again, you can then use your favorite site to navigate to the official site and avoid the links altogether.
- Look for the padlock in the URL. The padlock icon indicates that you’re on a website that protects your sensitive information. While this isn’t enough to confirm a website's validity, all Old National Bank webpages will display the lock symbol. And you can rest assured that if the lock isn’t there, it’s not an official Old National Bank webpage. Note that some browsers like Chrome require you to click on the settings icon to the left of the URL to see if the site is secure)
- Use the mobile app. The Old National Bank mobile banking app helps ensure that you have access to your accounts safely and securely. Download and install our app directly from the Apple App Store or Google Play Store for easy access. The cybersecurity threats evolve quickly, but we’re moving just as fast. Learn how to safely access your Old National Bank accounts, and contact us immediately if you suspect fraud.
Kevin Novak is the Chief Information Security Officer for Old National Bancorp, where he leads the enterprise-wide strategy and programs responsible for protecting the organization's information assets and supporting the security of client data. Throughout his career, Kevin has held senior cybersecurity leadership roles at Breakwater Solutions, Northern Trust, ServisFirst Bank, the University of Chicago Medical Center, and Discover Financial Services. He also serves as a National Sector Chief for InfraGard, is a committee member for the Chicago CISO of the Year program, and is a co-founder of ChiBrrCon.