|
Latest security and fraud
alerts:
November 14, 2009
Client Advisory: New Phishing Scam
NACHA - The Electronic Payments Association - has issued an advisory to financial institutions about phishing emails designed to appear as if they were sent from NACHA warning users about failed ACH transactions. The e-mail includes a link that, if clicked, redirects the individual to a fake web page that appears to be a NACHA website and contains a link that almost certainly leads to a Jabber/Zeus malware download.
This phishing attempt is not targeted specifically at NVE Bank or at any single financial institution. It is being sent broadly across the Internet.
Phishing E-mail Sample Content
From: nacha.org [mailto:report@nacha.org]
Sent: Thursday, November 12, 2009 10:25 AM
To: Doe, John
Subject: Rejected ACH transaction, please review the transaction report
Dear bank account holder,
The ACH transaction, recently initiated from your bank account, was rejected by the Electronic Payments Association. Please review the transaction report by clicking the link below:
Unauthorized ACH Transaction Report (this is how the link is presented)
Sanitized link:
hxxp://nacha[DOT]org[DOT]fffazsa[DOT]org[DOT]uk/ACHNetwork/Unauthorized/
report[DOT]php?transaction_id=3D00149589098593&reference=3D8227416592
37684356904818198557124583214180193361899444733=20
= = = = = End of Sample E-mail = = = = = =
NACHA is aware of the phishing attack and has an article on their home page at www.nacha.org.
August 26, 2009
Press Release: Federal Reserve Bank
The Federal Reserve Board on Wednesday warned consumers about fraudulent solicitations that appear to be made with the approval or involvement of the Federal Reserve, Federal Reserve officials, or other U.S. government officials. These solicitations promise bogus financial services or large sums of money in exchange for either payment or personal information that can then be used to access a consumer's bank account.
The Federal Reserve is advising consumers that it has no involvement in these solicitations. Consumers are strongly urged to verify the legitimacy of potential service providers before entering into a business transaction. Individuals seeking help with repairing their credit history, avoiding home mortgage foreclosure, finding mortgage refinance options, or managing their credit card debt should do business only with reputable service providers. Information related to these issues may be found on the Federal Reserve Board's website.
Individuals who have or suspect they have been a victim of a scam should contact local law enforcement agencies. Information related to how to identify a fraud or scam may be found on the Federal Reserve Board's Consumer Help Center website.
October 23, 2008
WARNING: PHONE SCAM ALERT
Customers and Non Customers of NVE Bank are receiving calls from entities stating that they are NVE Bank Fraud Dept. or Security Dept. and requesting personal information.
PLEASE DO NOT SUPPLY ANY INFORMATION OVER THE PHONE, UNLESS YOU INITIATED THE CALL. PLEASE CALL YOUR BRANCH IF YOU RECEIVE SUCH A CALL OR FOR MORE INFORMATION! THERE HAS BEEN NO SECURITY BREACH AT NVE BANK, NOR HAS YOUR INFORMATION BEEN COMPROMISED! THIS IS A SCAM!
Please contact customer service, custsvc@nvebank.com or your branch location to report if you have received a phone call requesting personal information.
September 26, 2008
Phishing Email Alert
Please be advised that there is a phishing scam underway that is targeting Business Banking users by sending e-mails that appear to be from official Digital Insight sources (e.g., "Digital Insight Customer Care"). The scam is designed to trick the recipient into clicking a link in the fraudulent e-mail for the purpose of acquiring sensitive data, such as passwords or financial information.
While the primary targets appear to be Business Banking users, other Internet Banking users may also be affected.
- Digital Insight systems nor NVE Bank have not been breached in any way. Your information is still safe.
- Recipients of these e-mails are not specific to NVE Bank end users. Phishing e-mails can go to anyone that has an e-mail address on the Internet, so it is not the case that someone has a list of your customers.
- We are currently working to shut down the sites that these phishing e-mails link to.
- Please do not click the link in this particular e-mail. If you are trying to identify the URL for reporting purposes, we recommend that you use your mouse to hover over the link.
- Some of the false e-mail addresses that users have reported include:
- tech-support@digitalinsight.com
- support@scfederal.digitalinsight.com
- admin@support.digitalinsight.com
- admin-support@digitalinsight.com
- customer-care@digitalinsight.com
- accounts@digitalinsight.com
- support@update.digitalinsight.com
- administration@digitallnsight.com
- While the addresses differ, the body of the e-mail remains relatively consistent ("We inform you that your account is about to expire. It is strongly recommended to update it immediately. Update form is located here. However, failure to confirm your records may result in account suspension.")
Contacting NVE Bank Customer Service (CS):
Please contact customer service, custsvc@nvebank.com or your branch location to report whether you have clicked on the link and submitted your personal or financial information.
July 19, 2008
Phishing Email Alert
Phishing e-mails have been circulating that seems to come from @digitalinsight.com. Examples of the false email addresses that users have reported include:
- admin-support@digitalinsight.com
- customer-care@digitalinsight.com
- accounts@digitalinsight.com
- support@update.digitalinsight.com
- administration@digitallnsight.com
While the e-mail addresses differ, the body of the email remains relatively consistent ("We inform you that your account is about to expire. It is strongly recommended to update it immediately. Update form is located here. However, failure to confirm your records may result in account suspension.")
Do not follow the instructions in these Phishing e-mails... DO NOT CLICK ON THE LINK. These e-mails are not emanating from Digital Insight nor would Digital Insight ever request you to make such changes to your account.
If you feel you have been a victim of this Phishing scheme, please call one of our branch office locations or 1-866-NVE-Bank.
May 30, 2008
Fraud/Scam Alert
We have received notifications that residents of Northern NJ have been receiving “Vishing” telephone calls impersonating local financial institutions. The automated calls specify local financial institutions and indicate to the consumer that their bank accounts have been frozen. In order to reactivate their accounts(s) the consumer should enter their ATM/Debit card information including card number, expiration date, PIN, and CV2 information from the back of the card.
The calls appear to be made from various telephone numbers. Please do not respond to this request over the telephone. NVE Bank does not initiate contact to its customers and request such information. NVE Bank will never ask for your ATM/Debit card PIN information at anytime.
So far, customers of NVE Bank have not reported any such calls or have been a victim of this scam. Please notify the bank by calling your branch office if you have received such a call or feel that you have been a victim of this scam.
|