Online banking phishing: When a call from your "bank" is a trap
Almost every day, phishing or fraud attempts pop up in our inboxes or on our smartphones. Often, we recognise these criminal communications and delete them. However, when it comes to online banking in particular, a believably worded phone call, a seemingly official phone number or an SMS containing a verification code is frequently enough for fraudsters to gain access to sensitive data. Situations like these pose considerable risks. This year’s S-U-P-E-R.ch national awareness campaign, "SUPER, right?", reminds us that we should always check whether information is credible and stick to established cybersecurity strategies.
In online banking phishing, perpetrators often pose as employees of a bank or its security department. They claim that they want to stop a suspicious payment, that a transaction is incorrect or that they need to resolve a security issue right away. In some cases, victims are also pressured with text messages and codes.
Check whether the story is credible
Because fraudulent communications appear very professional nowadays, it is a good idea to double-check everything. Do the details, sequence of events and explanation you are given actually add up? Some claims may sound plausible, but they fall apart under closer inspection. Although your bank can see that a transaction has taken place, it does not generally know exactly which product or service you have bought. If someone phones you and provides very detailed information about an alleged purchase, you should be particularly cautious.
Do not allow yourself to be put under pressure
Phishing thrives on a false sense of urgency. Fraudsters claim that they need to stop a payment immediately, protect your account or resolve an issue right away. Their aim is always to make you act quickly, without assessing the situation calmly. You should therefore be sceptical of any calls warning you of financial losses, criminal charges or suspensions to your accounts. Hang up immediately, and contact your bank yourself using their official phone number or app.
Never disclose your login details or codes
Through phishing, vishing and smishing, criminals attempt to access confidential data such as passwords, credit card details and one-time codes. This information is then misused to log directly into the victim’s online banking or make payments. Personal data such as passwords and credit card details should never be disclosed over the phone or on any websites linked in emails or text messages. Banks and credit card providers will never ask customers to share passwords or verify their credit card details via email.
Do not allow remote access to your devices
In particularly dangerous cases, victims are persuaded to install remote maintenance software on their smartphone or computer. They are then instructed to carry out various steps in their online banking, supposedly to stop fraudulent payments. In the background, however, the perpetrators use the data they have obtained to log in to the victim’s online banking account and execute payments themselves. If you are asked to install remote access software, end the call immediately. If you have already granted remote access, you should remove the software immediately and have the device checked by an expert.
Only use official access points
Never enter personal data on a website you have opened via a link in an email or text message. Instead, you should always use the official app or enter your bank’s web address directly in the browser yourself. Activating two-factor authentication offers you additional protection. This extra step may seem a little more inconvenient, but it is a simple and effective security measure.
Take immediate action if your data has already been compromised
If you have already disclosed your credit card details, contact your provider immediately to have your card blocked. If you have disclosed a password, change it immediately on all services where you use it. If you have installed remote access software, you should uninstall it and have the device checked by an expert. In the event of financial loss, the NCSC recommends informing your bank and reporting the incident to the police.
Using online banking securely may require a little more vigilance. However, this effort is not just a minor detail – it is an important step towards protecting your money, data and cybersecurity. Many phishing communications appear deceptively genuine, which makes critical thinking vital.
The tips above will help you to recognise these fraud attempts and avoid becoming a victim!
This year’s S-U-P-E-R.ch national awareness campaign, "SUPER, right?", reminds us that we should always check whether information is credible and stick to established cybersecurity strategies.
