MADISON, Wis.—How concerned should senior executives at credit unions be that they are at risk of a home invasion by sophisticated robbers who hold them hostage and force them to go to their credit union to commit a robbery?
It’s a question getting new focus while police continue to investigate an alleged home invasion/robbery attempt at Achieve Financial CU in New Britain, Conn., where the CFO has said that he and his mother were held hostage in his home overnight before robbers placed what they said was a bomb vest on him and forced him to drive to a branch.
The scenario in Connecticut is not unique. In 2007 a branch manager of Jeep Country FCU in Ohio was held hostage overnight in her home with her family, then driven in the middle of the night by two robbers to go to a branch and get money. The manager was left in her pajamas in the CU’s parking lot while the robbers escaped with the money. No one was hurt.
Now, with personal information on credit union executives, including their home addresses, more readily accessible than ever, should CUs and individuals be taking additional precautions?
Mike Petrone, risk management consultant with CUNA Mutual, said the risk is a “concern,” but he was also careful that that risk not be over-stated.
“Employee abduction is absolutely is something we take seriously and we do play close attention to when we do our security reviews,” said Petrone. “We don’t want to exaggerate it, but it is something that does happen.”
Petrone said CUNA Mutual works with all the credit unions it insures to set up controls to minimize abduction risks, and has published a white paper on how to handle such situations, such as listening carefully to background noise during phone calls.
“We do address it with senior management, but not usually with the entire staff, as we don't want to lead a teller to file her resignation,” said Petrone. “Most credit unions do not give this as much attention as they should; unfortunately, a lot don't think that it could happen to them.”
When a would-be robber is casing a credit union, he or she is looking to find out who does what, when they do it, and whether there is one person who has a key, an alarm code and the combination to the safe.
“If one person has all three, then the bigger the target as it's just one step with a hostage,” said Petrone. “It is critical that there is not just one person and that there is a separation of duties, a split combination and a time lock. (Robbers) don't want to be involved with multiple people. They make case you multiple times so they know exactly who it is, so separation is key. The CEO and the CFO who may not even know the combination.”
The increased prevalence of social media usage has raised the risk factor, said Petrone, which is why employees should be required to sign confidentiality agreements that no credit union-related information ever be shared on personal accounts.
As for whether asset size might contribute to the risk, Petrone said that is not the case.
“A lot of this happens at the branch level so asset size does not matter,” he said.
Petrone urged credit unions seeking more information to contact the CUNA Mutual Protection Resource Center or their sales team or risk manager.
