DES MOINES, Iowa–As credit unions have turned to social media, crooks have followed—including finding ways to scam members in fewer than 140 characters.
“Fraudsters are now monitoring Twitter and other social networks for customer service complaints,” explained Ashley McAlpine, fraud prevention manager with CO-OP Financial Services.
The crooks then reply to those complaints via direct message using a spoofed account that looks legitimate, like they are a representative of the company, she said.
“For example, I am on Twitter and I had a bad credit union experience. I say, ‘The ATMs at XYZ Credit Union stink.’ I put that on my Twitter account, that tag is out there, and fraudsters see that and respond to it,” said McAlpine.
Crooks often ask the consumer to call them at a specific number and then trick them into revealing more of their personal information during the call. Or, they can send a link that contains a malware attachment, explained McAlpine.
New Approach
McAlpine said this type of fraud attack has been occurring recently, but mostly against retail companies since credit unions have yet to begin seriously using social media as a means to deliver service responses.
“But credit unions are moving into this channel for service, and they need to be careful,” said McAlpine. “Credit unions using social media in this manner must be very active in monitoring what is taking place on their social media sites. They need to check for Twitter handles that are coming through, and then also educate members.”
McAlpine said that not only should credit unions explain this fraud tactic to members, but also note on their websites the type of information they will and will not ask for over social media, or on any other contact channel.
“For example, tell members that you will never ask for their PINs. Let them know the phone numbers you will use to contact them,” said McAlpine.
The focus on Twitter and other social media channels is part of fraudsters’ efforts to build complete consumer profiles, said McAlpine.
“Big Data is a buzzword among credit unions. Well, crooks are using Big Data too. They are building their own massive databases, getting information from breaches like Yahoo and Anthem,” said McAlpine.
Account Takeover
Analysts have stated that thieves are focusing less on stealing payment data in favor of account takeover as EMV makes it more difficult to steal card information.
As other experts have told CUToday.info, McAlpine recommended that to prevent against account takeover that CUs use other means of member authentication than data that can be easily stolen. She recommended biometrics, and if challenge questions are used, use out-of-wallet questions.
