ALEXANDRIA, Va. – NCUA downgraded a fraud warning issued last week on a CD mailed to a credit union, saying the CD was actually mailed by the credit union to itself as part of an internal "system penetration" test.
As part of the test, a credit union created a facsimile of an NCUA Fraud Alert. This was an unauthorized and improper use of the NCUA logo, and also included a falsified signature of then-Chairman Michael Fryzel, NCUA said Friday.
The bogus alert was forwarded to NCUA, prompting the issuance of the August 25 Fraud Alert. The false Fraud Alert appears to be confined to that credit union, and is not wide-spread.
Credit unions are not authorized to create facsimile documents bearing NCUA logos or signatures, or to improperly represent communications from NCUA, even during the legitimate conduct of business such as a computer security assessment.
Earlier in the week NCUA issued a Fraud Warning based on the case which prompted widespread reporting of a Trojan or some other kind of malware being sent to credit unions.
NCUA said it takes any type of security breach seriously. "We also place a high priority on making federally insured credit unions aware of any illegal, fraudulent or deceptive activities that are frequently aimed at financial institutions."










