LAS VEGAS -
In fact, members seem to have only one sure defense against phishing: become a phishing victim, according to Christie Jordan, financial operations manager at $637-million Clark County Credit Union here.
"In general, consumers only care about fraud when they've been affected by it," Jordan said. "Then they're more cautious. Otherwise it's easy to get someone click on a phishing link in an e-mail."
And click they do. "The old trick is still working on members, and, in fact, it is working with credit union employees as well," said Brian Warfel, svp-sales and service at $475-million Power Financial CU in Pembroke Pines, Fla., and chair of the CUNA Technology Council executive committee.
"One of the security audits that we do at Power Financial is to send an e-mail to employees asking them for their login credentials," Warfel explained. "The e-mail comes from a fictitious address and the webpage they are taken to is fictitious as well. The point is to see how many employees will supply their information simply because a 'trusted source' asks for it."
Neither Warfel nor Jordan could provide the percentage of members and employees who submit to spoofed e-mails or an indication of how many phishing attacks lead to actual fraud at their respective CUs.
However, if you look at the increasing volume of attacks against financial institutions over the past few years, as measured by security firms such as RSA and SecureWorks, as well as resultant card data breaches, it seems that phishing must still be a worthwhile endeavor.
Certainly, phishers haven't found the need to improve their tactics; they still send the same spoofed e-mails, marked by slipshod syntax and doltish design, that tell members their accounts will be under review or suspended until they log-in via what turns out to be a fraudulent link.
"Many consumers still ignore the warnings from their security software so they can surf at will," Warfel said. "We can create all of the security programs we want to, but convenience and time often win out over security."
The industry still stands by end-user training as the antidote to phishing. "Overall, I am not certain we have invested enough in member education," added Tripp Johnson, a senior director at Scottsdale, Ariz.-based Cornerstone Advisors.
"The best tactic is member education," Warfel agreed.
Members should certainly know not to click on e-mail links, but they should also be warned to apply security patches and software updates to their personal computers, Warfel said.
Jordan hopes that tomorrow's online members will be savvier. "Maybe the next generation will have a better understanding of what is and isn't' appropriate with web-based activity."
Meanwhile, there's nothing like some fraudulent big-ticket charges to your account to make you a believer, Jordan continued.
"Education is important, but I think once you've been affected, you become more cognizant," she said. "Once they've had fraud, our members become more actively engaged in their accounts. They don't wait for their monthly statements-they continually call and check online banking."
Jordan estimated that at least 60% of the credit union's fraud victims continually monitor their accounts after they've been hit. "A successful attack makes the vigilance stick."
more
Read more about marketing tools at cujournal.com and search the following terms in the archive:
Naked On The Net
Multi-Factor Fallout
Multi-Factor Authentication
For Info On The Story:
* www.ccculv.org
* www.powerfi.org
* www.cunatechnologycouncil.org
* www.crnrstone.com











