Scammers Resort To Low-Tech 'Vishing' Attack On Two CUs

BEAVERTON, Ore. - Members of two credit unions on opposite ends of the continent have been receiving automated calls with a similar pitch-access to their accounts has expired and they must call a toll-free number to "reactivate."

Processing Content

The problem: the phone calls came from scammers, not their CUs.

The use of telephone calls seeking personal or account information is known as "vishing," and is a close relative of "phishing" scams that rely on e-mail and/or websites. As consumers have become more sophisticated users of the online space, identity thieves increasingly have turned to auto-dialers and authoritative-sounding announcements.

In the case of First Technology CU and Northeast CU, Porsmouth, N.H., the damage was limited. A spokesperson for First Tech said no member credit cards were compromised; while the CEO of Northeast CU reported only two transactions were processed for a total of less than $1,000. Both credited member education efforts and prompt action by their respective staffs for limiting exposure.

Deborah Colby, vice president of marketing and business development for First Tech, told the Credit Union Journal the Beaverton police department had received complaints on Aug. 19 after members in the area received calls. The CU's phone center is not open on Sundays, so management did not learn of the scam until the morning of Aug. 20.

According to Colby, the calls targeted ZIP codes near First Tech branches, not a list of members. She was aware of at least two versions of the pitch. The recorded announcement said to "continue functionality," credit card data must be updated. If someone answered the call, a live person came on the line and attempted to gather information. If voice mail or an answering machine was reached, a message was left telling people to call a toll-free number.

"We had enough calls in a short period of time to know we had a problem," Colby said. "We posted information on our website and sent e-mails to all members we had addresses for. Within that morning we had contact with the local police department. As events unfolded throughout the day we could see it was a vishing attack, not a data breach."

Within the first day, First Tech isolated the telephone number and took steps to have it shut down, she said. The next day, individuals in nearby Lane County received similar phone calls using another credit union's name.

"It was a busy couple of days, but no member accounts were compromised," said Colby. "We had 33 members release their information, but we were able to shut down their accounts before anything happened. At this point, we have no information that would lead us to believe any fraud has taken place on any of those accounts."

First Tech has heard from approximately 325 members who were contacted in this scam. Colby said the CU heard from non-members, as well, because its name was used in the voice mail. "We are not a community credit union, so they wanted to know why we were calling them."

Criminals will try anything to get through to people, Colby said.

"They are fishing for information to see who is going to fall for it. The best thing we can do for our members is educate them about scammers. Because we can shut one down one day, but the next day there will be something else. Education is the key to helping protect their identity. As much as you don't want your credit union's name tied to something like this, I'm glad the media covered it because the more coverage there is, the less these guys have the opportunity to scam people." (c) 2007 The Credit Union Journal and SourceMedia, Inc. All Rights Reserved. http://www.cujournal.com http://www.sourcemedia.com


For reprint and licensing requests for this article, click here.
MORE FROM AMERICAN BANKER
Load More