Account Takeover | Phishing & Spoofing | United Community Bank
FDIC-Insured - Backed by the full faith and credit of the U.S. Government
All UCB locations will be closed Monday, Sept. 7, in observance of Labor Day. ITMs will be available for your convenience.

Customer Awareness

Personal Banking Login

Business Banking Login

Open Account

Customer Awareness

CORPORATE ACCOUNT TAKEOVER
At United Community Bank we are committed to your security and want to make you aware of an evolving electronic crime.

What is Corporate Account Takeover?

Corporate account takeover is a type of fraud where thieves gain access to a business’ finances to make unauthorized transactions, including transferring funds from the company, creating and adding new fake employees to payroll, and stealing sensitive customer information that may not be recoverable. Corporate account takeover is a growing threat for small businesses. It is important that businesses understand and prepare for this risk.

Cyber thieves target employees through phishing, phone calls, text messages, and even social networks. It is common for thieves to send emails posing as a bank, delivery company, court or the Better Business Bureau. Once the email is opened, malware is loaded on the computer which then records credentials and passcodes and reports them back to the criminals.

Fraudsters are increasingly contacting businesses while posing as the Bank's Fraud Department to obtain sensitive information. These criminals may use caller ID spoofing to make their calls appear to originate from the Bank.

Scammers are also sending text messages containing links to fraudulent Bank login websites designed to steal online banking credentials. These scams do not require victims to download malicious software to their devices; simply clicking the link and entering login information can expose sensitive account credentials.

How does Corporate Account Takeover Work?

  • Criminals target victims by scams.
  • The victim unknowingly divulges confidential information to the fraudsters including but not limited to login credentials, authorization codes, account numbers, or account history.
  • The victim is tricked into attempting to log in to a fraudulent bank login site, where the fraudster captures the credentials entered.
  • The victim is tricked into accepting fraud alerts without reviewing them or questioning why they were sent.
  • Victim unknowingly installs software by clicking on a link that can programmatically record activity to obtain personal information.
  • Fraudsters use harvested credentials, compromised information, or infected systems to access the victim's account and conduct financial fraud.

Where does it come from?

  • Malicious websites, including Social Networking sites.
  • Email
  • Phone Calls
  • Text Messages
  • P2P Downloads (e.g. LimeWire)
  • Ads from popular websites

What can a Business do to PROTECT?

  • Provide security awareness training to employees
  • Secure your computers, networks, and mobile devices
  • Limit administrative rights (Do not allow employees to install any software without receiving prior approval).
  • Install and maintain spam filters
  • Surf the internet carefully
  • Install and maintain up-to-date commercial anti-virus and desktop firewall software on all computer systems and applicable mobile devices.
  • Utilize routine and "red-flag" reporting for transaction activity.
  • Install routers and firewalls to prevent unauthorized access to your computer or network. Change the default passwords on all network devices.
  • Install security updates to operating systems and all applications as they become available.
  • Use the latest versions of browsers such as Microsoft Edge, Firefox or Google Chrome with pop-up blockers enabled.
  • Do not open attachments from e-mail. Be on the alert for suspicious emails.
  • Do not click on links in text messages/ Be on the alert for suspicious messages.
  • Do not provide confidential information over the phone unless you have independently verified who you are speaking with and why the information is required. Be on the alert for suspicious phone calls that claim to be from the Bank.
  • Never access Bank Accounts at Internet Cafes or from public wi-fi hotspots (airports, etc.)
  • Use a dedicated computer for financial transaction activity.
  • Initiate ACH and wire transfer payment under dual control (E.g. One person authorizes the creation of the payment file, and the second authorizes the release of the file)
  • Reconcile accounts daily
  • Note any changes in the performance of your computer like dramatic loss of speed, computer lock up, unexpected rebooting, unusual popups, etc.
  • Make sure that employees know how to and whom to report suspicious activity to at your Company and the Bank.
  • Sign up for Positive Pay, a service offered to businesses at no additional cost.

Contact the Bank immediately at 866.505.3736 if you:

  • Suspect a Fraudulent Transaction.
  • If you are trying to process an Online Wire or ACH Batch and you receive a maintenance page.
  • If you receive an email, phone call or text message claiming to be from United Community Bank and it is requesting personal/company information.

PHISHING AND SPOOFING

As part of our commitment to protecting your account and personal information, we’ve assembled the following tips to help you identify fraudulent emails, text messages, and phone calls.

  • Links that appear to be from United Community Bank but aren’t. If you receive a suspicious email, place your cursor over any links to preview the destination URL. Do not click the link. Review the URL carefully. For example, a URL formatted as ucbanking.fakewebsite.com leads to a fake website. The presence of “ucbanking” in a URL does not mean the site is an official United Community Bank website.
  • Requests for personal information. United Community Bank will never ask you to reply to an email with confidential personal information, such as your Social Security number, ATM card number, PIN, or other sensitive account information.
  • Urgent appeals. We will never threaten to close or restrict your account if you fail to confirm, verify, or authenticate your personal information through an email.
  • Messages about system or security updates. We will never ask you to confirm sensitive information by email because of a system upgrade, security update, or other technical changes.
  • Offers that sound too good to be true. Be cautious of messages offering money or other incentives in exchange for completing a customer service survey and then requesting your account or personal information.
  • Obvious typos and other errors. Fraudulent emails and websites often contain spelling or grammatical errors, awkward wording, unusual formatting, or poor visual design. These can be warning signs that a message or website is not legitimate.
  • Fraudulent phone calls. United Community Bank will not call you and ask for confidential account or personal information. Fraudsters can spoof Caller ID to make a call appear to come from United Community Bank, even when it does not.

If You Receive a Suspicious Message

If you receive a suspicious email or text message that uses United Community Bank’s name or branding, do not click any links, open attachments, or provide personal information. Forward the message to us immediately at onlinesupport@ucbanking.com.

Secure Email

To help protect the confidentiality of your private information, United Community Bank uses Microsoft Purview Message Encryption to secure email communications containing sensitive information.

This service helps protect information such as Social Security numbers, driver’s license numbers, account numbers, and other confidential information. Please do not send sensitive information to United Community Bank through unencrypted email.

How Encrypted Email Works

When an email contains sensitive information, the message will be encrypted. You may receive an email notification with instructions to “Read the message” to access the secure email.

When prompted, you may sign in using your existing Microsoft account. If you do not have a Microsoft account, you may need to create one. Depending on your email provider, you may also be able to authenticate using your existing Google or Yahoo account.

You may also receive a one-time passcode by email to verify your identity and access the encrypted message.

Once you have successfully accessed the encrypted email, you can reply directly to the message. Your response will also be encrypted, helping ensure that any sensitive information you provide is transmitted securely.

If you are a Microsoft 365 customer, encrypted messages between your organization and United Community Bank may be delivered securely and appear in your inbox like a standard email. No additional steps may be required to access the message.

If You Receive an Unexpected Notification

If you receive an encrypted email notification from United Community Bank that you were not expecting, please contact us before clicking any links, buttons, or attachments in the message.

Our goal is to make communicating sensitive information with United Community Bank as secure and convenient as possible.