Banking Security & Fraud
Learn how to protect yourself against cyber threats and fraud attempts.
The security of your information and the reliability of your online transactions are a top priority.
In response to growing threats, banks have implemented robust security systems. Behind every transaction, payment and login, sophisticated security measures are working behind the scenes to help reduce fraud.
While these tools provide strong levels of protection, adopting safe online habits remains essential. With a few simple precautions, it is easy to protect your personal data online without complicating your daily life.
On this page, you will find key security practices, useful tips and protective measures to help safeguard your information and enjoy greater peace of mind!
The Most Common Threats
How can I tell if I have received a fraudulent email?
Fraudsters often send emails impersonating the Bank to a large number of internet users.
These emails contain false information, often designed to create a sense of urgency, encouraging recipients to click on a link included in the message. These so-called "phishing emails" are intended to steal your personal information or gain access to online banking services.
Fraudsters may pretend to be a company, a bank, an online retailer or even someone you know. They send emails directing you to a fake website designed to mislead you.
The fake website then asks you to enter your login credentials. This is known as phishing, a fraudulent practice that allows criminals to collect your credentials and use them later to access your accounts unlawfully.
Please note that your Bank will never contact you directly via your personal email address to request your bank card number, customer ID or password.
How can I protect myself from phishing?
To protect yourself from phishing, follow these basic rules:
- Only send messages to people you know (such as friends and family) or to verified contacts.
- Use an anti-spam filter for your email account.
- Make sure your have an antivirus software installed and regularly updated.
- Remain vigilant about every email you receive, even those coming from trusted contacts. An infected device can use its owner's address book to send viruses without their knowledge.
- Never disclose personal information (such as your online banking password or account details) by any means, especially by email.
What should I do if I have responded to a phishing email?
If you clicked on the link and entered your login credentials, we recommend that you:
- Contact your Advisor to change your password. Blocking your bank card may also be necessary.
- Install a security software such as Trusteer Rapport.
- Check that your antivirus software and computer are up to date.
- Run a full antivirus scan.
Malicious Emails: Best Practices
Malicious email campaigns are common. These emails often contain attachments with file names such as "name.doc", "name.xls" or "name.lnk". Other types of malicious files may also be used.
Opening these attachments can infect your computer with banking malware. Once installed, this malware may capture your usernames and passwords for banking websites, email accounts and social media platforms. Such malware is often difficult, or even impossible, for antivirus software to detect.
To encourage recipients to open these attachments, fraudsters often use urgent subject lines such as "Unpaid Invoices", "Invoice for the Month of..." or "VAT Declaration".
To avoid compromising your computer:
- Install security software such as IBM Trusteer Rapport, which can help protect you against banking malware and phishing websites.
- When you receive an email, verify that you know the sender and carefully review the subject line and content.
- Do not click on links or open attachments hastily.
- If in doubt, delete the email.
- Regularly check that your computer and antivirus software are up to date.
- Perform full system scans regularly using your antivirus software and, ideally, anti-malware software.
- Monitor account activity and transfers regularly.
If your computer has been infected:
- Contact your Bank immediately to reset your password.
- Clean and disinfect your device before changing all your passwords (banking accounts, email accounts, etc.).
How to clean your device:
- Factory reset your computer. This is the most effective solution, as it restores your computer to its original settings. Be sure to back up your personal data (photos, videos, important documents, etc.) beforehand.
- Perform a full scan using an up-to-date antivirus solution.
- Perform a full scan using up-to-date anti-malware software.
What is a money mule?
Imagine someone offers you an easy way to make money. They ask you to receive funds into your bank account and then transfer the money to another person. It may seem simple and risk-free.
In reality, the money often comes from fraud or theft. The individual contacting you is a criminal attempting to conceal the source of the funds by using your account. By participating, you become a "money mule" and an intermediary in an illegal activity.
How do fraudsters recruit money mules?
They often target people seeking additional income, such as students or job seekers. Fraudsters may contact you through social media, private messages or fake job advertisements promising easy earnings. They may also claim to be a friend or relative in need of assistance and ask for what appears to be a harmless favour.
What are the risks?
Even if you are unaware of the fraudulent nature of the transaction, you may face legal consequences for aiding criminal activity.
Potential consequences include the closure of your bank account, difficulties obtaining credit in the future and, in some cases, criminal penalties, including imprisonment.
How can you avoid the trap?
- Never allow anyone to use your bank account to transfer money.
- Be cautious of job offers that seem too good to be true or promise quick financial rewards.
- Never share your banking information with strangers.
- If you have any doubts, seek advice from a professional or report the situation to the relevant authorities.
Remember: easy money is often a trap!
How can I shop online safely?
To help prevent the fraudulent use of bank cards online, the Bank provides a payment authentication system supported by VISA.
Through the Verified by VISA programme, the security of your online payments is enhanced. This service is completely free of charge.
When making a payment on a merchant website that uses Verified by VISA, you will be asked to enter your usual payment details as well as your 3D Secure password, which helps confirm that the legitimate cardholder is making the transaction.
Merchants participating in the programme can be identified by the Verified by VISA logo displayed on their website.
Lost password / 3D Secure payment blocked
If you enter an incorrect code three times, your card will be blocked on websites using the Verified by VISA service.
In this case, please contact your Advisor or Customer Service (or use the Contact section of this website).
You can continue to use your bank card with retailers and at ATMs.
What is vishing?
Vishing (voice phishing) is a fraud technique that involves impersonating trusted organisations, including your bank, by spoofing their identity and/or phone number. The objective is to obtain your personal or banking information or persuade you to perform an action, such as validating or cancelling a transaction.
How should I respond to a vishing attempt?
These simple precautions can help protect you:
- Do not be pressured by a sense of urgency. This is a warning sign.
- Any security code received by SMS can only be used to validate a transaction, never to cancel or block one.
- Never disclose your PINs, bank card details, usernames or passwords. Hang up immediately.
- Do not hand over your bank card. Your Bank will NEVER send a courier to collect your bank card for any reason.
- More generally, never perform any action (cancel, block, validate or confirm a transaction) at the instruction of a third party.
IMPORTANT
Your Bank will never ask you, by email, SMS or telephone, regardless of the circumstances or level of urgency, to provide:
- Your bank card PIN or card details (card number, expiry date or security code).
- Your bank account number.
- A security code received by SMS (3D Secure code).
- Your online banking customer ID and/or password.
Configuration and Security
Using the internet to manage your accounts and transactions requires a basic understanding of online security.
Which browser should I use on my computer?
You can access the Bank’s website using most modern internet browsers. If you experience technical issues while using our website, we recommend installing the latest version of your browser.
Updating Your Microsoft Browser
New security vulnerabilities are discovered every day. Fraudsters and malware exploit these weaknesses to gain access to vulnerable systems. If your browser is not up to date, your computer, personal information and banking data may be at risk.
This affects not only your access to our website, but also your email accounts, social media accounts, online shopping data, and more.
To avoid vulnerabilities that could compromise the security of your computer and digital information, we strongly recommend updating your browser as soon as possible.
Regardless of the browser you use, you should always install and apply updates for your software and operating system.
How can I protect my Client Area?
- Change your password regularly.
Every six months, or immediately if you believe someone else may know your credentials. - Review your transactions and account activity frequently.
- Never share your customer ID with anyone.
- Only log in from secure computers.
Avoid accessing your online banking or shopping websites from public computers (such as internet cafés or self-service terminals). - Sign out after each session by closing your browser.
The "Log Out" button allows you to disconnect immediately and securely from your Client Area, without waiting for the automatic timeout after several minutes of inactivity.
This helps prevent any unauthorised access to your accounts from someone using your computer.
What are the key security recommendations?
1) Create a strong password
It is essential to choose a strong password that is difficult for others to guess or discover. Avoid using personal information such as your date of birth.
When accessing your accounts, you should enter your confidential code only through the virtual keyboard provided.
2) Protect your browser with security software
The antivirus or security software you currently use is important, but it is often not enough on its own.
Various studies and recent incidents have shown that traditional security tools are not always effective in preventing fraudsters from gaining access to online accounts. As cyberattacks become increasingly sophisticated, we strongly recommend adding extra layers of protection to your computer when using online banking services.
Security software helps protect your connection to your bank's online platform. It can block fraud attempts targeting your account and provides additional protection alongside your firewall, antivirus software and other security tools already installed on your device.
3) Be cautious with unknown emails
One of the most effective ways to spread malware is through email attachments.
To protect yourself, never open attachments sent by unknown or untrusted senders.
4) Keep your operating system and software up to date
We recommend regularly checking that all your software is updated, including:
- Your operating system (e.g. Windows, macOS)
- Your internet browser
- Your antivirus software
- Your firewall
- Your anti-spyware software
Passwords: Best Practices
- Always use different passwords for different systems and services. In particular, the password for your Client Area should be different from the password for your email account.
- Change your passwords regularly, at least once or twice a year.
- Choose passwords that are not linked to your identity (name, surname, company name, date of birth, etc.).
- Never store your passwords in Word or Excel files, as these can easily be compromised if your computer is hacked. Avoid writing them down on easily accessible paper. Use a password manager instead.
- Never send passwords to your personal email account, as they can easily be intercepted.
- Configure your applications, including your web browser, so that they do not save or remember your passwords.
Personal Information Theft Attempts: How to Respond and Protect Yourself?
You may receive an unsolicited email requesting personal information, often under the pretext of security checks, account restrictions or changes to your login credentials.
Typically, either:
- The email contains a link to a fake online banking website, a fake telecom provider website or a fake social benefits website.
- The email includes an attachment that you are asked to complete, such as "Questionnaire.html" or "Bank-Verification.html".
Warning: In both cases, these are attempts to steal your personal information and impersonate your identity.
The Bank will never send this type of message. Such emails should be forwarded to Customer Service and then deleted.
If you have responded to such an email, change your passwords immediately.
IMPORTANT
Your Bank will never ask you to provide or enter the following information by email, SMS or telephone, regardless of the reason given or the level of urgency:
- Your bank card PIN or card details (card number, expiry date and security code).
- Your bank account number.
- A security code received by SMS (3D Secure code).
- Your online banking customer ID and/or confidential access code