Happy Credit Union Customers Become the Target of Spoofing Scams Due to a Lack of Email Security

Stu Sjouwerman | May 12, 2022

Happy Credit Union Customers Become the Target of Spoofing Scams Due to a Lack of Email SecurityTaking advantage of heightened levels of customer trust and satisfaction, along with lowered levels of properly implemented security, credit unions are seeing a rise in email-based scams.

An uptick in phishing campaigns targeting credit union customers intent on harvesting credentials and taking victims for their money has been identified by security researchers at Avanan. The attack spoofs the credit union, attempting to get the victim to access the [fake] credit union website, provide their credentials, and take care of some banking activity the phishing email claims needs to be addressed.

According to Avanan, there are a few factors that aid in the success of this kind of attack:

  • 66% of credit unions lack controls like DMARC to avoid spoofing
  • 92% of them don’t have proper email security in place
  • A majority of credit union customers are happy with, and trust, their credit union

Add all this up and you have scammers lining up to impersonate credit unions, and customers who naturally assume emails claiming that something’s wrong with their account are going to take the prescribed (albeit, malicious) actions.

This alignment of insecurity and ignorance creates the perfect storm for these kinds of scams to thrive. And while you can’t control whether your credit union does or does not have proper security controls in place, you can educate your own users so they don’t become victims while on a company endpoint by enrolling them in Security Awareness Training so they don’t err on the side of simply believing an email is from their credit union… just because it says so.

Topics: Phishing

Access the World’s Largest Security Awareness Library

Explore over 1,000 interactive modules, videos, and games designed to sharpen user instincts and secure AI interactions. Get instant access to our Free Training Preview and find the perfect content to fortify your security culture.

Get Your Free Training Preview

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.