Main

CYBERSECURITY AND BEST PRACTICES

Plaquemine Bank and Trust Company is required to notify our customers at least annually of the following information. This information may be printed and retained for your reference. Here are a few website we encourage our customers to review:

Federal Trade Commission website is a central location for you to report fraud, identity theft, other free resources and get Consumer Alerts. https://www.ftc.gov

Federal Trade Commission “On Guard Online” is tips to help you stay safe and secure online. https://www.consumer.ftc.gov/features/feature-0038-onguardonline

Federal Trade Commission’s “Identity Theft” website will assist you in reporting Identity Theft. Please refer to the Federal Trade Commission's website.

Federal Trade Commission “Consumer Information” will provide information and best practices related to Computer and Mobile security. Please refer to the Federal Trade Commission's website.

FBI’s Scams and Safety is information on common scams, protecting your children online, as well as other information to help you not become a victim of crime and fraud: https://www.fbi.gov/scams-and-safety

ONLINE BANKING AND FRAUD PREVENTION BEST PRACTICES

User ID and Password Guidelines:

  • Create a "strong" password with at least 10 characters that includes a combination of mixed case letters and numbers and special characters.

  • Change your password frequently.

  • Never share username and password information with third-party providers.

  • Avoid using an automatic login feature that saves usernames and passwords.

General Guidelines:

  • Do not use public or other unsecured computers for logging into Online Banking.

  • Check your last login date/time every time you log in.

  • Review account balances and detail transactions regularly (preferably daily) to confirm payment and other transaction data and immediately report any suspicious transactions to your financial institution.

  • View transfer history available through viewing account activity information.

  • Whenever possible, use Bill Pay instead of checks to limit account number dissemination exposure and to obtain better electronic record keeping.

  • Take advantage of and regularly view system alerts; examples may include:

  • Do not use account numbers, your social security number, or other account or personal information when creating account nicknames or other titles.

  • Whenever possible, register your computer to avoid having to re-enter challenge questions and another authentication information with each login.

  • Review historical reporting features of your online banking application on a regular basis to confirm payment and other transaction data.

  • Never leave a computer unattended while using Online Banking.

  • Never conduct banking transactions while multiple browsers are open on your computer.

Tips to Protect Online Payments & Account Data:

  • Take advantage of transaction limits.

  • When you have completed a transaction, ensure you log off to close the connection with the financial organization’s computer.

  • Use separate accounts for electronic and paper transactions to simplify monitoring and tracking any discrepancies.

  • Reconcile by carefully monitoring account activity and reviewing all transactions initiated by your company daily. Account Transfer

  • Use limits provided for monetary transactions

  • Review historical and audit reports regularly to confirm transaction activity.

  • Utilize available alerts for funds transfer activity.

Account Transfer:

  • Use limits provided for monetary transactions

  • Review historical and audit reports regularly to confirm transaction activity.

  • Utilize available alerts for funds transfer activity.

Tips to Avoid Phishing, Spyware and Malware:Do not open e-mail from unknown sources. Be suspicious of e-mails purporting to be from a financial institution, government department, or other agency requesting account information, account verification, or banking access credentials such as usernames, passwords, PIN codes, and similar information. Opening file attachments or clicking on web links in suspicious e-mails could expose your system to malicious code that could hijack your computer.

  • Never respond to a suspicious e-mail or click on any hyperlink embedded in a suspicious e-mail. Call the purported source if you are unsure who sent an e-mail.

  • If an e–mail claiming to be from your financial organization seems suspicious, checking with your financial organization may be appropriate.

  • Install anti-virus and spyware detection software on all computer systems. Free software may not provide protection against the latest threats compared with an industry standard product.

  • Update all your computers regularly with the latest versions and patches of both anti-virus and anti-spyware software.

  • Ensure computers are patched regularly, particularly operating system and key application with security patches.

  • Install a dedicated, actively managed firewall, especially if using a broadband or dedicated connection to the Internet, such as DSL or cable. A firewall limits the potential for unauthorized access to your network and computers.

  • Check your settings and select, at least, a medium level of security for your browsers.

  • Clear the browser cache before starting an online banking session to eliminate copies of Web pages that have been stored on the hard drive. How the cache is cleared depends on the browser and version you are using. This function is generally found in the browser’s preferences menu.

Tips for Wireless Network Management: Wireless networks can provide an unintended open door to your business network. Unless a valid business reason exists for wireless network use, it is recommended that all wireless networks be disabled. If a wireless network is to be used for legitimate business purposes, it is recommended that wireless networks be secured as follows:

  • Change the wireless network hardware (router /access point) administrative password from the factory default to a complex password. Save the password in a secure location as it will be needed to make future changes to the device.

  • Disable remote administration of the wireless network hardware (router / access point).

  • If possible, disable broadcasting the network SSID.

  • If your device offers WPA encryption, secure your wireless network by enabling WPA encryption of the wireless network. If your device does not support WPA encryption, enable WEP encryption.

If only known computers will access the wireless network, consider enabling MAC filtering on the network hardware. Every computer network card is assigned a unique MAC address. MAC filtering will only allow computers with permitted MAC addresses access.

CORPORATE ACCOUNT TAKEOVER

What is Corporate Account Takeover? Corporate account takeover is a type of fraud where thieves gain access to a business’ finances to make unauthorized transactions, including transferring funds from the company, creating, and adding new fake employees to payroll, and stealing sensitive customer information that may not be recoverable. Corporate account takeover is a growing threat for small businesses. It is important that businesses understand and prepare for this risk.

Cyber thieves target employees through phishing, phone calls, and even social networks. It is common for thieves to send emails posing as a bank, delivery company, court or the Better Business Bureau. Once the email is opened, malware is loaded on the computer which then records login credentials and pass codes and reports them back to the criminals.

Employee Education is Essential but is Missing the Mark: You and your employees are the first line of defense against corporate account takeover. A strong security program paired with employee education about the warning signs, safe practices, and responses to a suspected takeover are essential to protecting your company and customers. Respondents to a recent survey indicated employee education of small business employees was effective in reducing the threat of account takeover. However, nearly all of respondents to a small business survey said they had no formal internet security policy, with almost half indicating they provide no internet safety training to employees.

How do I protect myself and my small business? The best way to protect against corporate account takeover is a strong partnership with your financial institution. Work with your bank to understand security measures needed within the business and to establish safeguards on the accounts that can help the bank identify and prevent unauthorized access to your funds.

A shared responsibility between the bank and the business is the most effective way to prevent corporate account takeover. Consider these tips to ensure your business is well prepared:

  • Protect your online environment. It is important to protect your cyber environment just as you would your cash and physical location. Do not use unprotected internet connections. Encrypt sensitive data and keep updated virus protections on your computer. Use complex passwords and change them periodically. Educate and Train your employees

  • Partner with your bank to prevent unauthorized transactions. Talk to your banker about programs that safeguard you from unauthorized transactions. Positive Pay and other services offer call backs, device authentication, multi-person approval processes and batch limits help protect you from fraud.

  • Pay attention to suspicious activity and react quickly. Look out for unexplained account or network activity, pop ups, and suspicious emails. If detected, immediately contact your financial institution, stop all online activity and remove any systems that may have been compromised. Keep records of what happened.

  • Understand your responsibilities and liabilities. The account agreement with your bank will detail what commercially reasonable security measures are required in your business. It is critical that you understand and implement the security safeguards in the agreement. If you don’t, you could be liable for losses resulting from a takeover. Talk to your banker if you have any questions about your responsibilities.

  Additional Measures You Should Take:

  • Secure your computer and networks

  • Limit Administrative Rights–Do not allow employees to install any software without receiving prior approval.

  • Install and Maintain Spam Filters

  • Surf the Internet carefully

  • Install and maintain real-time anti-virus, anti-spyware, desktop firewall, malware detection and removal software. Use these tools regularly to scan your computer. Allow for automatic updates and scheduled scans.

  • Install routers and firewalls to prevent unauthorized access to your computer or network. Change the default passwords on all network devices.

  • Install security updates to operating systems and all applications as they become available.

  • Do not open attachments from e-mail. Be on the alert for suspicious emails.

  • Do not use public Internet access points

  • Reconcile Accounts Daily

  • Note any changes in the performance of your computer

  • Dramatic loss of speed, computer locks up, unexpected rebooting, unusual popups, etc.

  • Make sure that your employees know how and to whom to report suspicious activity to at your Company & the Bank 

ATM AND DEBIT CARD SECURITY

Making ATM Security your business: Electronic banking at ATM's is a fast, convenient way to withdraw cash, make deposits, check account balances, transfer funds and more. If you use ATM's to conduct financial transactions, you must make security a priority. Here are some important steps you can take to make ATM security your business.

Treat your ATM card like cash: Always keep your card in a safe place. It is a good idea to store your card in a card sleeve. The sleeve protects the card's magnetic stripe.

Keep your "secret code; PIN” a secret: Your ATM card will work only with your personal identification number (PIN). When choosing your PIN, do not use dates of birth, parts of your social security number, addresses or phone numbers. Memorize your code. Never write it on your card or store it with the card. Never tell your code to anyone. And never let someone else enter your code for you. NEVER write your PIN on anything!

Take your receipt with you. Do not leave it at or near the ATM: You can get a receipt every time you make an ATM transaction. Verify each transaction by checking the receipts against your monthly account statements to guard against ATM fraud.

Do not give out any information about your ATM card over the telephone: No one needs to know your secret code. Not even your financial institution.

Report a lost or stolen card at once: Promptly report a lost or stolen card to reduce the chance that it will be used improperly. You will be issued another card.

Here are 10 ways a criminal could potentially gain access to your ATM or Debit Card:

  • Steal cards: The simplest way for a criminal to get card data is to steal someone’s card. To get the PIN, the thief might shoulder surf or guess a weak password, such as a birth date.

  • Steal machines: A criminal might decide to steal either an ATM or Point of Sale terminal. Cash can be pulled from the ATM's, but both types of machines could store card numbers if misconfigured. A stolen machine is also valuable to learn about weaknesses or ways to physically attack it.

  • Offline account takeover: Breaking into mailboxes and stealing bank statements or other personal information can let a criminal conduct identity theft. Often, they will try to change the victim’s mailing address with the bank, order a new card, and activate it. If the bank has good processes in place that are adhered to, then this type of attack can be stopped.

  • Separate skimming device: If a deft criminal can get a hold of a card for a few seconds, then they can swipe it through a reader and get its data.

  • Overlaid skimming devices: In this case, the criminal places a card reader over the machine’s intrinsic reader. They might also attach a video camera or a pin–pad overlay to capture the PIN.

  • Internal skimming devices: More capable criminals could place a skimming device inside a terminal, such as at a gas pump. The skimmer intercepts messages on the data lines and is tough to detect without opening machines.

  • Hijacked terminals: A terminal can be hijacked by replacing the operating system with a compromised one. An avenue of attack might be available for those ATM's with remote control capabilities that are left in the default (and insecure) settings. Stolen machines might also be modified and then used to replace an existing, non–compromised terminal.

  • Ghost ATM's and fake fronts: Why add a skimming device to a real terminal when you can just use your own fake one? Criminals have been known to place fake, modified terminals in public spaces where victims will use their cards but receive communication error messages. The terminal has captured card data and PIN and stored it for later retrieval.

  • Buying the data: With so many means of attack, there is a glut of card information on the market. Lazy criminals can simply buy card data, starting at $1 or less. Quality costs extra, but in the underground marketplace there are products for everyone.

  • Data breaches: Capable hackers can crack the security on merchants and other card data holders, and access large volumes of card data. With the heightened awareness of cybercrime, the industry has made strides in using more secure techniques for storing data (or in many cases, ensuring that they do not store it). This has made it harder for criminals, but there are still many opportunities for attacks.

CUSTOMERS GUIDE TO CYBERSECURITY

Protecting Your Identity: The number of people who have experienced identity theft has risen with the incidence rate increasing every year. Substantial measures are in place at your bank to protect your identity and your accounts against theft and fraud. For example, stringent bank privacy policies protect your personal and financial information.

Password protection for online transactions: Passwords help assure online security. When using our online services, you develop a secret password that only you know. Encryption of online transactions with your bank converts your information into secure code, protecting you against hackers.

Maximum security is possible only with your help. Here is what you can do to stop these crimes before they happen:

  • Do not share personal information over the phone, through the mail, or over the internet unless you initiated the contact or know the person you are dealing with.

  • Be suspicious if someone contacts you unexpectedly online and asks for your personal information. It doesn’t matter how legitimate the e-mail or website may look. Only open e-mails that look like they are from people or organizations you know, and even then, be cautious if they look questionable. Be especially wary of fraudulent e-mails or websites that have typos or other obvious mistakes.

  • Do not give out valuable personal information in response to unsolicited requests. Social Security numbers, financial account information and your driver’s license number are some of the details that should be kept confidential.

  • Shred old receipts, account statements, and unused credit card offers.

  • Choose a PIN and Passwords that would be difficult to guess and avoid using easily identifiable information such as your mother’s maiden name, birth dates, the last four digits of your social security number, or phone numbers.

  • Pay attention to billing cycles and account statements and contact your bank if you do not receive a monthly bill or statement since identity thieves often divert account documentation.

  • Review account statements thoroughly to ensure all transactions are authorized.

  • Guard your mail from theft, promptly remove incoming mail, and do not leave bill payment envelopes in your mailbox with the flag up for pick up by mail carrier.

  • Obtain your free credit report annually and review your credit history to ensure it is accurate.

  • Use an updated security program to protect your computer.

  • Be careful about where and how you conduct financial transactions, for example do not use an unsecured Wi-Fi network because someone might be able to access the information you are transmitting or viewing.

  • Report lost or stolen checks immediately. Your bank will block payment on them.

  • Notify your banker of suspicious phone inquiries such as those asking for account information to “verify a statement” or “award a prize.”

  • Closely guard your ATM Personal Identification Number and ATM receipts.

  • Shred any financial solicitations and bank statements before disposing of them.

  • Put outgoing mail into a secure, official Postal Service collection box.

  • If regular bills fail to reach you, call the company to find out why.

  • f your bills include questionable items, do not ignore them. Instead, investigate immediately to head off any possible fraud.

FACT Act Helps to Fight Identity Theft: The Fair and Accurate Credit Transactions Act (FACT Act) will help reduce identity theft according to Congress and the Federal Trade Commission. For example, one provision requires the three-major credit-reporting agencies to provide consumers with a free copy of their own credit report.

Another provision to help prevent identity theft is the National Fraud Alert System. Consumers who reasonably suspect they have been or may be victimized by identity theft, or who are military personnel on active duty away from home, can place an alert on their credit files. The alert will put potential creditors on notice that they must proceed with caution when granting credit.

Other measures will help consumers recover their credit reputation after they have been victimized:

  • Credit reporting agencies must stop reporting allegedly fraudulent account information when a consumer establishes that he or she has been the victim of identity theft.

  • Creditors or businesses must provide copies of business records or fraudulent accounts or transactions related to them. This information can assist victims in proving that they are, in fact, victims.

  • Consumers will be allowed to report accounts affected by identity theft directly to creditors—in addition to credit reporting agencies—to prevent the spread of erroneous information.

How Not to Get Hooked by a 'Phishing' Scam:Phishing is a high-tech scam that uses spam or pop-up messages to deceive you into disclosing your credit card numbers, bank account information, Social Security number, passwords, or other sensitive information.

According to the Federal Trade Commission (FTC), phishers send an email or pop-up message that claims to be from a business or organization that you deal with - for example, your Internet service provider (ISP), bank, online payment service, or even a government agency. The message usually says that you need to "update" or "validate" your account information. It might threaten some dire consequence if you don't respond. The message directs you to a Web site that looks just like a legitimate organization's site, but it isn't. The purpose of the bogus site? To trick you into divulging your personal information so the operators can steal your identity and run up bills or commit crimes in your name.

The FTC, the nation's consumer protection agency, suggests these tips to help you avoid getting hooked by a phishing scam:

Do not reply or click on a link the message:If you get an email or pop-up message that asks for personal or financial information, do not reply, or click on the link in the message. Legitimate companies do not ask for this information via email. If you are concerned about your account, contact the organization in the email using a telephone number you know to be genuine, or open a new Internet browser session and type in the company's correct Web address. In any case, do not cut and paste the link in the message.

Do not email personal or financial information: Email is not a secure method of transmitting personal information. If you initiate a transaction and want to provide your personal or financial information through an organization's Web site, look for indicators that the site is secure, like a lock icon on the browser's status bar or a URL for a website that begins "https:" (the "s" stands for "secure"). Unfortunately, no indicator is foolproof; some phishers have forged security icons.

Review credit card and bank account statements: As soon as you receive them to determine whether there are any unauthorized charges. If your statement is late by more than a couple of days, call your credit card company or bank to confirm your billing address and account balances.

Check Fraud: A significant number of check fraud losses that occur involve customer accounts. To avoid becoming an unwitting victim of fraud schemes, you need to know about the existence and consequences of fraud, proper check issuing, and timely statement balancing.

Following is a brief list of checking account protection tips:

  • Guard your checkbook and extra (new) checks.

  • Never give your account and routing numbers to people you do not know, especially to anyone over the telephone.

  • Never use your deposit slip for "scrap" paper or notes and then give it to someone. Guard your deposit slips.

  • If your checkbook is lost or stolen, immediately inform us.

  • When traveling for a period, it is wise to leave your checkbook at home, locked away, and purchase traveler's checks.

  • Always write checks using ink pens or typewriters - never pencil.

  • Balance or reconcile your checkbook register with your monthly bank statements.

  • When writing the payee name on the "Pay to the Order of" line, make sure the name is spelled out so it cannot be altered (e.g. L.S.U. could be changed to L.S.Underwood.

Use anti-virus software and keep it up to date: Some phishing emails contain software that can harm your computer or track your activities on the Internet without your knowledge. Anti-virus software and a firewall can protect you from inadvertently accepting such unwanted files. Anti-virus software scans incoming communications for troublesome files. Look for anti-virus software that recognizes current viruses as well as older ones; that can effectively reverse the damage; and that updates automatically.

Firewall: A firewall helps make you invisible on the Internet and blocks all communications from unauthorized sources. It's especially important to run a firewall if you have a broadband connection. Finally, your operating system (like Windows or Linux) may offer free software "patches" to close holes in the system that hackers or phishers could exploit.

Be cautious about opening any attachment or downloading any files from emails: you receive, regardless of who sent them. Report suspicious activity to the Federal Trade Commission (FTC).  If you believe you have been scammed, go to the FTC's web site to file your complaint (www.ftc.gov) then visit the FTC's Identity Theft Web site to learn how to minimize your risk of damage from ID theft. Visit the FTC’s Spam website to learn other ways to avoid email scams and deal with deceptive spam.

Social Engineering: To better identify, reduce and mitigate your risk. One type of fraud that is on the rise is Social Engineering. Social engineering is the use of fraudulent emails, texts, or phone calls designed to lure people into providing sensitive data.

Scammers often impersonate companies, vendors, or people you know to trick you into providing personal information such as usernames, passwords, or access to your device. Often, these scammers create a story that generally ends with you paying them over the phone with gift cards.

Tips to help prevent the infection and spread of Social Engineering:

  • Never provide sensitive personal information to an unsolicited email.

  • Do not respond to emails requesting your login credentials or credit/debit card information.

  • Be suspicious of link or attachments in emails or texts from those you do not recognize.

  • If you question the legitimacy of a request, contact the source directly through a company website contact.

  • Our bank does NOT initiate emails seeing your personal data, account, or card numbers.

  • Always be cautious of any demands requesting urgent or immediate action.

MOBILE BAKING SECURITY BEST PRACTICES

Mobile banking is a great tool you can use to detect fraudulent activity because it provides an easy way to check your account on a regular basis for suspicious activity.  Some suggested security measures are:

  • Jail broken: Never use a “jail broken” device. Jail breaking a device is the act of changing the device software to remove restrictions and limitations to the operating system of the device. This could potentially subject your device to virus and or malware.

  •  Password: PIN or password protect your phone or tablet and lock it when not in use; do not reveal password information to anyone or keep it stored on the device; and do not let your device automatically log you in or save any of your login information. Use a complex password on your device including alpha-numeric, 8 or more characters. If an “app” on your phone can use a password, you should use it and make it different than your online banking password and or your device password.

  • Texting or email: Do not text message or email any confidential information about your account to the bank or elsewhere since text messages and email are not transmitted on a secure channel.

  • Identity protection: Never respond to a “phishing” text or email that requests your PIN, account number, or any card, and please remember that the bank will never request this information by text or email.

  • Anti-virus software: If available, install mobile anti-virus and anti-spyware software on your device and keep it updated.

  • Anti-malware: If available, install mobile anti-malware software on your device and keep it updated

  • Operating System/Firmware: Keep your device operating system and application up to date.

  • Application downloads: Only download and install a bank application from reliable sources such as Apple iTunes store or Google Android market; and report any banking application that appears to be malicious to the bank immediately. If an “app” on your phone can use a password, you should use it and make it different than your online banking password and or your device password.

  • Opening files: Be cautious of opening unsolicited files, text messages, or applications, especially if they are received from unknown sources.

  • Connection: Only connect to the bank via a secure connection or a non-public Wi-Fi network and remember to log out of mobile banking when you are finished with your session. Connecting to unknown Wi-Fi or public network is risky and could potentially expose your device.

  • Bluetooth: Disable Bluetooth, or set the Bluetooth status to hidden, until you want to share something.

  • Monitor: Monitor your accounts on a regular basis to detect unauthorized activity more readily.

  • Lost or stolen device: Immediately disable within the Mobile Banking Center in online banking, contact the bank, or call your mobile service provider to disconnect the service. If the “auto-wipe” feature is available to you, we recommend using it.

  • Phone lock: Lock your device to your SIM card and enable a PIN to prevent access to the device if it is lost or stolen.

PUBLIC Wi-Fi

Public Wi-Fi can be found in popular public places like airports, coffee shops, malls, restaurants, and hotels — and it allows you to access the Internet for free. These “hot-spots” are so widespread and common that people frequently connect to them without thinking twice. Although it sounds harmless to log on and check your social media account or browse some news articles, everyday activities that require a login — like reading e-mail or checking your bank account — could be risky on public Wi-Fi.

What are the risks? The problem with public Wi-Fi is that there are a tremendous number of risks that go along with these networks. While business owners may believe they are providing a valuable service to their customers, chances are the security on these networks is lax or nonexistent.

Man-in-the-Middle attacks: One of the most common threats on these networks is called a Man-in-the-Middle (MitM) attack. Essentially, a MitM attack is a form of eavesdropping. When a computer makes a connection to the Internet, data is sent from point A (computer) to point B (service/website), and vulnerabilities can allow an attacker to get in between these transmissions and “read” them. So, what you thought was private no longer is.

Un-encrypted networks: Encryption means that the information that is sent between your computer and the wireless router are in the form of a “secret code,” so that it cannot be read by anyone who does not have the key to decipher the code. Most routers are shipped from the factory with encryption turned off by default, and it must be turned on when the network is set up. If an IT professional sets up the network, then chances are good that encryption has been enabled. However, there is no surefire way to tell if this has happened.

Malware distribution: Thanks to software vulnerabilities, there are also ways that attackers can slip malware onto your computer without you even knowing. A software vulnerability is a security hole or weakness found in an operating system or software program. Hackers can exploit this weakness by writing code to target a specific vulnerability, and then inject the malware onto your device.

Snooping and Sniffing: Wi-Fi snooping and sniffing is what it sounds like. Cyber criminals can buy special software kits and even devices to help assist them with eavesdropping on Wi-Fi signals. This technique can allow the attackers to access everything that you are doing online — from viewing whole webpages you have visited (including any information you may have filled out while visiting that webpage) to being able to capture your login credentials, and even hijack your accounts.

Malicious Hot Spots: These “rogue access points” trick victims into connecting to what they think is a legitimate network because the name sounds reputable. Say you are staying at the Goodnyght Inn and want to connect to the hotel’s Wi-Fi. You may think you are selecting the correct one when you click on “GoodNyte Inn,” but you have not. Instead, you have just connected to a rogue hot spot set up by cyber criminals who can now view your sensitive information.

How to stay safe on public Wi-Fi?

The best way to know your information is safe while using public Wi-Fi is to use a virtual private network (VPN) when surfing on your PC, Mac, smartphone, or tablet. However, if you must use public Wi-Fi, follow these tips to protect your information.

Do not:

  • Allow your Wi-Fi to auto-connect to networks

  • Log into any account via an app that contains sensitive information. Go to the website instead and verify it uses HTTPS before logging in

  • Leave your Wi-Fi or Bluetooth on if you are not using them

  • Access websites that hold your sensitive information, such as such as financial or healthcare accounts

  • Log onto a network that is not password protected

Do:

  • Disable file sharing

  • Only visit sites using HTTPS

  • Log out of accounts when done using them