• Home
  • Education
  • News and Resources
  • Advocacy
  • Associate Members
  • Contact
  • My Profile
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

Tag Archive for: paycheck protection program

Posts

Education

The Long Tail of Paycheck Protection Program

By Jeff Otteson, vice president of sales at Midwest Bankers Insurance Services, a WBA subsidiary

Jeff Otteson

Why Bank Customers Are Being Targeted Again

The Paycheck Protection Program (PPP) may have ended, but the information it generated continues to create opportunities for fraudsters.

Businesses that received PPP loans are now being targeted through highly personalized bank-impersonation schemes. Using publicly available PPP loan information, criminals can identify a business, its loan amount and, in many cases, the financial institution associated with the loan. That information gives a fraudster enough credibility to make an unexpected call, text message or email sound legitimate.

This is not simply another generic phishing campaign. It is a targeted social-engineering attack built around real information and a trusted banking relationship.

How the Scam Works

The Small Business Administration maintains a public, loan-level dataset covering disbursed PPP loans. Fraudsters can combine that data with business websites, social media and other public records to develop a convincing profile of a potential victim.

A fraudster may know:

• The business’s legal name and address
• The amount of its PPP loan
• The lender associated with the loan
• The names of owners, executives or accounting employees
• The bank’s treasury-management or fraud-department terminology

The criminal then contacts the business while impersonating an employee of its bank. Caller ID may be spoofed so the call appears to originate from the bank’s actual telephone number. Emails and text messages may use the bank’s name, logo and branding.

The purported reason for the contact can vary. The customer may be told that:

• A suspicious ACH or wire transfer is pending
• Someone attempted to access the company’s online banking account
• A check or electronic payment must be verified
• The account must be frozen to prevent additional fraud
• A security update is required
• The bank needs to confirm the customer’s credentials
• A one-time passcode is needed to stop or reverse a transaction

The fraudster creates urgency and positions himself as the person trying to protect the customer. In reality, the criminal may already possess the customer’s username and password. The call is designed to obtain the final piece needed to defeat multifactor authentication: the customer’s one-time security code.

The FBI has specifically warned about account-takeover schemes involving criminals impersonating financial-institution support personnel. Once the customer provides the requested code, the fraudster may gain access to the account, establish a new device, change contact information or initiate unauthorized ACH and wire transfers.

Why These Calls Are So Convincing

Traditional fraud-awareness training often tells customers to look for spelling mistakes, unfamiliar senders or vague messages. Those warning signs may not be present here.

The caller may correctly identify the customer’s bank, PPP loan and business information. The telephone number appearing on caller ID may match the number printed on the back of the customer’s debit card or listed on the bank’s website. The criminal may even transfer the victim between several supposed departments to create the appearance of a legitimate financial institution.

The use of accurate information does not make the caller legitimate. It only demonstrates that the criminal has done research.

Bank customers should understand that caller ID is not a reliable authentication method. A person who receives an unexpected banking call should hang up and contact the bank through a telephone number the customer independently knows to be correct – not a number provided by the caller or contained in an unsolicited message.

What Banks Should Be Telling Their Customers

Banks should communicate directly with business customers, particularly customers identified in public PPP data. The message should be simple and specific: The bank will never call and ask a customer to disclose a password, authentication token or one-time security code.

Customers should also be reminded that a code generated by multifactor authentication is not merely an identification number. It may authorize access, approve a new device or permit a transaction. Providing that code to another person can be the digital equivalent of handing over a key to the account.

Additional customer guidance should include:

• Never provide usernames, passwords, PINs, tokens or one-time passcodes in response to an incoming call, email or text.
• Do not click an online-banking link contained in an unsolicited message.
• Access online banking through the bank’s official website or mobile application.
• Hang up and call the bank using a known, independently verified telephone number.
• Require dual control for ACH and wire activity.
• Establish transaction and daily exposure limits that reflect the company’s actual needs.
• Review new users, authorized devices and changes to account contact information.
• Enable alerts for password changes, new-device enrollment and outgoing transactions.
• Report suspicious communications immediately, even if no money appears to have left the account.

Prompt reporting can help prevent or limit a loss. Customers should not wait until the next business day if they believe credentials or authentication codes have been disclosed.

Banks Must Also Examine Their Own Procedures

Customer education is only one part of the response. Banks should review how employees handle calls involving compromised credentials, new-device enrollment, changes to telephone numbers or email addresses and requests to add new treasury-management users.

A fraudster who has compromised a customer’s email account may attempt to add a supposed new CFO or controller to the customer’s wire agreement. The request may come from the customer’s legitimate email address, but that does not establish that the request is authorized.

Material changes to authorized users, callback numbers, transaction authority or security procedures should be independently verified with an existing authorized person using previously established contact information. Employees should not rely on the telephone number or contact information contained in the request being verified.

The bank should also confirm that its written wire-transfer agreement clearly identifies:
• Who is authorized to request wires
• The predetermined telephone number to be used for callbacks
• The PIN or passcode the requester must verify during the callback
• The procedures for changing authorized persons or callback information

Having a written agreement is only the beginning. Employees must consistently follow the security procedures contained in it. A callback to a number supplied in the fraudulent request is not an effective callback. Similarly, completing a callback without requiring the agreed-upon PIN or passcode may undermine the protection the procedure was designed to provide.

The Insurance Question Is More Complicated Than It Appears

When an account-takeover loss occurs, the customer, bank and their respective insurers may all examine who was compromised, who authorized the transaction and which security procedures were followed.

Coverage is highly dependent on the specific facts and policy language. A bank’s Financial Institution Bond may distinguish between a direct compromise of the bank’s systems and a loss resulting from a customer voluntarily providing credentials or authentication codes. Computer-fraud, funds-transfer, fraudulent-instruction and social-engineering provisions may contain materially different definitions, exclusions and authentication requirements.

The customer’s cyber or crime policy may also be relevant, particularly when the customer’s employee was deceived into disclosing credentials or approving a fraudulent transaction. However, the existence of insurance should never be assumed to eliminate the potential dispute between the customer and the bank.

Banks should review both their operational procedures and insurance coverage before a loss occurs. That review should address customer credential compromise, account takeover, new-device authorization, fraudulent changes to authorized users and the failure to follow agreed callback or authentication procedures.

The Takeaway for Community Banks

PPP data has created a lasting roadmap that criminals can use to identify businesses and their banking relationships. The immediate scam may target the customer, but the resulting financial loss, customer dispute and reputational damage can quickly reach the bank.

Community banks are particularly well positioned to respond because they know their customers and can communicate with them directly. A timely warning from a trusted relationship manager may be more effective than a general fraud notice posted on a website.

Banks should not treat the end of the PPP lending period as the end of PPP-related risk. The loans may have been forgiven, but the publicly available information remains – and criminals are finding new ways to use it.

August 19, 2026/by Emily Torgerson
https://www.wisbank.com/wp-content/uploads/2021/09/Untitled-3_Blue.jpg 972 1920 Emily Torgerson https://www.wisbank.com/wp-content/uploads/2021/09/Wisconsin-Bankers-Association-logo.svg Emily Torgerson2026-08-19 15:14:572026-08-19 15:14:57The Long Tail of Paycheck Protection Program
Search Search

Categories

  • Advocacy
  • Community
  • Compliance
  • Credit Unions
  • Education
  • Member News
  • News
  • Products
  • Resources
  • Uncategorized

Recent Posts

  • Congratulations to the August 2026 BankWork$ Graduates!
  • Bay Bank Announces Leadership Advancements to Strengthen Service and Expand Access
  • Christine Barwick Joins First Citizens State Bank
  • The Road to November 3rd With WBA: Governor and Attorney General Update
  • Mound City Bank Announces Jaydon Bierman’s Promotion to Agribusiness Lending Officer

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2016
Wisconsin Bankers Association logo
  • About
  • Community
  • Subsidiaries
  • Staff

questions@wisbank.com

608-441-1200

4721 S Biltmore Ln.
Madison, WI 53718

Get our Newsletter!
Subscribe

© 2025 Wisconsin Bankers Association. All rights reserved. | Website Design by Bizzy Bizzy
Scroll to top Scroll to top Scroll to top

This site uses cookies. By continuing to browse the site, you are agreeing to our use of cookies.

OKLearn more×

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Terms of Use
Accept settingsHide notification only

Subscribe

* indicates required








Membership