By Jeff Otteson, vice president of sales at Midwest Bankers Insurance Services, a WBA subsidiary

Jeff Otteson
Why Bank Customers Are Being Targeted Again
The Paycheck Protection Program (PPP) may have ended, but the information it generated continues to create opportunities for fraudsters.
Businesses that received PPP loans are now being targeted through highly personalized bank-impersonation schemes. Using publicly available PPP loan information, criminals can identify a business, its loan amount and, in many cases, the financial institution associated with the loan. That information gives a fraudster enough credibility to make an unexpected call, text message or email sound legitimate.
This is not simply another generic phishing campaign. It is a targeted social-engineering attack built around real information and a trusted banking relationship.
How the Scam Works
The Small Business Administration maintains a public, loan-level dataset covering disbursed PPP loans. Fraudsters can combine that data with business websites, social media and other public records to develop a convincing profile of a potential victim.
A fraudster may know:
• The business’s legal name and address
• The amount of its PPP loan
• The lender associated with the loan
• The names of owners, executives or accounting employees
• The bank’s treasury-management or fraud-department terminology
The criminal then contacts the business while impersonating an employee of its bank. Caller ID may be spoofed so the call appears to originate from the bank’s actual telephone number. Emails and text messages may use the bank’s name, logo and branding.
The purported reason for the contact can vary. The customer may be told that:
• A suspicious ACH or wire transfer is pending
• Someone attempted to access the company’s online banking account
• A check or electronic payment must be verified
• The account must be frozen to prevent additional fraud
• A security update is required
• The bank needs to confirm the customer’s credentials
• A one-time passcode is needed to stop or reverse a transaction
The fraudster creates urgency and positions himself as the person trying to protect the customer. In reality, the criminal may already possess the customer’s username and password. The call is designed to obtain the final piece needed to defeat multifactor authentication: the customer’s one-time security code.
The FBI has specifically warned about account-takeover schemes involving criminals impersonating financial-institution support personnel. Once the customer provides the requested code, the fraudster may gain access to the account, establish a new device, change contact information or initiate unauthorized ACH and wire transfers.
Why These Calls Are So Convincing
Traditional fraud-awareness training often tells customers to look for spelling mistakes, unfamiliar senders or vague messages. Those warning signs may not be present here.
The caller may correctly identify the customer’s bank, PPP loan and business information. The telephone number appearing on caller ID may match the number printed on the back of the customer’s debit card or listed on the bank’s website. The criminal may even transfer the victim between several supposed departments to create the appearance of a legitimate financial institution.
The use of accurate information does not make the caller legitimate. It only demonstrates that the criminal has done research.
Bank customers should understand that caller ID is not a reliable authentication method. A person who receives an unexpected banking call should hang up and contact the bank through a telephone number the customer independently knows to be correct – not a number provided by the caller or contained in an unsolicited message.
What Banks Should Be Telling Their Customers
Banks should communicate directly with business customers, particularly customers identified in public PPP data. The message should be simple and specific: The bank will never call and ask a customer to disclose a password, authentication token or one-time security code.
Customers should also be reminded that a code generated by multifactor authentication is not merely an identification number. It may authorize access, approve a new device or permit a transaction. Providing that code to another person can be the digital equivalent of handing over a key to the account.
Additional customer guidance should include:
• Never provide usernames, passwords, PINs, tokens or one-time passcodes in response to an incoming call, email or text.
• Do not click an online-banking link contained in an unsolicited message.
• Access online banking through the bank’s official website or mobile application.
• Hang up and call the bank using a known, independently verified telephone number.
• Require dual control for ACH and wire activity.
• Establish transaction and daily exposure limits that reflect the company’s actual needs.
• Review new users, authorized devices and changes to account contact information.
• Enable alerts for password changes, new-device enrollment and outgoing transactions.
• Report suspicious communications immediately, even if no money appears to have left the account.
Prompt reporting can help prevent or limit a loss. Customers should not wait until the next business day if they believe credentials or authentication codes have been disclosed.
Banks Must Also Examine Their Own Procedures
Customer education is only one part of the response. Banks should review how employees handle calls involving compromised credentials, new-device enrollment, changes to telephone numbers or email addresses and requests to add new treasury-management users.
A fraudster who has compromised a customer’s email account may attempt to add a supposed new CFO or controller to the customer’s wire agreement. The request may come from the customer’s legitimate email address, but that does not establish that the request is authorized.
Material changes to authorized users, callback numbers, transaction authority or security procedures should be independently verified with an existing authorized person using previously established contact information. Employees should not rely on the telephone number or contact information contained in the request being verified.
The bank should also confirm that its written wire-transfer agreement clearly identifies:
• Who is authorized to request wires
• The predetermined telephone number to be used for callbacks
• The PIN or passcode the requester must verify during the callback
• The procedures for changing authorized persons or callback information
Having a written agreement is only the beginning. Employees must consistently follow the security procedures contained in it. A callback to a number supplied in the fraudulent request is not an effective callback. Similarly, completing a callback without requiring the agreed-upon PIN or passcode may undermine the protection the procedure was designed to provide.
The Insurance Question Is More Complicated Than It Appears
When an account-takeover loss occurs, the customer, bank and their respective insurers may all examine who was compromised, who authorized the transaction and which security procedures were followed.
Coverage is highly dependent on the specific facts and policy language. A bank’s Financial Institution Bond may distinguish between a direct compromise of the bank’s systems and a loss resulting from a customer voluntarily providing credentials or authentication codes. Computer-fraud, funds-transfer, fraudulent-instruction and social-engineering provisions may contain materially different definitions, exclusions and authentication requirements.
The customer’s cyber or crime policy may also be relevant, particularly when the customer’s employee was deceived into disclosing credentials or approving a fraudulent transaction. However, the existence of insurance should never be assumed to eliminate the potential dispute between the customer and the bank.
Banks should review both their operational procedures and insurance coverage before a loss occurs. That review should address customer credential compromise, account takeover, new-device authorization, fraudulent changes to authorized users and the failure to follow agreed callback or authentication procedures.
The Takeaway for Community Banks
PPP data has created a lasting roadmap that criminals can use to identify businesses and their banking relationships. The immediate scam may target the customer, but the resulting financial loss, customer dispute and reputational damage can quickly reach the bank.
Community banks are particularly well positioned to respond because they know their customers and can communicate with them directly. A timely warning from a trusted relationship manager may be more effective than a general fraud notice posted on a website.
Banks should not treat the end of the PPP lending period as the end of PPP-related risk. The loans may have been forgiven, but the publicly available information remains – and criminals are finding new ways to use it.
