Pinnacle Bank’s terms, privacy and security policies do not apply to the site you’re about to enter. Please review its terms, privacy and security policies to see how they apply to you. Pinnacle Bank isn’t responsibe for or endorse
Recently, the cybercriminal group, FIN7, known for targeting US businesses through phishing emails, deployed an additional tactic of mailing USB devices via the United States Postal Service (USPS). The mailed packages sometimes include items like teddy bears or gift cards to employees of target companies working in the Human Resources (HR), Information Technology (IT), or Executive Management (EM) roles. The enclosed USB device is a commercially available tool known as a “BadUSB” or “Bad Beetle USB” device. After the USB device is plugged into a target system, the USB device automatically injects a series of keystrokes in order to download and execute a unique malware payload commonly known as the GRIFFON malware, which is also a payload observed in several variations of FIN7 phishing emails.
Please do not plug an unknown USB device into any computer system. And always be wary of packages coming from someone unknown to you or of a package coming from someone that seems out of the normal routine. Call to verify before inserting anything in your computer system.
Early indications are that fraudsters may be increasing phishing attacks in an effort to exploit the current COVID-19 pandemic. The Risk Office has observed fraudster emails and voice mails sent directly to cardholders asking for personally identifiable information (PII) and impersonating the Financial Institutions (FI), health groups, and federal government agencies.
Additionally, criminals in possession of card details and other forms of PII are spoofing the phone number from financial institutions to fool cardholders into thinking that text messages and phone calls are actually from the fraud department of their financial institution.
It makes a difference when you and your cardholders remain vigilant. If something sounds suspicious, question it. As a reminder to your cardholders, it’s important that they remain diligent in reviewing their accounts daily and quickly report any unauthorized activity.
Please remind your cardholders that there is a lot that they can do to protect their own financial accounts and information in order to avoid compromising their own information. Here are some of the points you can make to help educate your cardholders:
A text alert warning of suspicious activity on a card will NEVER include:
A VALID notification will provide information about the suspicious transaction and ask the cardholder to reply to the text message with answers such as ‘yes,’ ‘no,’ ‘help,’ or ‘stop.’
It is important to us that all individuals have access to the information contained within our documents. However, please note that some documents, particularly PDF files, may not be fully compatible with screen reader software used by individuals with visual impairments or other disabilities.
If you encounter any difficulties accessing or navigating our PDF documents, we are here to assist you. Please contact Pinnacle Bank at 877.759.7939 for further assistance or to request an alternative format of the document.
We are committed to ensuring accessibility for all individuals and appreciate your understanding and cooperation.