At the end of March 2022, the NCUA published a new risk alert titled Heightened Risk of Social Engineering and Phishing Attacks. Citing the ongoing conflict in Ukraine and concerns about potential cyber-attacks against the United States' critical infrastructure, the NCUA guidance reminded credit unions to remain vigilant in the face of increased phishing and other social engineering attempts.
According to the FFIEC Information Security Booklet, social engineering is "a general term for trying to trick people into revealing confidential information or performing certain actions." Social engineering comes in many flavors, including phishing (via email), smishing (via text message), and vishing (via phone call).
Phishing emails are currently the most prevalent form of social engineering. However, the NCUA risk alert warns credit unions to be on the lookout for smishing attempts, as well.
The NCUA alert provides five common clues associated with phishing attempts.
In short, if you notice these things in an email and your spidey-sense starts tingling, it might be phishing.
The NCUA goes on to provide six tips to help you avoid becoming a victim.
If your credit union does become a victim of phishing, or any kind of cyber incident, the risk alert recommends reporting the incident to:
For more information about reporting incidents to CISA, check out our blog on the New Cyber Incident Reporting Act.
The NCUA risk alert reinforces the "continued importance of educating your employees and members on how to avoid these threats."
If you are looking for a way to train your teams on phishing, check out Tandem Phishing. This do-it-yourself tool allows you to send simulated phishing campaigns, obtain status reports, and provide follow-up training to your teams on how to avoid phishing in the future.