A New Fraud-Fighting Resource

By Ray Birch

TALLAHASSEE, Fla.—With fraudsters getting so good and their attacks ever more sophisticated, it’s time for credit unions to call in a new resource to fight fraud—their own members.

That’s advice from Ann Davidson, VP-risk consulting, experience and credentials at Allied Solutions, who believes effectively educating members on how to combat fraud themselves is no longer a nice thing to do, it’s a necessary strategy to not just protect members but the reputation of the credit union itself.

“The crooks are getting so skilled that you have got to call in members now,” emphasized Davidson. “Members have become another important leg of defense now. I have been saying this for a while, and this is needed.”

What is truly cause for alarm, according to Davidson, is just how good criminals and criminal organizations have become at spoofing the credit union and then contacting members directly.

“The bad actors are acting like the credit union,” Davidson said. “They are taking the position of the credit union.”

Painfully Effective

Davidson Ann

Ann Davidson

Davidson explained this tactic, where crooks pose as the CU and then reach out to members, is painfully effective because members depend on their credit unions and are often waiting for a response back from the credit union on a matter, and they drop their guard.

“They think, ‘This is my trusted credit union’ when the criminals call,” explained Davidson, noting the ruse is made even more effective because criminals have a wealth of data on consumers as well as knowledge of the credit union they are pretending to be.

One tactic fraudsters are now using to penetrate accounts is to call members pretending to be the CU’s call center and asking members to provide the six-digit authorization code that was sent to them to log into their account.

“And some members are giving this code to the fraudsters,” said Davidson. “Members should know that code should never be redisplayed anywhere or given back to the credit union. The credit union needs to let members know they will never ask for that code to be given back to them.”

An Absolute Necessity

Davidson said educating members on how to prevent fraud is now an absolute necessity.

“In the past many credit unions may have thought about this and some have taken steps to educate members. But now they have to—and they are. I just was on three Zoom calls with credit unions and their members that covered how members can fight fraud,” Davidson said.

Davidson said the attack vectors are increasing, including via payment apps like Zelle and Venmo, which are increasingly being used by criminals now. She said crooks are relying a great deal on credential stuffing—the automated injection of stolen username and password pairs into website login forms.

Davidson urged credit unions to communicate regularly with members about how they can join the fraud fight. She recommended CUs share examples through website information, Zoom meetings, text messages, links via mobile apps as to what tactics are being used by fraudsters and what members should be doing to avoid being victimized.

Additional Steps to Take

She also outlined what credit unions should be doing now to further protect member data:

  • Utilize member information for identification versus only using member account information
  • Avoid using Social Security numbers, date of births, mother’s maiden name or other public information, since these types of authentication layers are public and can be used by the bad actor
  • Consider using “dynamic” knowledge base authentication questions for new and existing members. These questions are unique to an individual that are not publicly accessible or easy to guess and can even be rotated. Some examples could include:
    • What is your mortgage payment?
    • What is the color of your car?
    • Who is joint on your account?
    • What branch do you use?
    • What was your last transaction?
    • Review FFIEC Guidelines that encourage the use of challenge questions during authentication that do not rely on information that is publicly available
    • Configure clear and defined pass/fail requirements during the authentication process to help keep information secure
    • For employees, outline the specific number of questions asked and number of multiple answers allowed
    • Set time limits to prevent the bad actor from researching the answer
    • Educate members on how important it is they do not share any of their personal or financial information with anyone they did not call, email or text. This can include helpful resources, classes, or fraud prevention tools
    • Research industry information on prevention of authentication fraud. Talk with peers on what action they are using to help understand the various attacks

“It has never been so critical and for the consumer to understand what they need to do, and what they should not do, so they won’t become a victim,” said Davidson.

Section: Standard
Word Count: 981
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto.flux5.ccplatform.net/THE-feature/A-New-Fraud-Fighting-Resource