Archive Links

Consumer Archive
CU System Archive
Market Archive
Products Archive
Washington Archive

News Now

FinCEN offers help to ID report account-takeovers
VIENNA, Va. (12/28?11)--The Financial Crimes Enforcement Network (FinCEN) is issuing an advisory to assist credit unions and other financial institutions in identifying account-takeover activity and reporting the activity by filing Suspicious Activity Reports (SARs).

FinCEN, in its alert, notes that cybercriminals are increasingly using sophisticated methods to obtain access to accounts, including the use of malware--the computer-ese for malicious software--SQL injection attacks (SQLIA), spyware, Trojans, and worms. These attacks aim to exploit a member's or customer's account and, often, to gain seemingly legitimate access to another customer's account.

FinCEN says that through ongoing monitoring, financial institutions may be able to identify inconsistencies with normal account activity, which could indicate illicit intrusions into an account. Such irregularities might include, but are not limited to, unusual ATM activity, clustered Automated Clearing House transactions in different geographic areas, sudden wire transfers, or changes to customer and account profiles.

Account-takeover activity is different than other forms of computer intrusion because it is the accountholder, rather than the financial institution maintaining the account, that is the primary target of the fraud.

FinCEN says that a financial institution is required under the Banker Secrecy Act to file a SAR if it: Knows, suspects, or has reason to suspect" that a transaction conducted or attempted by, at, or through the financial institution involves funds derived from illegal activity or an attempt to disguise funds derived from illegal activity, is designed to evade requirements under the BSA, or lacks a business or apparent lawful purpose, the financial institution may be required to file a SAR.

When completing SARs on suspected account takeover activity, financial institutions should use the term "account takeover fraud" in the narrative section of the SAR and provide a detailed description of the activity.

Use the resource link below to read more of the FinCEN advisory and to see more examples of possible account-takeover red flags.
Other Resources


News Now LiveWire
.@FAACreditUnion named a top Okla workplace by @TheOklahoman via @Cornerstone_CUL
1 hours ago
NY @NYGovCuomo signs historic FOM law @NYCUAtweets
1 hours ago
Shop for Miracles day nets $450K for CUs for Kids #NewsNow #System
2 hours ago
2 Calif. #creditunions on why the #IOLTA reg relief bill is important. See #NewsNow
2 hours ago
Sony hack linked to N. Korea, says U.S.intelligence via @nytimes
16 hours ago