Banco Finantia does not send emails, text messages or use any other means of communication to request account details or login credentials from its customers; therefore, under no circumstances should customers provide such information or enter it in such circumstances. Clients should not reply to this type of communication, nor should they click on any links contained therein.
Clients should never disclose their account details, usernames or passwords. The websites authorised by Banco Finantia are as follows:
Clients should remain vigilant and, should they come across any other address that bears a visual, phonetic or name-based resemblance, they should refrain from using it or contacting the parties listed there and should contact Banco Finantia immediately via the usual channels.
To prevent fraudulent use of the Homebanking Service, clients should adopt the following preventive measures:
a) Keep the Access Code confidential;
b) Do not allow third parties to use the Access Code, even if they are authorised representatives;
c) Memorise the Access Code and refrain from writing it down;
d) Do not store or record the Access Code in a way that could be understood by or accessible to third parties.
In the event of loss, theft or misplacement of personalised security elements (User ID or Access Code), the client must notify Banco Finantia immediately.
Pishing
The term originates from the English word fishing. This threat consists of fraudulent messages sent by criminals impersonating trusted companies or individuals. They cast the bait and, often, victims are “caught”.
Examples include: a very urgent email “from the bank” warning that the account has been blocked; or a generous offer from a well-known company that must be claimed within a short time.
Attack methods:
The most common phishing attacks occur via email. In some cases, criminals use domains similar to legitimate email addresses, or even common domains such as Hotmail or Gmail. If a person becomes a victim of phishing, criminals may gain access to their email account and misuse it, impersonating the victim.
These attacks typically share an alarming tone, using phrases such as “your bank account has been blocked” or “your email account will be deleted” to prompt rapid, unconsidered action.
Prevention Tips
Smishing
Smishing is a type of phishing carried out via SMS or text messages sent to mobile phones. These messages usually ask the recipient to click on a link and complete a form or reply to the message. They may refer, for example, to the need to update information or the opportunity to claim an attractive prize.
Attack methods:
By clicking on or replying to the message, the victim may be redirected to malicious websites where, once personal data are entered, they can be misused by criminals. Targets typically include personal information such as address or tax identification number, banking details, and access passwords for banking, social media and email.
Prevention tips:
Never click on links sent via messages from unknown senders and never provide your details on unknown forms or websites. When making purchases or transactions that require entering personal data, always check that the URL starts with https (secure protocol) rather than http.
Vishing
Vishing is the third type of phishing and is carried out via phone calls. Using social engineering techniques, attackers attempt to persuade victims to disclose their information.
Attack methods:
Calls may be made by a person, through recordings or automated voices. Attackers often claim they need to confirm personal data held by the bank, authorise a banking transaction, or grant a loan.
Prevention tips:
Do not provide personal data over the phone to unknown callers. If you genuinely have pending banking transactions, contact your bank directly using official phone numbers. Do not call the numbers provided by the caller, as these may also be part of the fraudulent scheme.