Return to the home page Access your accounts online Learn more about Astoria Federal Savings The branch locator is powered by Google, and governed by its own Privacy Policy Look up Current Deposit Rates We're a part of your neighborhood We're here to help...
 

Understanding Identity Theft & Phishing Brochure
4 Privacy Policy & Terms
 
 Special Alerts
Counterfeit Official Checks
Unsolicited Emails

External Resources

4   Federal Trade Commission Identity Theft Site

4   Social Security Fraud Reporting

4   US Postal Inspectors Mail Fraud Information

4   New York State Consumer Protection Board

4   Equifax

4   Experian

4   TransUnion

4   AnnualCreditReport.com

4   PhishingInfo.org

 

 

5/28/2008 Be Aware of Email Scams

Criminals are soliciting small business customers by email in an effort to illegally obtain personal information. Details


Astoria Federal is Looking Out for You
At Astoria Federal, protecting your personal and financial information is a top priority, which is why we take steps to protect the sensitive/personal information you may provide to us. We follow strict guidelines to guard against unauthorized access to your sensitive information. But it’s also important that you learn what you can do to protect yourself against Identity Theft, both online and offline. Please take a few moments to read about some important safety tips that will help protect the security of your personal information:
 

4 Steps You May Take to Protect Yourself Against Identity Theft

8  Never give your personal information over the phone, through the mail or over the Internet unless you have initiated the contact or are confident you know who you’re dealing with.

8  If you are not sure that a contact is legitimate, contact the company yourself, either by phone,
in person, or by visiting the company’s Web site by typing in the site’s address or using a page you have previously bookmarked.

8  Don’t carry your Personal Identification Numbers (PINs) with you––memorize them and keep them in a safe, secure location.

8  Review account statements regularly to ensure that all charges are correct. If your statement is late in arriving, call your financial institution to find out why. Take advantage of Online Banking to periodically review activity online and identify suspicious activity.

8  Tear or shred personal financial documents such as charge receipts, credit applications, insurance forms, or any other important material.

8  Keep your Social Security Card in a safe place and only give out the number when absolutely necessary.

8  Laptop and Personal Digital Assistant (PDA) Users:
- Never leave your laptop/PDA unattended
- Make sure your laptop/PDA requires a password when starting up
- Encrypt sensitive date on your laptop/PDA to help prevent data theft if the device is lost or stolen
 

4 The Phishing Lure

Phishing isn't really new -- it's a type of scam that has been around for years and in fact predates computers. Malicious crooks did it over the phone for years. What is new is its contemporary delivery vehicle -- spam and counterfeit Web pages.


Phishing uses email messages that claim to come from legitimate businesses that one might have dealings with – banks, online organizations, Internet service providers, online retailers, and insurance agencies. The messages may look quite authentic, featuring corporate logos and formats similar to the ones used for legitimate messages. Typically, they ask for verification of certain information, such as account numbers and passwords, allegedly for auditing purposes. And, because these emails look so official, up to 20% of unsuspecting recipients may respond to them -- resulting in financial losses, identity theft and other fraudulent activity against them.


Cutting the Line
Even before Phishing became so prevalent, legitimate businesses and financial institutions would hardly ever ask for personal information via email. If you receive such a request, call the organization and ask if it's legitimate or check its legitimate Web site (use a search engine to find it).


Look for misspellings and bad grammar. While an occasional typo can slip by any organization, more than one is a tip-off to beware.


If the e-mail refers you to a Web site, look carefully at the URL. It's easy to disguise a link to a site. The longer the URL, the easier it is to conceal the true destination address. Other ways to disguise URLs include substituting similar-looking characters, so that paypal.com could be (and has been) spoofed as paypaI.com or paypa1.com. Similarly, a zero can be substituted for the letter O within a URL. Don't click on links contained in the email if you're unsure whether the contact is legitimate. Instead, contact the organization directly or visit its legitimate Web site (use a search engine to find it).

 

4 Pharming for Your Information

Pharming is a technique used to redirect as many users as possible from the legitimate Web sites they'd intended to visit and lead them to malicious ones. Pharming involves Trojans, worms, or other technology that attack the browser address bar so that when users type in a "valid" URL they are redirected to the criminals' Web sites. The bogus sites, to which victims are redirected without their knowledge or consent, will likely look the same as a genuine site. Unaware of anything out of the ordinary, you therefore reveal your password and user name to criminals.

Don't Get Hooked

To help our customers avoid this type of attack, Astoria Federal introduced Secure Sign On, an added layer of online banking security. Secure Sign On further safeguards your financial information by displaying a picture and phrase that you select to let you know that you are at our legitimate website and that it is safe to enter your log-in information. If you enter your User ID and the next screen does not show your picture and phrase, do not enter any personal information. Instead, re-enter your User ID or contact us at 1-800-ASTORIA (1-800-278-6742) and press “3” for online banking support. As an additional identity check, we require that customers answer “challenge questions” when logging-in from a computer that our system does not recognize.
 

4 Additional Steps You May Take to Protect Yourself Online

8   Before entering any sensitive information, verify that the Web site is secure by looking for:
4
  The Lock Symbol lock symbol

Check the status bar at the bottom of your Web browser window for an unbroken lock symbol. This means your personal information is scrambled, and no one can read it but the e-business you've contacted. Double-click on the lock symbol to view the security certificate. Make sure the certificate is "Issued to" the Web site and the "Valid from" dates are current.

4  "https" in the Web Site's Address

Secure sites have "https://" at the beginning of the address, rather than "http://." The "s" stands for "secure" and indicates the information you send is encrypted or scrambled, so it can't be read during transmission.

 

8  Update your anti-virus software regularly to guard against new viruses.

8  Keep your browser and operating system up-to-date. Look for programs that offer automatic updates, including important security enhancements, and take advantage of free patches that manufacturers offer to fix newly discovered problems.

8  Only open email attachments if you’re expecting them and know what they contain. Even if the
messages look like they came from people you know, they could be from scammers and contain programs that will steal your personal information.

8  Do not be intimidated by an email or caller who suggests serious consequences if you do not
immediately provide or verify financial information.

8  Use a personal firewall to limit uninvited access to your computer, especially if you have high-speed or an “always on” connection to the Internet, such as broadband cable or DSL.

8  If you store financial information on your computer, use a password consisting of numbers and letters, both upper and lower case.

8  Avoid using an automatic login feature that saves your user name and password and always log off when you’re finished.

8  Use anti-spyware and ant-spam software

8  Be cautious when using public computers, such as those in coffee houses; or public networks, such as those in hotels and airports, to access the internet . Check with the staff to verify that their network is secure.

8  Be sure to read Web site privacy policies to know your information will be secure, how it will be used, and if it will be shared with third parties.
 

4 Steps You Should Take If Believe Your Identity Has Been Stolen

If you suspect your identity has been stolen, there are four steps you should take immediately.

1.  Place a fraud alert on your credit reports
Call any one of the three major credit bureaus to help prevent an identity thief from opening additional accounts in your name.

Equifax 1-800-525-6285
Experian 1-888-EXPERIAN (397-3742)
TransUnion 1-800-680-7289

     As soon as the credit bureau confirms your fraud alert, an alert will automatically be placed by all credit bureaus, and all three reports will be sent to you free of charge. Once you receive these reports, review them carefully for any incorrect information, particularly accounts you didn’t open or unexplained debts.

2.  Close any accounts that have been tampered with or opened fraudulently

3.  File a report with your local police or the police in the community where the identity theft took place Keep a copy of the report.

4.  Contact the authorities that specialize in Identity Theft
Federal Trade Commission Identity Theft Hot Line:
(877) IDTHEFT (438-4338)
Social Security Fraud Hot Line:
(800) 269-0271
US Postal Inspectors:
(800) 372-8347

 

Do More to Protect Yourself
While there is no way to completely prevent identity theft, there are things you can do, including taking reasonable precautions to help stop identity theft before it happens. With Debix Fraud Defense™*, the Debix Identity Protection Network™ goes to work at the moment that matters most: when a thief could be attempting to get credit in your name. Debix Fraud Defense is just one of the many benefits of the
Astoria Federal Plus Package**, a membership program available exclusively to our checking customers. To learn more about how you can take advantage of the security of Debix Fraud Defense, just stop by your neighborhood Astoria Federal branch.

 

Astoria Federal is dedicated to keeping you safe from identity theft. We’re taking steps to protect you, and hope you’ll take advantage of this valuable information to protect yourself as well. If you suspect that you have received a fraudulent email or phone call from someone claiming to be from Astoria Federal, please contact Telephone Banking immediately at 1-800-ASTORIA (1-800-278-6742)), or forward the email to phishingreports@astoriafederal.com, so we can investigate. If you have any questions about identity theft, please visit your neighborhood Astoria Federal branch—because protection of your sensitive/personal information is our concern.

 

* No endorsement or approval of any third parties or their advice, opinions, information, products or services is expressed or implied by any information contained on this site.

** Please refer to the Plus Package section for complete details of Debix Fraud Defense coverage and exclusions.

Important Security and Safety Tips Reminder Investing in us Join our team Privacy Policy & Terms and Conditions Look up financial and other banking related terms How to use and navigate through this web site