Cyber Fraud Tactics
Passwords & Authentication
Physical Security
IT Policies
100

An urgent text message claiming your bank account is locked and instructing you to click a link to verify your identity.

Smishing (SMS phishing)

100

Combining something you know with something you have is known as this security measure.

Multi-Factor Authentication (MFA / 2FA)

100

The Windows keyboard shortcut key combination that instantly locks your computer screen before stepping away from your workspace.

Windows Key + L

100

OCCU's IT incident response plan lists this as the first action to take if you believe you may have a ransomware infection on your device.

Disconnect the device from the network immediately

200

A fraudster calls an employee over the phone pretending to be a vendor to trick them into giving up credentials.

Vishing (voice phishing)

200

Rather than creating short, complex passwords with symbols, security best practice is to string together four or more random words into this type of credential.

Passphrase

200

Only USB drives with this setting enabled are permitted to be connected to OCCU devices.

Encryption (or Bitlocker)

200

Member account information, social insurance numbers, and payroll records fall into which of OCCU's 3 data classification tiers?

Class 1 - Confidential

300

A highly customized email attack that targets specific people or departments using personalized details gathered about the organization.

Spear phishing

300

The dangerous practice of using the exact same password for both your work and personal online accounts

Password reuse (or credential recycling)

300

Watching an employee's screen through a window or from far away to view confidential information or credentials

Shoulder surfing

300

This class of OCCU data may be shared or made available to the general public.

Class 3 - Public (or unrestricted)

400

Registering a fake domain name that closely resembles legitimate company address (e.g., swapping a lower-case L for the number 1)

Typosquatting (or lookalike domains)

400

An automated attack technique where hackers attempt a small list of commonly used passwords across thousands of different account usernames simultaneously to avoid locking out any single account.

Password spraying

400

Connecting a device to an unencrypted public Wi-Fi network exposes communication to this type of interception attack.

Man-in-the-middle attack

400

According to OCCU's Acceptable Use Policy, users are restricted from using this specific web browser feature to save credentials.

Remember Me, or Remember my Password, or Trust this Device

500

Cybercriminals sending a large number of MFA push notifications to a user's phone, hoping the user clicks "Approve" out of frustration or confusion.

MFA Fatigue (or Prompt Bombing / Push Harrassment)
500

A sophisticated cyber attack where an active login session token is stolen directly from a user's browser, allowing the fraudster to impersonate the user without needing their password or MFA.

Session Hijacking (or Pass-the-cookie)
500

These steps should always be performed when allowing a vendor to access a secured area within the branch.

Telling a manager
Checking the vendor's ID or badge
Asking why access is required
Ensuring they are supervised



500

When leaving their workstation, employees must take this action for any PII, confidential and sensitive data or documents.

Ensure it is placed in a secure location such as a locked drawer or filing cabinet, or scanned to Google Drive and shredded.
M
e
n
u