Unfair Deceptive Abusive
Bank Secrecy Act
Spear Phishing
Social Engineering
Robbery
100

Hidden fees or refusing to release a lien on a paid-off loan is an example of what? 

UNFAIR. 

100

The regulatory framework commonly abbreviated as AML that works hand-in-hand with the Bank Secrecy Act.

What is anti-money laundering. 

100

The specific form of spear phishing directed exclusively at high-level executives or credit union C-suite members.

Whaling 

100

An unbadged visitor closely following an authorized staff member through a secure branch door without scanning their keycard.

Tailgating or piggybacking 

100

The term for a robbery where perpetrators break into the credit union after hours to access the vault, avoiding staff contact entirely.

Burglary 

200

Bait-and-switch tactics or false advertising is an example of what? 

Deceptive. 

200

The government bureau within the U.S. Department of the Treasury that receives and analyzes BSA filings.

FiCEN (Financial Crimes Enforcement Network) 

200

A spear phishing attack carried out over SMS or text messaging rather than traditional email.

Smishing 

200

The strict physical security rule requiring all sensitive member files and documents to be locked away when leaving a desk.

Clear desk policy 

200

The single most important rule for all credit union employees during an active robbery.

Remain calm and cooperate fully 

300

Exploiting consumer confusion about a complex financial product is an example of what? 

ABUSIVE. 

300

A Currency Transaction Report (CTR) must be filed when a member conducts aggregate cash transactions exceeding this dollar threshold in a single business day.

What is 10,000

300

Scammers often exploit this emotion by claiming an account will be "permanently closed within 1 hour" if action isn't taken immediately.

Sense of urgency / fear 

300

When an unannounced vendor or repair technician arrives at a branch, staff must perform this check before granting entry to secure areas.

Identity & Work-Order Verification

300

To preserve evidence for law enforcement, staff must prevent anyone from touching counter surfaces, door handles, or this item left behind by the suspect.

Robbery Note 

400

Unlike Deception, which relies on a "reasonable consumer" standard, Abusive practices often target members who fall under this status.

Vulnerable.

400

A credit union has this many calendar days to file a Suspicious Activity Report (SAR) after initial detection of a suspect.

30 days. 

400

A spear phish claiming to come from internal IT that asks for your single-use code to "verify system maintenance" is attempting to bypass this security layer.

Multi Factor Authenticator 

400

The social engineering strategy where an attacker offers a fake service, like "free tech support," in exchange for sensitive network credentials.

Quid Pro Quo 
400

Security devices that deploy colored chemical staining and tear gas inside stolen cash bundles shortly after leaving the branch.

Dye Packs 

500

Unfair, Deceptive, and Abusive acts are defined as? 

Unlawful business standards that are prohibited by federal law and enforced to prevent financial injury and ensure transparency for consumers. 

500

Under the Bank Secrecy Act, financial institutions must maintain a detailed log whenever a member purchases cashier's checks or money orders using cash within this specific dollar range.

$3,000 - $10,000

500

The internal tool or button integrated into the credit union's email client allowing staff to instantly report suspicious messages to Information Security.

Phishing Alert Button (phish hook)
500

According to security industry standards, this non-technical asset is considered both the most vulnerable target for social engineering and the credit union's strongest first line of defense.

Employees (or Human Element)

500

To prevent memory contamination, employees should complete this task independently before discussing the event with coworkers.

Robber / Suspect Identification Forms