Digital Banking Login
Turn Your Side Hustle Into a Main Character

INtroducing: The Side Hustle Business Bundle

Giving entrepreneurs the legit tools, confidence, and financial setup to grow on their terms.

Something's Trying to Get In!: The Fright Files Case #002

The Case of the Uninvited Intruder

One password isn't enough to keep the monsters out.

Imagine locking your front door, only to discover that someone has stolen your key. Suddenly, the barrier protecting everything inside isn't quite as secure as you thought.

Your online accounts face a similar threat. Cyber criminals use phishing emails, data breaches, and other deceptive tactics to steal passwords and gain access to your personal and financial information.

But what if your password wasn't the only thing standing between a criminal and your accounts?

In our second installment of The Fright Files, we're investigating multi-factor authentication (MFA), an additional layer of security that can help stop intruders in their tracks.  

 

The Suspect: Stolen Passwords

Even a strong password can fall into the wrong hands. That's why relying on a password alone can leave your accounts vulnerable.

Multi-factor authentication adds another layer of protection by requiring two or more different ways to verify your identity before granting access. Even if someone steals your password, they may be unable to complete that additional verification step.

Think of it as adding a deadbolt to your digital front door. 

 

The Evidence: How MFA Works

MFA uses a combination of different types of identification to verify that you're really you.

    • Something you know - A password or PIN that only you should know.

    • Something you have - A trusted device, authenticator app, or physical security key.

    • Something you are - A unique physical characteristic, such as your fingerprint or facial features.

By combining at least two of these factors, MFA makes it considerably harder for someone to impersonate you.

For example, after entering your password, you might be asked to enter a temporary code generated by an app on your phone. Without that second step, a stolen password may not be enough to access your account.

 

The Investigation: Not All Locks Are Created Equal

There are several ways to use MFA, and some offer stronger protection than others.

    • Text Message Verification: You receive a temporary code by text that you enter after your password. This is a familiar and convenient option, although criminals can sometimes intercept these codes or take control of phone numbers.

    • Authenticator Apps: Apps generate temporary codes or send verification requests directly to your device. They generally offer stronger protection than text messages.
       
    • Security Keys: These small physical devices can be plugged into or tapped against your device to verify your identity. When used with supported services, they offer strong protection against phishing attacks.

    • Biometric Verification: Fingerprint and facial recognition can provide a convenient additional way to confirm your identity when used as part of an MFA system. 

The important thing is to enable MFA wherever it's available and choose the strongest method supported by your accounts. 

Learn more: How to Create a Good Password

 

The Frightening Twist: Scammers Want Your Verification Codes Too!

Just when you thought the intruders were locked out, the investigation takes a sinister turn.

Cyber criminals know that MFA makes stealing accounts more difficult. That's why some target the additional verification step itself.

A scammer might pretend to represent your financial institution and claim they need a code that was just sent to your phone. Others may repeatedly trigger login approval notifications, hoping you'll eventually approve one.

Never share an unexpected verification code or approve a login request you didn't initiate.

If you receive an unexpected authentication request, deny it. If you're concerned someone is trying to access your financial accounts, contact your financial institution using a trusted phone number or its official website. 

 

Your Assignment: Secure Your Digital Doors

Ready to give cyber criminals another obstacle? Start with these four simple steps:

    1. Investigate your accounts. Check the security settings for your email, financial accounts, social media, and online shopping accounts.

    2. Activate MFA. Look for settings labeled multi-factor authentication, two-factor authentication, or two-step verification.

    3. Choose your protection. Select the strongest available option, preferably a phishing-resistant passkey or security key when supported.

    4. Stay alert. Never approve unexpected login requests or share verification codes with anyone who contacts you unexpectedly.

Learn more: Turn on MFA

 

Case Closed: Keep the Intruders Out!

A stolen password doesn't have to become a stolen identity. Multi-factor authentication is a simple but valuable tool that can help protect your accounts, personal information, and hard-earned money.

This Cyber Security Awareness Month, take a few minutes to investigate your online security settings and add another layer of protection wherever possible.

And keep following The Fright Files throughout October as InRoads Credit Union continues exposing the tricks and traps cyber criminals use to target your finances.

The investigation continues. Don't let your guard down! 

Learn More

For more info about fraud prevention and safe banking, visit our Fraud Prevention page.

Experience the InRoads Difference

Invested, innovative, and here for you and our community.