
There is an emerging web impersonation tactic being used by threat actors called third party phishing. Phishing is one of the oldest, most common, and most successful types of cyber-attacks. In a traditional phishing attack, a single organization is targeted. The threat actors will send out text messages or emails pretending to be from a reputable business or organization such as a financial institution. In that communication, there would be a link that if clicked, would take you to a fraudulent website that looked exactly like the organization’s legitimate webpage.
Throughout 2023, there were several reported smishing (phishing via text message) scams in which fraudulent account alerts were sent to consumers from various local banks and credit unions. Each text message contained a link which would direct consumers to a phishing website that looked just like the login page of the bank or credit union.
Threat actors have now developed a way to target hundreds of financial institutions at the same time, through the impersonation of the digital payment service -Zelle.
How it Works
Threat actors are sending out emails and text messages, claiming that you have received a payment from Zelle. In that message, they provide a link to a phishing site designed to look like Zelle. The landing page tells you that you have received money from someone. You then click “Start Search”, where you can search for your bank or credit union from a list of hundreds of Financial Institutions. You will then be asked to log in and connect your bank account to the Zelle account. At which point, the threat actors have stolen your login credentials.

Staying Safe
By reading this article you have already taken a step toward protecting yourself from these types of attacks. Being aware and educating yourself on what types of scams are out there is the best way to protect yourself.
Some other tips are:
- Enable MFA (Multi-Factor Authentication) if it’s available. This way, just knowing your login credentials will not be enough. If you receive a random MFA alert that you did not initiate, be sure to change your password.
- “If it sounds too good to be true, it probably is.” These are words to live by when scammers present scenarios that seem too good to be true, like saying you’ve won a contest or gift card.
- Don’t open attachments or follow links especially if you don’t know the sender. If an email seems strange in any way, delete it and move on.
- Never give personal information, including account information, in an email, text or unsolicited phone call. If you want to check what you’re being told is needed, type in the true company website or phone number yourself and check your account. Consider bookmarking websites for those accounts you use most often.
The views, opinions, and ideas expressed in this blog do not constitute legal or financial advice. The writers of these blogs are educated on the topics they are writing about, but they are not attorneys, licensed financial advisors, or registered investment advisors. The information presented in this blog post was deemed to be accurate at the time of publication. First Heritage Federal Credit Union is not responsible for any actions a person may take as a result of the information they read in this blog.

Leave a Reply