We have been notified of a high-risk phishing and impersonation scam currently in circulation.
Overview of the Incident
A member received a fraudulent text message claiming that they were entitled to a €1,500 energy grant.
The text message included a malicious link.
When clicked:
- The member was taken to a fake webpage requesting:
-
- Three digits of their online banking PIN
- Followed by another three digits, capturing the full six-digit PIN
- They were then asked to complete a form providing:
-
- Name
- Date of birth
- Branch
- Member number
Approximately 20 seconds later, the member received a phone call from a fraudster posing as the Credit Union.
During the call, the fraudster:
- Claimed there was suspicious activity on the account
- Asked whether family members had access to online banking
- Said they would send a One-Time Passcode (OTP) to “verify details”
Because the fraudster was attempting to log in using the stolen information, the One-Time Passcode genuinely issued from the credit union’s system.
Thankfully, the member became suspicious, ended the call, and contacted their credit union immediately. The account was secured before any loss occurred.
Key Risk Indicators
- Unexpected texts offering grants, refunds, or energy credits
- Links requesting PIN digits or login credentials
- Follow-up phone calls claiming to be from the Credit Union
- Requests for One-Time Passcodes or verification codes
- Pressure, urgency, or warnings of “suspicious activity”
- We would like to remind members that:
-
- Staff will never ask for full PINs or online banking credentials
- One-Time Passcodes should never be shared with anyone.
If in doubt, pop in or ring us on our landline – remember, we are here to help.
