You look at the clock. It’s 30 minutes until your clock-out time at work. You’re finishing up your last tasks for the day, already thinking about your weekend plans.
You receive an email with the subject line: “Urgent: Problem with account ID management, confirmation needed.”
The email appears to be from your credit union. The email address and sender both look and read as if it were someone from the financial intuition reaching out. You aren’t sure what the problem is, but you decide to handle it when you get home.
Your phone begins to ring. The caller ID shows that the call is coming from your financial institution. You start to worry that there is an issue with your account due to the email and now phone call. You decide to take the call to hopefully get things sorted out.
The caller claims to be from the financial institutions’ fraud department, telling you about a recent security breach and how it is affecting members’ accounts. They want to confirm that no unauthorized access or transactions occurred.
The caller tells you not to login via the mobile app or online banking to check the status of your account. Instead, they ask you to use the link that was sent to your email as it is more secure. You follow their instructions, clicking on the link that was sent to your email. It looks exactly like the normal online portal. You enter your username and password credentials. Once logged in, you are greeted with a pop-up notice: “Thank you – Your account has been secured and your identity confirmed.” The caller lets you know that everything with your account is taken care of and there is nothing to worry about. Unfortunately, the caller was not someone from the fraud department at your financial institution. There was no system breach, and your login information is now in the hands of a fraudster.
What just happened?
You were just the target of a multi-channel impersonation or phishing attack. An attacker sets up a high-stake situation with initial contact via email or text. Then, whether the initial message is opened or not, they follow up with a phone call. By referencing the previous message sent, they successfully build your perceived trust in the interaction.

This multi-channel approach gets the member on the phone with a “trusted” source while believing you are in a high-stake situation. Once you are on the phone and that attacker sets the stage as the trusted authority, they guide you into giving away information that will grant them access to your account. During the process, they reassure you that your accounts are fine.
Building your defenses
Now that you understand the architecture of a multi-channel impersonation attack, let’s review how to handle these attacks and red flags you should look for:
- Recognize the push for urgency: When someone contacts you via email, text or phone with an intent to pressure you for information regarding your account.
- Be on the lookout for re-directs: Financial institutions will never call or message you out of the blue and tell you to avoid logging in through the normal login portals (online banking or mobile app) and to follow a different link instead.
- Protect one-time codes: One-time codes sent to your phone are meant for you ONLY. If someone else is asking for a verification code or password that was sent to you, they may be trying to gain access to your account.
- Break the Chain: If you are in a situation where you think the call is fake or not someone you should be speaking to, hang up. Call the financial institution to report the incident. DO NOT call the number that you were contacted on.
You hold the power
As the tools attackers have at their disposal evolve, these attacks become easier and more common. Multi-Channel attacks are crafted to catch targets of all age groups, creating a perfect funnel to get victims to complete requested tasks.
It is more important than ever to remember the attacker’s formula and mental checkpoints. If the call seems suspicious, offer to hang up and call them back. Find a known phone number to call; do not call the number back that you received the call from or one verbally provided by the caller. Be mindful of personal information that is being shared through social media as well; specific information may be used as a tool to make these calls sound more realistic.
Fraud can happen in any industry. Be cautious when communicating with others about important or personal information, stay alert and identify the red flags that may be presented.
Call to action
If you have questions about fraud or suspect you’ve received a fraudulent email claiming to be from KH Credit Union, please contact us immediately to report it and receive guidance in protecting your account. Our phone number is (937) 558-9070 and you can reach us during our office hours of 8:30 a.m.-4:30 p.m., Monday-Friday.
Exclusive to team members
Ready to take advantage of one of your Kettering Health benefits?
Whether you’re looking to save more, borrow smarter or simply improve your financial wellness, KHCU is here to help. Visit us online, stop by our office or contact our team to learn more about becoming a member.
We look forward to helping you achieve your financial goals.