Online banking makes it easier to manage your money, pay bills, transfer funds and monitor your accounts from almost anywhere. With a few simple security habits, you can help protect your banking information and reduce the risk of fraud.
Online banking is generally safe, but scams such as phishing, malware and stolen login credentials can put accounts at risk. The Canadian Centre for Cyber Security recommends using strong passwords or passphrases, multi-factor authentication, updated devices and secure connections when accessing online banking. The good news is that protecting your online banking account doesn't have to be complicated. Here are some practical steps you can take to help keep your accounts and personal information secure.
Your online banking password should be strong and different from the passwords you use for other accounts. If the same password is used across multiple websites and one of those websites experiences a data breach, criminals may try those stolen credentials on other services, including financial accounts. Consider using a strong passphrase that is easy for you to remember but difficult for someone else to guess. A password manager can also help you create and manage unique passwords for your accounts. If you use a password manager, choose one with strong security features such as multi-factor authentication.
Remember:
Multi-factor authentication, commonly called MFA, adds another layer of protection to your account. Instead of relying only on a password, MFA requires an additional form of verification when you sign in. Depending on the service, this could include an authentication app, security code, fingerprint or another verification method. The Canadian Centre for Cyber Security recommends using MFA where possible, particularly for important accounts such as online banking and email. If your financial institution offers MFA or enhanced login security, consider enabling it. Remember that MFA is an additional layer of protection, not a reason to approve an unexpected login request. If you receive an MFA notification that you didn't initiate, don't approve it.
One of the simplest ways to avoid phishing scams is to access your financial institution directly.
Instead of clicking a banking login link in an unexpected email or text message:
Phishing messages can imitate financial institutions and direct you to websites designed to collect your login information.
A website can look professional and still be fraudulent, so don't rely on logos or familiar-looking designs alone.
Fraudsters may send messages that appear to come from your financial institution.
The message might claim:
Don't let an unexpected message pressure you into acting quickly. If you're concerned about your account, open your banking app or website yourself and check your account directly. Never provide your password, PIN or security codes in response to an unexpected email, text or phone call.
Regularly reviewing your accounts can help you notice unusual activity sooner.
Check your:
Consider setting up available account alerts for transactions and changes to your account. Even a small unfamiliar transaction can be worth investigating. If you notice something you don't recognize, contact your financial institution promptly.
Your computer, phone, tablet, browser and apps should be kept up to date. Software updates frequently include security fixes that address known vulnerabilities. Turn on automatic updates where appropriate so important security updates aren't forgotten. The Canadian Centre for Cyber Security recommends keeping operating systems and software updated as part of protecting online banking accounts. Also use reputable security software and keep it updated.
When accessing sensitive financial information, use a trusted network whenever possible.
For example, consider using:
Public Wi-Fi can introduce additional security risks, including fraudulent networks designed to look legitimate. The Canadian Centre for Cyber Security recommends using a secure Wi-Fi connection or cellular data when carrying out sensitive activities. If you need to check your bank account while you're away from home, using your cellular data connection can be a practical option.
Your device is an important part of your online banking security. Use a PIN, passcode, fingerprint or other available security feature to prevent unauthorized access if your device is lost or stolen.
You should also:
Protecting the device you use to access your banking accounts is just as important as protecting your banking password.
Avoid accessing online banking from public or shared computers. If you do use a device that isn't yours, don't save your username or password in the browser and make sure you sign out when you're finished. For your own devices, use the security features that are available to prevent other people from accessing your accounts. The Canadian Centre for Cyber Security recommends avoiding public computers for online banking and signing out when you're finished using sensitive accounts.
Your online banking password, PIN and security codes should be kept private. Be cautious if someone contacts you unexpectedly and asks for this information. A legitimate organization should not ask you to disclose your online banking password so they can "protect" your account. If someone claims to be from your financial institution and you're unsure whether the request is legitimate, end the conversation and contact the institution using a trusted phone number.
Multi-factor authentication can help protect your accounts, but you still need to pay attention to the requests you receive. If you receive a login notification, authentication request or security code when you aren't trying to sign in, don't approve it. Unexpected MFA requests can sometimes be part of an attempt to gain access to an account. The Canadian Centre for Cyber Security specifically identifies techniques such as MFA fatigue as a potential threat. If this happens, change your password and contact your financial institution if you believe someone may have attempted to access your account.
Information you share publicly can sometimes be used to make scams more convincing.
Think carefully before publicly sharing information such as:
Fraudsters can use publicly available information to make phishing and impersonation attempts more believable.
Yes. Online banking is generally safe when you use appropriate security practices. The biggest risks often involve stolen credentials, phishing, malware and fraudulent websites rather than online banking itself.
You can reduce your risk by:
If you believe someone may have accessed your online banking account, act promptly.
Use a trusted phone number or official website to contact your financial institution. Tell them what happened and follow their instructions to protect your account.
Change your online banking password using a trusted device. If you used the same password anywhere else, change those passwords as well.
Look for unfamiliar withdrawals, transfers, bill payments, purchases or other activity.
If the same credentials were used for other important accounts, including your email, change those passwords too.
Your financial institution can help explain what steps you should take if you believe you've been the victim of fraud. You may also need to report suspected fraud to the appropriate authorities. The Canadian Centre for Cyber Security recommends contacting your bank immediately if you have fallen victim to fraud or attempted fraud and reporting the incident to the Canadian Anti-Fraud Centre.
Protecting your financial information is something we take seriously. If you're a YNCU member and have questions about online banking security, account alerts, e-transfers or other account protections, our team can help you understand your options.
If you believe your YNCU account or banking information may have been compromised, contact YNCU as soon as possible.
YNCU Service Excellence Centre: 1-800-413-YNCU (9628)
Don't be embarrassed about asking questions. If something doesn't look right or you're unsure about a message, it's always reasonable to stop and verify it.
Before you finish, make sure you've taken these basic steps:
Use a strong, unique password or passphrase, enable multi-factor authentication, keep your devices updated, access your bank through its official website or app, avoid unexpected links and monitor your account regularly.
Online banking is generally safe when appropriate security practices are used. Common risks include phishing, malware, stolen credentials and fraudulent websites. Using MFA, strong passwords, updated devices and trusted connections can help reduce these risks.
It's better to use a trusted Wi-Fi network or cellular data when accessing sensitive financial information. Public Wi-Fi can introduce additional security risks, including fraudulent networks.
If you weren't expecting the message, it's safer not to click the link. Instead, access your bank through its official app or website, or contact the institution using a trusted phone number.
A password manager can help you create and manage unique passwords or passphrases. If you choose to use one, consider a reputable service with strong security features, including multi-factor authentication.
Regularly reviewing your transactions can help you identify unfamiliar activity sooner. Consider checking your accounts frequently and setting up available transaction and security alerts.
Don't approve the request if you didn't initiate the login. Change your password and contact your financial institution if you believe someone may be trying to access your account.
Contact your financial institution immediately using a trusted phone number and follow its instructions. Change compromised passwords, review your transactions and report suspected fraud to the appropriate authorities.
Good online banking security comes down to a few consistent habits: use strong and unique credentials, enable multi-factor authentication, keep your devices updated, verify unexpected messages and monitor your accounts. You don't need to be a cybersecurity expert to take these steps. When something doesn't look right, stop and verify it before taking action. A few extra seconds can help you make a safer decision about your money and personal information.