FDIC logo

FDIC-Insured - Backed by the full faith and credit of the U.S. Government

Fraud & Security Library

Learn about the latest fraud and financial security topics, plus steps you can take to manage your account security.

Your Information is Safe with Orrstown Bank.

"I have been inundated with telemarketing calls, letters, and emails from other lenders since I applied for a mortgage. Did Orrstown Bank sell my information?"

No, it is actually illegal for your mortgage company to sell or share your information without your express written consent. Orrstown Bank does not sell your information. A well-kept secret in the mortgage industry is the act of buying information from the credit bureaus. Mortgage companies pay to be notified when you have a mortgage-related pull on your credit score, and then they begin reaching out to you to try and get your business. If you pay for a service that notifies you about any changes to your credit report, it's just like that, and it's also pretty immediate.

These companies are able to get your cell phone number from the report, as well as your email and mailing address. When you opened an account for a mobile phone or utilities, you probably gave them your Social Security Number, which means your phone number and addresses are now linked to your Social Security Number, and thus, showed up on a credit report. Some credit reports can even show your place of work, as well as previous addresses you have listed.

The best practice to avoid such calls is to list your phone number on the National Do Not Call Registry.


Fraud Prevention Tips

Safeguard Your Online Information

  • Never provide your confidential information, such as Social Security Number or Date of Birth, to someone unless you have initiated the contact.
  • If you are contacted by phone or email and asked to confirm your confidential information, do not respond to the caller or the email. Contact the company back using the phone number found on your monthly statement or on their legitimate website. Do not use the phone number provided in the email correspondence or that the caller provides to you.
  • Do not use your confidential information as a Personal Identification Number (PIN) or a password.
  • When completing online applications or making purchases, ensure the website is utilizing encryption and the page shows as an “https” page.
  • Do not record your Social Security Number on a check, traveler's check, gift certificates, etc., unless required by law.
  • Don't carry your Social Security Card and be cautious of your surroundings. Old-fashioned wallet stealing is still profitable and utilized by criminals.
  • Be mindful when using online social networking. Use a search engine to see how much information about you is listed online and could be pieced together to commit Identity Theft.
  • Order your FREE Annual Credit Report.

Eliminate Paper

  • Reduce the amount of mail and paper with your personal information printed on it to reduce the chance of criminals stealing it.
  • Sign up for electronic statements and stop receiving paper account statements.
  • Sign up for direct deposit with your employer to have your funds put directly to your account without paper checks.
  • Pay your bills with online bill payment to reduce the risk of sending your checks in the mail.
  • Watch for the signs of identity theft such as receiving bills in the mail for things you didn’t authorize.
  • Purchase a shredder and shred bills and statements.

Secure Your Computer

  • Anti-spyware and anti-virus protection detects and removes viruses and spyware, which can steal vital information.
  • A firewall prevents unauthorized users from gaining access to a computer or monitoring transfers of information to and from the computer.
  • Operating system and software updates, sometimes called "patches" or "service packs," should be installed as soon as possible.
  • Web browser updates are deployed with your security in mind so keep them current.

Secure Your Mobile Device

  • Your smartphone contains a host of personal information about you. Secure access to your application by applying a strong password or enabling biometric verification.
  • Change your password regularly and never write it down or share it with anyone.
  • Configure your phone to automatically lock and apply the password when your device is not in use.
  • Do not allow the device to save your mobile banking passwords. Anyone else who uses your device can easily gain access to your account because the access information would already be stored.
  • If your phone is lost or stolen, report it to us immediately.
  • Links in emails, tweets, social networking postings and text messages are often ways cybercriminals disperse their malware. If it looks suspicious, even if you know the sender, it’s best to delete it or call the sender to validate the message.
  • Be wary of any communications that require you to act immediately or ask for personal information. Remember, Orrstown Bank will never:
  • Call, email or text you asking for your online banking password, wire pin or challenge question answers
  • Consider adding anti-virus software to your smartphone.
  • Mobile Banking does send confirmation messages to your device to alert you of transactions taking place. These messages do not contain private information about you or your account. Become familiar with content of these messages and contact us immediately if you receive a message you feel is suspicious.
  • Jailbreaking is a method of “self-hacking” your smartphone. This makes your smartphone more susceptible to malware and other malicious programs. If you choose to use your mobile device for online banking we advise you not to jailbreak your smartphone.
  • Review your account transactions regularly and immediately report any suspicious activity.

Phishing

Criminals “phish” for your personal information. Phishing can take place via phone calls, emails, text messages, visiting your place of business or by directing you to a phony website that claims to be Orrstown Bank.

Stop and ask yourself, if you were to receive an email, text message or phone call from Orrstown Bank stating there was a problem with your account, would you question the validity of the message?

Criminals attempt to trick you into believing the communication you are seeing or hearing is from someone you trust.

Remember, Orrstown Bank Will Never:

  • Call, email or text you asking for your online banking password, wire pin or challenge question answers.
  • Direct you to a website that asks you to update your personal account information.
  • Email you computer software updates.
  • Visit your place of business and request to perform maintenance on your computer.

If you receive a phone call, email, text message or visit to your place of business that you question, please take the time to call and ask us to validate the communication before taking any action requested. Please do not use the contact information provided in the email or text message you receive. Use the number advertised on our website or on the back of your debit card so you know you’re reaching us.

Email Phishing

Criminals may send you an email that looks like it has come from Orrstown Bank. These phony emails may contain an infected link or attachment. These emails will either ask you to reply and provide your confidential information or they will direct you to a website that asks you to enter your confidential information. Remember, Orrstown Bank will not ask you to email us your personal information, nor will we ask you to enter it online to update our records. Do not take any action requested in the message. Report the message to us.

These messages are usually well-crafted to trick you into thinking you must take immediate action. Be on the lookout for messages like the following:

  • Urgent appeals claim that your account may be closed if you fail to confirm, verify, or authenticate your personal information.
  • Messages about system and security updates claim that the bank needs you to confirm important information and states that you must update your information online.
  • Offers that sound too good to be true often are. You may be asked to fill out a short customer service survey in exchange for money being credited to your account, and you are then asked to provide your account number for proper routing of the supposed credit.
  • Typos and other errors are often the mark of fraudulent emails. Be on the lookout for typos or grammatical errors.

If you receive a suspicious email, do not click on any links or reply to it. Simply delete it. To report a suspicious email that is abusing Orrstown Bank’s brand, please contact Client Care Center at 1-888-677-7869.

Phone Phishing

Phone Phishing, called “Vishing” uses Voice over Internet Protocol (VoIP) to generate automated phone calls. The calls are usually an automated recording that states your account has experienced unusual activity. The message instructs you to call a phone number to have the issue corrected.

Rather than return the phone call, contact us and report the incident. We do not utilize automated systems to contact you about your accounts. Please do not use the number in the message. Contact Client Care at 1-888-677-7869.

Text Phishing

Text message Phishing, called “SMShing” is phishing that happens via SMS text messages. A criminal sends a text message tricking you into providing financial or personal information or clicking on links that will sneak viruses onto your mobile device.

Do not respond to these messages or click the links in the messages. Please contact Client Care at 1-888-677-7869 to report the incident.

Malware

Malware is a general term for software that is meant to cause harm. Computer viruses, spyware, adware, and Trojan horses are all examples of malware. The purpose of malware can be something as seemingly harmless (yet annoying) as popping up a window to show you unwanted advertising, or as dangerous as capturing the keystrokes as you type your internet banking password or internet banking challenge question answers.

Computers become infected with malware through a number of mechanisms – sharing files on USB thumb drives or DVDs, opening suspicious email attachments, clicking on links in emails or visiting websites that are themselves infected with malware. Malware can also arrive with downloaded files, such as music or videos from peer-to-peer file sharing networks, or simply by visiting a website that has been hacked and infected. No longer is it a matter of staying away from “bad” websites. Unfortunately, any website that is not properly secured can be hacked and infected with malware that could infect your PC, and you most likely will not receive any warning that malware is being downloaded onto your computer. In most cases, the website owners themselves do not know their sites have fallen victim to dispersing criminal malware.

How do you avoid getting malware? Taking these steps can help limit the chances of infection:

  • Install and use well-known, reputable anti-virus software. Configure the software to update the virus definitions daily and to scan files and your system in real-time. Setting up an additional full system scan on a regular basis is a good practice as well. This software can help in providing a layer of protection when you visit a site that has been hacked and infected. Anti-virus is no longer enough though. If the only measure you employ is anti-virus, you don’t have enough layers of protection to protect you from attacks.
  • Use a firewall. If you are using Windows, enable the Windows Firewall. If you have a Mac, enable the built-in firewall. If you have the means to install a corporate firewall that protects the PCs within your network that is most certainly recommended as well.
  • Avoid fake anti-malware. Don’t buy anti-malware software advertised in pop-up ads. Legitimate software isn’t sold this way.
  • Don’t open suspicious email attachments or click the links within emails. Infected email attachments and html website links are one of the most popular ways to spread malware. Even if you know the sender of the email, it’s better to verify why they sent you the message before clicking the attachment or links. They may not know they’ve sent you the message.

Cyber criminals disguise their emails to look as though they’re from a legitimate business. Often, they employ some type of scare tactic to entice you to open the email and/or provide account information. For example, emails may state they are from:

  • UPS claiming there is a “problem with your shipment”
  • A Financial Institution claiming there is a “problem with your banking account”
  • The Better Business Bureau stating “A compliant has been filed against you.”
  • Court system stating that “You have been served with a subpoena.”

Other popular emails are ones that claim to show photos or video of current events like natural disasters and major sporting events.

  • Don’t respond to messages that try and scare you in to providing an “Immediate Response”. Emails stating your account is subject to being closed or stating that you’re required to install new software updates should be reported immediately. If either of these situations were true we would have sent you previous correspondences letting you know of an upcoming change or issue with your account status.
  • Patch your computer regularly. Ensure you are applying vendor-distributed patches.
  • Report suspicious behavior. If you cannot access our online banking site, contact us immediately to determine if the site is down for scheduled maintenance or if a fraudster is deliberately locking you out of viewing your account activity.
  • Review your account activity on a regular basis and report suspicious activity.

Money Mules

Money mules are unsuspecting victims who become middlemen for criminals trying to launder stolen funds. Victims are lured by the promise of a new career opportunity making large sums of money for minimal work. Criminals recruit money mules, send them stolen money and then ask the money mules to wire or transfer the money unwittingly to the criminals. Using the money mule masks the criminal's identity.

The money mule may keep a commission for performing the transfer or wire. The victims of these scams may not only have their bank accounts closed and financial reputation ruined, but are often left financially responsible for returning the stolen funds.

Common signs of a money mule scam:

  • Overseas companies requesting money transfer agents in the United States.
  • Opening new bank accounts to receive money from someone you don't know.
  • Accepting large sums of money into your personal bank account for a new job.
  • Transferring or wiring funds out of your personal bank account to people you do not know.

Beware of These Scams

1. Phishing (Email, Text, and QR Code Scams)

What It Looks Like

  • Email claiming your bank account is locked
  • Fake package delivery notifications
  • Text messages asking you to verify an account
  • QR codes that direct you to fake login pages

Warning Signs

  • Urgent requests to act immediately
  • Links that don't match the company's website
  • Requests for passwords or verification codes
  • Poor grammar or unusual wording

How to Protect Yourself

  • Never click links in unexpected messages
  • Go directly to the company's website instead
  • Enable multi-factor authentication (MFA)
  • Verify requests using a known phone number

CISA identifies phishing as one of the most common forms of cyberattack affecting both individuals and organizations.

2. Account Takeover Attacks

What It Looks Like

A criminal gets your password through phishing, a previous data breach, or social engineering and gains access to:

  • Email accounts
  • Banking accounts
  • Amazon accounts
  • Social media accounts

Warning Signs

  • Login alerts from unknown locations
  • Password reset emails you didn't request
  • MFA prompts you didn't initiate

How to Protect Yourself

  • Use unique passwords for every site
  • Use a password manager
  • Turn on MFA everywhere possible
  • Never approve unexpected MFA prompts

This was highlighted as a common attack method during internal scam awareness discussions.

3. Identity Theft

What It Looks Like

Criminals use stolen personal information to:

  • Open credit cards
  • Apply for loans
  • File fraudulent tax returns
  • Commit crimes using your identity

Warning Signs

  • Bills for accounts you never opened
  • Unexpected credit inquiries
  • Collection notices for unknown debts

How to Protect Yourself

  • Freeze your credit with Equifax, Experian, and TransUnion
  • Review your credit reports regularly
  • Limit personal information shared on social media
  • Shred sensitive documents

Identity theft continues to be a major enabler for many other fraud schemes.

4. AI Deepfake Scams

What It Looks Like

Criminals use AI to generate:

  • Fake phone calls from family members
  • Fake executive voices
  • Fake videos
  • Highly personalized messages

Warning Signs

  • Requests involving urgency or secrecy
  • Unexpected requests for money
  • Voice calls with unusual speech patterns

How to Protect Yourself

  • Establish family "safe words"
  • Verify requests using a separate communication method
  • Be skeptical of emotional or urgent demands

Internal discussions specifically highlighted AI-generated voice and video fraud as a rapidly growing threat.

5. Business Email Compromise (BEC)

What It Looks Like

A criminal impersonates:

  • A vendor
  • Your boss
  • A real estate agent
  • An attorney

The attacker convinces victims to send money to a fraudulent account.

Warning Signs

  • Requests to change payment instructions
  • Urgent wire transfer requests
  • Slightly altered email addresses

How to Protect Yourself

  • Verify payment changes by phone
  • Use known contact information
  • Never rely solely on email for financial transactions

BEC remains one of the most financially damaging cybercrimes.

6. Cryptocurrency and Investment Scams

What It Looks Like

Scammers promise:

  • Guaranteed returns
  • Secret investment opportunities
  • Cryptocurrency trading profits

Many begin with a "wrong number" text or online friendship.

Warning Signs

  • Guaranteed profits
  • Pressure to invest quickly
  • Offshore websites
  • Difficulty withdrawing money

How to Protect Yourself

  • Research investments independently
  • Be skeptical of unsolicited opportunities
  • Avoid transferring funds to unknown parties

These "pig butchering" scams were identified as an increasingly common criminal tactic.

7. Ransomware

What It Looks Like

Malware encrypts files and demands payment.

While individuals are targeted, ransomware more commonly impacts businesses, schools, hospitals, and governments.

How to Protect Yourself

  • Keep devices updated
  • Back up important files regularly
  • Avoid downloading unknown attachments
  • Use reputable security software

CISA lists ransomware among the most significant cyber threats today.

8. Social Media Scams

What It Looks Like

  • Fake giveaways
  • Fake customer support accounts
  • Romance scams
  • Marketplace fraud

Warning Signs

  • Too-good-to-be-true offers
  • Requests for gift cards or cryptocurrency
  • Rapid attempts to move conversations off-platform

How to Protect Yourself

  • Verify account authenticity
  • Restrict the personal information you share publicly
  • Never send money to online acquaintances

Scammers increasingly use social media to gather information and conduct targeted fraud.