Protect Your Account: Recognizing Fraud and Using Security Controls
Your account security is a shared responsibility. Our bank uses multiple safeguards to protect your information and funds, and there are simple steps you can take to help prevent unauthorized access. This guide explains how to recognize legitimate communications, use available security controls, monitor your accounts, and report suspicious activity.
1. How to Recognize a Legitimate Communication
Fraudsters may impersonate banks through email, text messages, phone calls, or other communications. They may claim that your account is at risk and ask you to provide information that could be used to access your account.
Be especially cautious when a message asks for:
- Your online banking username or password.
- A one-time verification or MFA code.
- Your debit or credit card PIN.
- Your full Social Security number or other sensitive identification information.
- Answers to security questions.
- Other credentials or information that could be used to authenticate you.
Never provide a one-time security code to someone who contacts you unexpectedly.
A fraudster may use a code you provide to complete an attempted login or transaction.
Ways to verify a communication
- Do not use links or phone numbers provided in a suspicious message. Instead, contact us using the phone number on the back of your card, your account statement, or our official website or mobile app.
- Check the sender carefully. An email address, phone number, or text message can be made to look like it came from the bank.
- Be suspicious of urgency or threats. Requests to "act immediately," threats that your account will be closed, or demands for secrecy are common warning signs.
- Be cautious even if the caller knows information about you. Fraudsters may obtain personal information from data breaches, social media, or other sources.
- When in doubt, end the conversation and contact us directly. We would rather help you verify a communication than have you provide information to a fraudster.
We may contact you to verify certain activity or protect your account. However, our employees will not ask you to disclose your password or to provide a one-time authentication code so that the employee can use it on your behalf.
2. Security Controls You Can Use
We provide security features designed to help protect your accounts. Use as many of these controls as are available for your account.
Multi-factor authentication (MFA)
MFA adds an additional layer of protection beyond your username and password. Depending on the service, you may be asked to approve a sign-in or provide a verification factor when accessing your account.
Enable MFA wherever it is offered, and never approve an authentication request that you did not initiate. Unexpected MFA requests can be a warning that someone else is attempting to access your account.
Strong, unique passwords
Use a unique password for online banking and do not reuse it for other websites. Consider using a reputable password manager to create and securely store strong passwords.
Never share your password with anyone, including someone claiming to be a bank employee.
Keep contact information current
Make sure your phone number and email address are current so we can send security notifications and contact you when appropriate.
Protect your devices
Keep your phone, computer, browser, and mobile banking application updated. Use a device lock such as a PIN, passcode, fingerprint, or facial recognition when available.
Avoid accessing financial accounts from shared or public computers whenever possible.
3. Monitor Your Account With Alerts
Account alerts can help you identify suspicious activity quickly. Depending on your account and our available services, you may be able to receive notifications by text message, email, push notification, or another communication method.
Consider enabling alerts for activities such as:
- Password or security-setting changes.
- Changes to contact information.
- Password resets.
- New payees or external accounts.
- Debit card transactions or unusually large transactions.
- Transfers, withdrawals, or other account activity.
- Changes to account preferences or security settings.
Review alerts promptly. If you receive an alert for activity you do not recognize, sign in through our official website or mobile app—or contact us using a trusted phone number—to investigate.
An alert is not a substitute for regularly reviewing your account. Check your transactions and statements and report suspicious activity as soon as possible.
4. How to Report Suspicious Activity
Contact us immediately if you believe someone has accessed your account without authorization, your credentials have been compromised, you provided information to a suspected fraudster, or you notice transactions you do not recognize.
Use only trusted contact methods:
- Fraud or suspicious account activity: 618-495-2225
- Online banking or account access: 618-495-2225
- Debit or credit card concerns: 618-495-2225
- Information security or suspected phishing: 618-495-2225
- Official website: fsbank.bank
- Mobile banking: Use the contact or secure-message feature within the official Farmers State Bank of Hoffman mobile app.
If you believe your credentials may have been compromised, change your password through our official website or mobile app and contact us promptly. If you believe an unauthorized transaction has occurred, report it immediately rather than waiting for your next statement.
If you receive a suspicious email or text message, do not click links, open unexpected attachments, or respond with sensitive information. Follow Farmers State Bank of Hoffman’s instructions for reporting suspected phishing.
5. When We May Use Enhanced Authentication
For your protection, we may require additional authentication when the risk of unauthorized access or fraud is higher.
Enhanced authentication may be required when you:
- Reset or change your online banking password.
- Recover a username or otherwise regain access to an account.
- Change important security or contact information.
- Enroll a new device or establish a new method of accessing your account.
- Add a new payee, external account, or transfer destination.
- Initiate certain transfers or other higher-risk transactions.
- Contact our call center about sensitive account information or account access.
- Perform activity that differs significantly from your normal account behavior.
- Attempt to access certain services or information from a new or unrecognized device.
The additional authentication may involve MFA, verification of information we have on file, a secure notification, or another authentication method appropriate to the situation.
These additional steps are designed to help us confirm that we are communicating with the legitimate account holder before allowing sensitive changes or transactions.
Important: Enhanced authentication does not mean you should provide your password or an MFA code to an unexpected caller, email sender, or text message. If you are unsure whether a request is legitimate, stop and contact us through a trusted channel.
Remember
When it comes to account security:
Stop. Verify. Protect.
- Stop when a communication unexpectedly asks for sensitive information.
- Verify by contacting the bank through a trusted channel.
- Protect your account by using MFA, strong passwords, security alerts, and other available controls.
- Report suspicious activity promptly—even if you are not certain that fraud has occurred.
We are here to help you protect your accounts and information.