Software
Houzz Logo Print
raee_gw

My even more aggravating banking breach story!

This is long, fair warning!

Yesterday I received a notice in the mail from my credit union (which has my "secondary" accounts, where I keep my emergency fund and parked other funds to earn interest that I can't get from the primary bank) that my checking account was overdrawn after a withdrawal - said withdrawal happened to be the entire amount in the account!

I have only once ever used this account to pay anything, since opening it in 2007 - that was to pay the IRS an unexpected amount last year; I only have transferred funds both from and to my primary bank as the need arose. I've never used the debit card, or written a check on that account (and both are still locked in my desk.) (side note- the unexpected amount was a mistake on the part of the IRS which took hours on the phone and months to correct.)

When I logged into my credit union, I could see that my account had been logged into (or attempts, the account page only says log ins) 3 times a day, on a schedule, since the day after I was last logged in. It must be a computer program. It does show the browser that was used to log in, & it isn't mine. After several days of log ins, it made the withdrawal - actually a transfer to a Venmo account (which I don't have and have never used or sent a payment to a user.) It continued to log in after that, even while I was logged in and looking at my account.

I immediately changed my password and enabled 2 factor identification. If I had known that the credit union now offered that, I would have had it already, as I do with credit cards, the other bank, my doctor's office - everywhere that it is offered. The customer service person also suggested that I change my user name, but she didn't know how - and it appears that I cannot via the online banking site either.

So the mystery log ins have stopped. Unfortunately, this credit union's 24 hour phone customer service says there is nothing that they can do until a branch opens on Tuesday AM - I have to go there in person, fill out a paper form there, request that the money be returned and the overdraft fee rescinded, and close the account. Needless to say, that they can't take any action to protect me or my other accounts over the weekend is beyond aggravating!

I checked on "haveibeenpwned.com" to see if my password had been compromised - that site says not.

The CU says that the thief had to know my account number and their routing number in order to make the transfer. How anyone got that information is beyond me. No one except the credit union knows that I have accounts there. I've run several different scans (different companies) on my computer and none have found malware. I have to wonder if someone breached the information at either the IRS, the CU, or my other bank.

PS I tried to contact Venmo, but since I don't use it and don't have an account, I can't talk to anyone there.

Comments (16)

  • 3 years ago

    Wow - what a nightmare!! I’m surprised the CU software didn’t block any further logins after several attempts - assuming they were unsuccessful.

    raee_gw zone 5b-6a Ohio thanked 3katz4me
  • 3 years ago

    This is so crazy, and I'm so sorry it happened to you. I truly hope that the bank makes it right on Monday. I feel like all of the missed login attempts should've alerted the bank to alert you and I'm surprised it didn't shut things down until you could be contacted.

    raee_gw zone 5b-6a Ohio thanked Mrs. S
  • 3 years ago
    last modified: 3 years ago

    What a nightmare ☹️

    I'm wondering if the culprit is an employee of the CU - or someone who was able to access the info through an employee...?

    raee_gw zone 5b-6a Ohio thanked carolb_w_fl_coastal_9/10
  • 3 years ago

    Oh no, this is awful. I agree that the CU should have froze out whoever kept attempting to login, especially considering how infrequent the log in history has probably been. Hope you can this resolved without a major hassle. So sorry this has happened.

    raee_gw zone 5b-6a Ohio thanked teeda
  • 3 years ago

    Yes, I have discovered that they now offer those features - 2 factor ID, notifications of withdrawals or transactions etc. They didn't have them when I became their customer, and for some reason it never occurred to me - and it should have - to check if they were - even as I began utilizing them at my other bank and business.

    It adds to the question of who did this, doesn't it? Not only found a way into my account, but an account that didn't have protections enabled. Although perhaps that is not as uncommon as I assume.

  • 3 years ago
    last modified: 3 years ago

    When we know better, we do better. I have every kind of alert activated on my accounts, so I get notified by email when my bank account is accessed, and when any kind of transaction occurs. This means sometimes multiple notifications in my email inbox daily, and I open every one and check it out.

    I just had a thought - do you get paper statements in the mail?

    raee_gw zone 5b-6a Ohio thanked carolb_w_fl_coastal_9/10
  • 3 years ago

    No, no paper statements mailed. Which begs to ask the question - why did my only notification of the overdraft come by mail, arriving 5 days after the fact, instead of emailing me? My primary bank emails such things, along with my daily account activity.

  • 3 years ago

    Credit Unions and smaller regional banks are often targets for these:

    Credential Cracking

    Credential cracking (OWASP OAT - 007) ─ Also known as ‘brute forcing,’ credential cracking is a way to identify valid credentials by trying different values for usernames and passwords (usually from lists of breached account credentials that were made public by malicious parties and hackers). Hackers deploy bots to hack into customers’ accounts using the brute force approach, dictionary attacks (inputting large numbers of words), and guessing attacks to identify valid login credentials. Brute force attack symptoms include a sudden increase in failed login attempts and high numbers of account hijacking complaints from customers.

    raee_gw zone 5b-6a Ohio thanked 1929Spanish-GW
  • 3 years ago

    I am definitely going to be asking the credit union how this could escape their notice!

  • 3 years ago
    last modified: 3 years ago

    Something vaguely similar happened to my sister and DSIL.

    DSIL wrote checks to pay some bills. He put them in their mailbox right in front of their house. When he got back to his in-home office, he realized he had missed a bill. He wrote the check and carried it out to the mailbox. Flag was still up but the box was empty! In the 10 or so minutes that he had been in the house, someone had stolen their mail, thereby obtaining the bank routing number and DD/DSIL’s account number.

    They immediately called the bank. The bank, for all intents and purposes, closed their account. However, the bank left the account active just to see if anyone tried to access the account. This was done by the bank with no liablity on DD/DSIL. Sure enough, many months later someone tried to write a check on their account!

    Is ther any possibility that the check to the IRS was stolen out of your mailbox? The thief could have stolen it, copied the info, and sent the check on to the IRS, so that you were not aware of any criminal activity.

    raee_gw zone 5b-6a Ohio thanked bbstx
  • 3 years ago

    Just finished reading this one - a woman's life savings drained from her Chase account and Chase is denying her restitution...

    https://www.cbsnews.com/detroit/news/bank-scam-text-message-chase-bank/

    raee_gw zone 5b-6a Ohio thanked carolb_w_fl_coastal_9/10
  • 3 years ago

    bbstx, I paid the IRS via online ACH transfer. So, not a physical check - but the banking information might have been available to someone working at the IRS, or a hack into their system?

  • 3 years ago

    carolb, that is outrageous!!

    I do no banking by phone, and have my 2 factor sent to my email. I would be accessing my accounts from home always (I might have to think about how to manage if I do travel overseas again).

  • 3 years ago

    Carolb, when we lost Mom several months ago, as her executor and POA, I called my atty and asked him how to begin. After discussing some amounts (not a large estate), he said I think you can handle this yourself without incurring my expenses and offered to send me a couple of forms I would need. Then asked, which bank will you be dealing with. When I said Chase, he responded 'Oh No. They are just the worst to deal with. Call me back if you find you do need my help.' I managed, but not without some effort and angst. It was 9 months before I could really call everything finalized and was able to close her accounts. No local branch here in this community and I made at least a half dozen 50 miles trips to speak to someone with authority in person at Chase.

  • 3 years ago

    Ugh, morz - Chase is so huge, I don't see how we can expect them to be easy to deal with.