Online Fraud

Summary: 

To keep safe online with Suncorp Bank All you need to remember is that we'll never send you an email asking you to verify your details, reset your account or supply any personal details.

Our emails won't ever contain any "Logon to Internet Banking" links.

 

Phishing and Hoax Emails

'Phishing' refers to a method used by criminals to trick our customers into using fake websites pretending to be those of Suncorp or other legitimate companies. These fraudsters send out lots of spam emails which include a link that entices the recipient to visit a fake Suncorp website instead of the legitimate one.

Email Security Tips

  • Be wary of emails from people you don't know or trust. Delete any emails you think are suspicious.
  • Never click onto a link or an attachment in an email, obtained from a source you don't know or trust.
  • Never provide your personal or security details, including Customer ID or passwords, in response to any email. Suncorp will never request this information from you via email.
  • Always scan any new programs or files for viruses before you open, install or use them. Your anti-virus software may do this for you automatically.

All you need to remember is that Suncorp Bank will never send you an email asking you to verify your details, reset your account or supply any personal details. Emails won't ever contain any "Logon to Internet Banking" links.

 

What Emails From Suncorp Internet Banking Look Like

 

Below is a typical notification email sent from Internet Banking. Notice how no personal details are supplied as well as no links to logon to Internet Banking within the email.

From: onlinebanking.ndr@suncorp.com.au 
Date: xx/xx/xxxx 
Subject: Funds Transfer Receipt 

One of your funds transfers via Suncorp Internet Banking has been successful.

To ensure your security and privacy is maintained, we haven’t included any details in this email.

To view the full details, logon to Internet Banking at suncorpbank.com.au and go to your secure messages. 

If you need any help, just call us on 13 11 75.

Regards,

Suncorp Internet Banking

Please don't reply to this email. This email has been automatically generated by Suncorp Internet Banking. No emails from Suncorp Bank will ever contain links to logon to Internet Banking or validate any details.


 

What to do if you receive a suspicious email

If you receive a suspicious email appearing to have been sent by Suncorp Bank, DON'T click on any links or attachments in the email.

Forward the email to us at security@suncorp.com.au. If you suspect you have responded to a fraudulent email, contact us immediately on 13 11 75.


 

How to Identify a Hoax Email

  • Poor grammar and spelling (although sometimes they can be grammatically perfect!).
  • Links to web addresses that are different to what you would usually expect (although there are ways to make links appear legitimate).
  • Urgent appeals for help or personal details (like credit card or account numbers, PINs or passwords).

Example:

sample fake email


How to Identify a Fake Website

  • Check that the web address of the website looks valid.
  • Become familiar with our Internet Banking website and logon screen. We will only ever ask you to provide your Customer ID, password and token code on the logon screen
  • We will never ask for your External Transfer Password (ETP), or personal details at the 'Logon to Internet Banking' screen.

Examples of Phishing Sites

Example 1 - A logon page that asks for extra information (in this case, your ETP) that you don't need to enter

fake website

Example 2 - A fake page asking for personal details

fake website


Fake Email & Survey Update 15/11/2011

Some customers are receiving emails asking them to click through to a survey (or download one) in order to receive some money into their account. These emails and surveys are fake.

An example of the email and survey are below. If you receive anything like this, please delete it immediately. If you have clicked on the email or have completed the survey, please call us on 13 11 75 immediately.

Fake Email Example:

fake email example

Fake Survey Example:

fake survey example