Security Tips

Stay Safe Online

Protect yourself from online threats with these essential security tips from Hisab Bank.

  • 🛡️ Protect Yourself
  • 🎭 Social Engineering
  • 📧 Email Spoofing
  • 🎣 Phishing
  • 🔑 Passwords
  • 💡 Other Tips

How Can You Protect Yourself?

Use common sense and do not release information that could be used to compromise your personal information. Regardless of the type of information requested, you are advised to:

  • Verify the requestor’s identity by calling back or requesting precise information (e.g., last name, first name, department, direct manager’s name).
  • Assess and determine the reasonableness of the request and ask yourself how critical the information requested is.

If you receive a suspicious e‑mail or SMS message that appears to be from Hisab Bank, please do the following:

  • Do not respond to the message or click on any of its links.
  • Report to the bank immediately via phone number or e‑mail.
📞
Report Suspicious Activity: Call us at 0775 430 30 33 or email erbil.b@hisabbank.com

What is Social Engineering?

“Social Engineering” refers to the practice of manipulating people to circumvent security systems and conduct fraud. This technique involves obtaining information people would not normally reveal to strangers.

Social engineering can take a variety of forms:

  • 📞 Telephone calls impersonating bank officials
  • 📧 E‑mail messages requesting sensitive information
  • 📨 Written mail or fax with fraudulent requests
  • 💬 Instant messaging and social media scams
⚠️
Remember: Hisab Bank will never ask for your password, PIN, or sensitive information via phone, e‑mail, or text message.

E‑Mail Spoofing

E‑mail “spoofing” is when an e‑mail message appears to have originated from one source when it was actually sent from another.

For example: A scammer contacts a company pretending to be a financial institution or vendor, claiming that their bank account number has changed so that subsequent payments will then unknowingly be routed to a fraudulent account.

💡
Protect Yourself: Always verify changes to payment information by calling the sender directly using a phone number you know is legitimate – not the number provided in the suspicious e‑mail.

Beware of Phishing

Phishing is a type of social engineering attack often used to steal user data, including login credentials and credit card numbers. It occurs when an attacker masquerades as a trusted entity.

Phishing messages can come from a growing number of sources, including:

  • 📧 E‑mails that appear to be from your bank
  • 📞 Phone calls from fake customer support
  • 💬 Social media messages and DMs
  • 📱 Text messages (SMS) with suspicious links

Victims can often be tricked into clicking malicious links or opening malicious attachments. Always verify the sender before taking any action.

🔍
Check the Sender: Hover over links before clicking, look for misspellings, and never share your credentials via e‑mail or text.

Passwords & Authentication

Password and authentication methods (e.g., token & one‑time password / OTP) are ways systems verify that you are who you claim to be. If your password is compromised, a person knowing your password can do anything you can do – including transferring funds.

Create and Use Only Strong Passwords

  • Passwords should be strong so that they are not easily guessed or cracked (i.e., at least 12 characters long, with upper/lower case letters, numbers, and special characters).
  • Tip: Hisab Bank’s online banking service supports multi‑factor authentication. Please consider using this security feature that generates a one‑time access code.
  • Use a strong password and OTP for optimal security! Call our Call Center for more information.
🔐
Pro Tip: Never use the same password for multiple accounts. Consider using a password manager to generate and store complex passwords securely.

Other Tips to Safeguard Your Information

  • Only enter credit cards and personal information when it involves a transaction you initiate and only on websites you trust.
  • Always use a secure website when submitting credit card numbers or financial or personal information online.
  • Update your phone number by notifying the bank as soon as you change it to ensure that you receive instant notifications for any transactions conducted on your accounts.

“Secure Websites” Have a Lock Icon:

  • Regularly monitor your account activity to detect fraudulent transactions.
  • Avoid accessing your online banking services in open, public areas like internet cafes.
  • Shred all documents containing personal information, such as bank statements, unused checks, and deposit slips.
📋
Quick Checklist: Use strong passwords • Enable biometric login • Monitor your accounts • Report suspicious activity • Keep your contact details updated.

Security at a Glance

Here are the most important things you can do to stay safe online, summarized for quick reference.

🔑

Use Strong Passwords

At least 12 characters with a mix of letters, numbers, and symbols.

👤

Enable 2FA

Two‑factor authentication adds an extra layer of security to your accounts.

📱

Update Your Apps

Keep your mobile banking app and operating system updated with the latest security patches.

📊

Monitor Your Accounts

Regularly review your transaction history and report any suspicious activity immediately.

Stay Protected

Your security is our priority. If you have any concerns or questions about your account security, please contact us.

Contact Us