The technology committee of the American Recovery Association warned repossession agents about how easily an operation can be impacted by phishing email and the collateral damage security breaches can cause.

ARA also gave six recommendations for best practices to avoid the problems because, “modern phishing emails are no longer filled with obvious spelling mistakes. Many are nearly impossible to distinguish from legitimate messages.”

Some common examples the committee mentioned:

—Password expiration notices
—Microsoft 365 login requests
—Google Workspace alerts
—Package delivery notifications
—DocuSign requests
—Invoice notifications
—HR or payroll messages
—Messages appearing to come from lenders or forwarders
—Requests to verify your email account

“The goal is almost always the same: Get you to click,” ARA said.

As not to just present a problem without a possible solution, the committee delved into best practices every agency should adopt to keep phishing schemes from becoming a technology disaster.

  1. Slow down before clicking

Never click a link simply because it appears urgent.

Cybercriminals create panic to force quick decisions.

If something feels unusual, stop and verify it first.

  1. Verify unexpected requests

Do more investigating if someone requests:

—Passwords
—Banking information
—Wire changes
—ACH updates
—Payment changes
—Login verification

Call the sender using a known phone number.

Do not reply directly to the suspicious email.

  1. Enable multi-factor authentication (MFA)

Every business email account should require MFA.

This is one of the most effective protections available today.

Even if a password is stolen, MFA can prevent unauthorized access.

  1. Use strong, unique passwords

Never reuse passwords between services.

Use a password manager whenever possible.

  1. Keep software updated

Updates often contain critical security patches.

This includes:

—Computers
—Mobile devices
—Email applications
—Browsers
—Firewalls
—Routers

  1. Train every employee

Cybersecurity is not an IT problem. It is a company-wide responsibility.

Anyone who answers email can become the entry point for an attack. Regular discussions and awareness reminders significantly reduce risk.

And if you think your agency infrastructure has been compromised, ARA urged operators to act immediately.

“Do not wait to ‘see what happens,’” the committee said, instead suggesting these steps:

  1. Disconnect the affected device from the internet if possible.
  2. Change passwords immediately using a different device.
  3. Notify your email provider.
  4. Enable or verify MFA.
  5. Inform management.
  6. Review email forwarding rules for unauthorized changes.
  7. Notify affected customers or business partners if fraudulent messages may have been sent.
  8. Contact your technology provider or a cybersecurity professional for assistance.

“The faster you respond, the greater your chance of limiting damage,” ARA said.

The ARA technology committee encouraged every member agency to review its cybersecurity practices, educate its employees, and develop a response plan before an incident occurs.

“Preparedness is always less expensive, and far less disruptive, than recovery,” ARA said.

For more information, visit repo.org or call (972) 755-4755.