6 best practices for repo agents to avoid pitfalls of phishing emails
Image by Thapana_Studio / Shutterstock.com
By subscribing, you agree to receive communications from Auto Remarketing and our partners in accordance with our Privacy Policy. We may share your information with select partners and sponsors who may contact you about their products and services. You may unsubscribe at any time.
The technology committee of the American Recovery Association warned repossession agents about how easily an operation can be impacted by phishing email and the collateral damage security breaches can cause.
ARA also gave six recommendations for best practices to avoid the problems because, “modern phishing emails are no longer filled with obvious spelling mistakes. Many are nearly impossible to distinguish from legitimate messages.”
Some common examples the committee mentioned:
—Password expiration notices
—Microsoft 365 login requests
—Google Workspace alerts
—Package delivery notifications
—DocuSign requests
—Invoice notifications
—HR or payroll messages
—Messages appearing to come from lenders or forwarders
—Requests to verify your email account
“The goal is almost always the same: Get you to click,” ARA said.
As not to just present a problem without a possible solution, the committee delved into best practices every agency should adopt to keep phishing schemes from becoming a technology disaster.
Subscribe to Auto Remarketing to stay informed and stay ahead.
By subscribing, you agree to receive communications from Auto Remarketing and our partners in accordance with our Privacy Policy. We may share your information with select partners and sponsors who may contact you about their products and services. You may unsubscribe at any time.
- Slow down before clicking
Never click a link simply because it appears urgent.
Cybercriminals create panic to force quick decisions.
If something feels unusual, stop and verify it first.
- Verify unexpected requests
Do more investigating if someone requests:
—Passwords
—Banking information
—Wire changes
—ACH updates
—Payment changes
—Login verification
Call the sender using a known phone number.
Do not reply directly to the suspicious email.
- Enable multi-factor authentication (MFA)
Every business email account should require MFA.
This is one of the most effective protections available today.
Even if a password is stolen, MFA can prevent unauthorized access.
- Use strong, unique passwords
Never reuse passwords between services.
Use a password manager whenever possible.
- Keep software updated
Updates often contain critical security patches.
This includes:
—Computers
—Mobile devices
—Email applications
—Browsers
—Firewalls
—Routers
- Train every employee
Cybersecurity is not an IT problem. It is a company-wide responsibility.
Anyone who answers email can become the entry point for an attack. Regular discussions and awareness reminders significantly reduce risk.
And if you think your agency infrastructure has been compromised, ARA urged operators to act immediately.
“Do not wait to ‘see what happens,’” the committee said, instead suggesting these steps:
- Disconnect the affected device from the internet if possible.
- Change passwords immediately using a different device.
- Notify your email provider.
- Enable or verify MFA.
- Inform management.
- Review email forwarding rules for unauthorized changes.
- Notify affected customers or business partners if fraudulent messages may have been sent.
- Contact your technology provider or a cybersecurity professional for assistance.
“The faster you respond, the greater your chance of limiting damage,” ARA said.
The ARA technology committee encouraged every member agency to review its cybersecurity practices, educate its employees, and develop a response plan before an incident occurs.
“Preparedness is always less expensive, and far less disruptive, than recovery,” ARA said.
For more information, visit repo.org or call (972) 755-4755.