Cybercriminals are becoming increasingly sophisticated in the way they target consumers. One of the most common tactics is sending spoofed emails or text messages that appear to come from your financial institution, a merchant, or a government agency. These messages may claim there is a suspicious transaction on your account, provide a shipping update, or warn of an unpaid toll violation or parking ticket.
These messages often use emotional triggers such as urgency, curiosity, or fear to manipulate you and influence your decision-making. They may warn that your account will be locked, your shipment has been delayed, or that you must verify your information immediately to avoid penalties or service interruptions. Others may entice you with refunds, prizes, or exclusive offers. The goal is to get you to react emotionally by clicking a link or providing personal information before verifying that the message is legitimate.
The message may include a link that appears to lead to your financial institutions or the merchant’s website. In reality, the link takes you to a fraudulent website designed to look nearly identical to the legitimate one. If you enter your username, password, account number, or other personal information, it is sent directly to the scammer.
In other cases, after you click on the link or enter information, you may receive a phone call from an individual claiming to be your financial institution, the merchant or government agency. The caller sounds legitimate and may already have some of your personal information which helps build trust. But the caller is just part of the scam.
How to Protect Yourself
- Be skeptical of unexpected emails and text messages. Even if a message appears to come from your financial institution, a trusted merchant, or a government agency, take a moment to verify that it is legitimate before responding or interacting.
- Don’t click links in unsolicited messages. Instead, open your web browser and type the organization’s web address yourself or use the merchant’s official mobile app.
- Never provide sensitive information in response to an email, text message, or unsolicited phone call. This includes your online banking credentials, one-time security codes, debit or credit card PIN, or other personal information.
- Verify requests using a trusted contact method. If you receive a suspicious message or phone call, contact the organization using a phone number from its official website, your account statement, or the back of your debit or credit card – not a phone number provided in the message or displayed on your caller ID, even if it appears to be your financial institution.
- Take your time before acting. Scammers rely on a sense of urgency. A legitimate financial institution, merchant, or government agency will not pressure you into making an immediate decision or threaten you for taking a few minutes to verify a request.
When in Doubt, Contact Us
If you receive an email, text message, or phone call claiming to be from our credit union and you are unsure whether it is legitimate, do not click any links, respond to the message, or provide any personal information.
If you receive an unsolicited phone call shortly after an unexpected email or text message, treat it as part of the same potential scam—even if the caller ID appears to display the credit union’s name or phone number. Scammers can spoof caller ID information to make a call appear legitimate.
Instead, contact us directly using the phone number listed on our official website, your account statement, or the back of your debit or credit card. We will be happy to verify whether a communication is legitimate and help protect your accounts.
Taking a few moments to verify a suspicious communication can help protect your accounts, your personal information, and your peace of mind.
Visit mcfcu.org/security for fraud alerts, prevention tips, and tools to safeguard your accounts.





