Fraud, phishing, and malware

Phishing is a type of fraud that uses phone calls or deceptive messages to steal sensitive personal information, such as access codes or payment card details. These tactics are increasingly sophisticated and can mimic the design and content of official websites, as well as infiltrate communication channels like SMS, email, phone calls, or WhatsApp.

Malware are programs that capture the codes a user types or alter the behavior of the browser they are using. That’s why it’s essential not to install uncertified Apps, avoid clicking on suspicious links, and always install the latest operating system updates.

phishing 1 (3)

How to recognize them: mobile

  • A phishing message may appear among the official ones sent by us, don’t rely on this alone.
  • These messages usually contain a link they urge you to click on.
  • They often use a sense of urgency and ask you to verify your identity, update your credentials, or warn you about suspicious activity or technical issues.
  • There may be inaccuracies, spelling mistakes, or punctuation errors.

 

Remember: we will NEVER ask you, on any channel, to share your personal codes, open suspicious links, or install any App other than the official one!

document_0 (3)

How to recognize them: desktop

  • Fake websites often look very similar to official ones, but they ask for different information than usual.
  • Your browser may warn you that the connection is not secure, using an icon or a label before the address.
  • The URL, the web address of the page, might include the bank’s name, but not exactly match the official one.
  • The “https” label is important, as it indicates that the security protocol is up to date.

Remember: we will NEVER ask you, on any channel, to share your personal codes, open suspicious links, or install any App other than the official one!

3 (4)

AI in fraud

The evolution of artificial intelligence has led to the spread of new, increasingly sophisticated forms of online fraud that are harder to detect. Cybercriminals use advanced techniques to manipulate documents, create fake identities, and deceive users. Some examples include:

  • Deepfakes: fake videos or audio recordings that imitate real people
  • Document forgery: manipulation of payslips, tax returns, or bank statements
  • Identity theft and creation of fake identities: use of stolen or fabricated personal data
  • Advanced phishing: emails or messages that appear to come from trusted sources

To protect yourself, always verify the authenticity of any request, keep your devices up to date, and enable two-factor authentication whenever possible.

Remember: we will NEVER ask you to share sensitive information via email, SMS, or unsolicited phone calls. If you have any doubts or suspicions, contact our customer service immediately.

What can you do to protect yourself?

We use all the tools necessary to offer you maximum security, in compliance with current regulations (e.g. PSD2). Also, remember: the best thing you can do if you receive a suspicious message or call is not to react at all, that way, you avoid any risk. Other measures you can take:

Don’t click on links

Ignore any links in suspicious messages that try to redirect you to other websites.

Be cautious

Sometimes, fraudsters’ SMS or emails may appear to come from Tinaba or Banca Profilo. But you’ll never find clickable links in our official communications. If you have any doubts about the authenticity of a message, don’t hesitate to contact our official customer service at 800.694.950.

Don’t share your information

Whether it’s security codes or other personal details, never share them with third parties.

Don’t share your information

Remember: we will never contact you, on any channel, to ask for: – Secret codes – Your card details – PIN and/or SMS PIN – OTP codes – To enter your personal account or card information outside the official App or website

Pay attention to communications

Always check the sender and carefully read the content of any messages you receive.

Pay attention to communications

The sender’s name might look very similar to the official one, but contain small inconsistencies (e.g. TiNABA). As for the content, these messages often use an urgent tone and pressure you to quickly provide personal information. They may also include inaccuracies, spelling mistakes, or punctuation errors.

Use only the official App and website

This helps you avoid entering your data on fake interfaces and prevents anyone from remotely accessing your device.

Use only the official App and website

Before logging in or entering your codes, always make sure you are on https://tinaba.bancaprofilo.it/ or using the official App. When you’re done, always log out to prevent unauthorized access to your account.

What if you’ve been targeted by an attack?

If it’s too late to follow prevention best practices, there are still some actions you can take to protect yourself:

REPORT

REPORT

Contact the relevant authorities or our customer service at 800.694.950 or via WhatsApp.

UPDATE

UPDATE

In the App, under Settings > Security, you can change your access code and device PIN.

BLOCK

BLOCK

Request to block your card: Contact Nexi for your Prepaid Card* or American Express for your Credit Card**.

*Nexi support from Italy: 800 15 16 16
*Nexi support from aborad: +39 02 3498 0020
**American Express support: 06 72 900 347