Navigate to main page content
PrivateBusiness

Secure banking

How to safe and secure while using online services?

  • Learn about 6 most common fraud scenarios bad-actors are using to trick businesses.
  • Get to know fraud techniques to be able to recognize it instantly.
  • Never disclose bank log in information to anyone.
  • Make sure that bank admin roles in your organization are up to date.
  • Follow bank recommendations how to protect your organization from fraudsters.

6 most common fraud scenarios

Fraudsters use various methods and channels to try to trick you out of money. Take a look at how the most common corporate scams work and how you can protect your organization from falling a victim to a cybercrime.

1. Internet bank fraud

Read more

2. False invoices

Read more

3. Business Email Compromise fraud (BEC) fraud

Read more

4. CEO fraud

Read more

5. Phishing emails

Read more

6. Email attachments

Read more

1. Internet bank fraud

How it works?

  • It looks like you are contacted by Swedbank via phone call, e-mail, or SMS.
  • Reason for contacting is usually something urgent related to your account, for example to block some wrong transfer.
  • Through an e-mail or SMS you are directed to a site that looks like the Internet Bank login screen. In a call you are asked for your Internet Bank User ID, PIN-codes or card numbers.
  • After you have provided the information or entered your login details, your account is taken over by fraudsters, and all your money is transferred to the fraudster’s account.

How to avoid?

  • Never share bank details (User ID, card information or PIN-codes) anywhere. The bank will never ask you for those!
  • Do not download any attachments from e-mails. Check that e-mails from the bank end with @swedbank.ee.

2. False invoices

How it works?

  • Fraudsters would send you a fake invoice. These types of invoices are more likely to be disguised as payments for advertising, membership fees, or software subscriptions.
  • Sometimes fraudsters mimic the existing suppliers with familiar sounding names.
  • The aforementioned examples are usually asking to pay amounts of money that would not draw the attention, because they don’t seem to be substantial.
  • Bear in mind, that after the payment is executed it is nearly impossible to trance back the fraudsters and get the funds back.

How to avoid?

  • Check every single invoice with the counterparties at your organization responsible for the budget line.
  • Background checks won’t probably work because fraudsters mimic real companies.

3. Business Email Compromise fraud (BEC) fraud

How it works?

  • A bookkeeper receives an email from an employee or partner, that their bank account number has changed and from now on salary or financial obligations should be transferred to the new one.
  • The new bank account is under fraudsters control and usually banks are used where the beneficiary's name and account number conformity are not checked upon receipt of money.
  • This might be that the fraudsters have gained the access to the mail server and took over the email accounts of the persons in question.

How to avoid?

  • If you are asked to make a swap the bank account number, try to reach out to the person who made such request over the phone (not the one you see in an email) and ask for the legitimacy of the request. If you still have doubts, do not proceed with the change.
  • Report the money transfer request to your bank, this will help to protect other organizations.

4. CEO fraud

How it works?

  • The member of a senior management sends you an email asking to make a money transfer to some account urgently.
  • You are asked to transfer money to a bank account in another country. Often to a person, not a company.

How to avoid it?

  • If you are asked to make a money transfer by your manager while he or she is on vacation, and supplier is not one of your regulars, try to reach out to the person who made such request over the phone (not the one you see in an email) and ask for the legitimacy of the request. If you still have doubts, do not proceed with the transfer.
  • Report the money transfer request to your bank, this will help to protect other organizations.

5. Phishing emails

How it works?

  • You receive an e-mail claiming that your bank account has been compromised, or that your company is being audited and inviting you to click on a link to find out more.
  • Clicking on the link inside the email takes you to a website that is often an exact copy of the legitimate site
  • When you enter your credentials to the faux website, scammer does enter the details to the real one and gains the access to your bank account.

How to avoid?

  • Make sure your firewalls, anti-virus are up to date, and you operate only using a safe connection (your VPN is turned on when you are working from home).
  • Check the legitimacy of an email address of a sender. Fraudsters tend to mimic real email addresses. An example of such email would be: alerts@sweedbank.lt
  • Fraudsters always tend to trigger the emotion and urgency. Never click on a links provided in emails alike. You can always check your bank statement by visiting your bank internet page directly, or at least hover with your cursor on a link to see what the actual URL is behind.
  • Report the phishing attempt to your bank or an institution fraudster was pretending to be. Inform your IT and your colleagues about the attempt.
  • Fraudsters might initiate transactions as a result. Never approve an operation if you are not 100% sure you initiated it.

6. Email attachments

What are they?

  • You get an email from your colleague, or supplier. This email contains the attachment.
  • You open the attachment, or a link leading to one, and malicious cod gets executed on your device in a background.

Now the fraudster can collect information you enter into your browser or encrypt files on your device and/or server asking for a ransom to get the encryption key.

How to avoid?

  • Check the legitimacy of an email address of a sender. Fraudsters tend to mimic real email addresses. If you get an email from a colleague whom you barely know, do not open the attachment.
  • Make sure your firewalls, anti-virus are up to date, and you operate only using a safe connection (your VPN is turned on when you are working from home).
  • If you have opened the file anyway, and it asks you to enable macros, deny the request, close the file.
  • Report the phishing attempt to your IT and your colleagues.
  • Fraudsters might initiate transactions as a result. Never approve an operation if you are not 100% sure you initiated it.
  • You shouldn’t confirm transactions or logins to internet bank or app, which are not initiated by you under any circumstances. Be extremely cautious if you are being contacted by a person introducing themselves as a bank representative asking you aforementioned bank the credentials.
  • Do not click on any links you get on emails, messaging apps or text messages. Do not comply with any requests asking you to provide internet bank log in or corporate bank card credentials.
  • If you have any doubts, do not rush into action, and dismiss all the actions.

Get in touch with us on +370 5 268 4422 if:

  • You notice suspicious transactions on your bank account.
  • You suspect that the third parties might have got or attempted to get the access to your corporate internet banking and/or corporate card details.
  • Get your bank card blocked. This can easily be done on “Swedbank” app or on the internet bank. Log in to your app, chose the menu tab “Cards” and click on an icon of a card you wish to get blocked. Wen you do so, simple slide right on “Block the card”. Alternatively log in to your internet bank, chose a menu tab called “Cards”, “Card management”. Chose the card you aim to block and perform the action.
  • Report the security issues. If you noticed suspicious activity, and you think that this might be a security issue, let us know.
  • You shouldn’t confirm transactions or logins to internet bank or app, which are not initiated by you under no circumstances.
  • You shouldn’t ever disclose your personal data or data used for login to internet bank & app to other persons, including family members, friends or bank employees, unless you are calling to the bank.
  • Do not write down, send by e-mail, SMS, etc. or otherwise save any confidential codes and passwords to unlock the screen of your computer or mobile phone. Create complex passwords, that are difficult to guess, memorise them and change them regularly. When creating PIN codes, be sure to make PIN codes in random number combination. Do not use combinations, such as 1111, 1234, dates of birth other personal details etc.
  • Remember that your User ID number is as important as your personal code, thus pay a great deal of attention to its security.
  • Keep in mind that after login you will have access to many services including external ones which do not require additional authentication.

We will also automatically block access to Internet Bank if incorrect login data (User ID or code from the PIN code generator) is entered 5 times in a row.

You can unblock it by calling us at +370 5 268 4422 (workdays only 8:00 to 18:00). In case of a repeated block, you will have to visit the bank’s branch. You should book a visit in advance. Have you discovered any unauthorised transactions on your account performed prior to the blocking of Internet Bank access? Review your account statement and submit the information to us.

The login session is terminated when no activity happens for 5 minutes. You will be asked to re-enter your login details. Time limits are used for security reasons, to prevent Internet Bank access if a user forgets to log off from his/her account after finishing using the Internet Bank.

Once you finish Internet Bank session, log off (by clicking 'Logoff') and close the browser.

The login session is terminated when no activity happens for 5 minutes. You will be asked to re-enter your login details. Time limits are used for security reasons, to prevent Internet Bank access if a user forgets to log off from his/her account after finishing using the Internet Bank.

Once you finish Internet Bank session, log off (by clicking 'Logoff') and close the browser.

Address of the Internet Bank website

On the computer:

By clicking on the lock sign you should see the correct Swedbank certificate:

On the smart device:

Before entering your login data, make sure that the website domain is “swedbank.lt”.

When accessing internet bank via a laptop or stationary computer, follow these safety measures:

  • Install antivirus software and configure it to automatic update of the virus definitions database (at least one auto-update per day).
  • Install the local firewall. It should be configured so that it prevents connections from the Internet to your computer.
  • Use the latest browser and operating system available.
  • Turn on automatic updates for all software. If it cannot be updated automatically, regularly check on its latest software.
  • Set your browser to block pop-ups.
  • Make sure you are using antivirus software that automatically updates the threat library at least once a day.
  • Use the firewall, that does not allow to log in to your computer remotely.
  • Make sure your Operational System and browser are up-to-date.
  • Turn on automatic updates of your software. If automatic updates are not possible you should check for then on a regular basis.
  • Set your browser to block the pop-ups.

Information on the ways to secure your device and to safely use other Internet services is available on the following website:

https://www.esaugumas.lt/lt

  • Download applications only from trusted sources such as the App Store, Google Play or Windows Phone Apps – Microsoft store.
  • Do not allow other persons to use your phone or tablet were Swedbank App is installed.
  • Do not reveal the screen lock codes to other persons and do not allow to unlock your phone with other persons’ biometric data.
  • Use antivirus software.
  • Always adhere to the requirements or security alerts of the manufacturer of your phone device.

What are safe browsers?

We encourage you to update your browser and operating system version as soon as update is released. These updates can be set up automatically for better security and experience in our digital channels. We officially support these browser versions:

  • Google Chrome 85 and later;
  • Microsoft Edge 85 and later;
  • Mozilla Firefox 80 and later;
  • Safari 14 and later.

What else should you know about security?

  • Do not share your personal authentication means. If you want to give your family members or your employees rights to manage funds on your accounts, please, request the Bank to grant them respective rights. They will be able to use company’s accounts on behalf of their own and by using their own personal authentication means. You can revoke these rights at any time. It is also possible to order a supplementary card linked to your account for a family member to use. Sharing the same authentication mean between the employees or family members is strictly forbidden.
  • Remember, that security of all your data (User ID, PIN codes, mobile phone number provided to the bank, personal number, etc.) is the key for protecting an access to your money.
  • If you’re using a public computer, avoid entering personal information as there might be malware that records your details.
  • Do not keep User ID number together with authentication means and their confidential codes.
  • Never send authentication data by email.
  • Never disclose your login information, unless you are initiating the call with the bank. No one has the right to request you to provide your personal number and authentication mean by phone. If you receive a call from a person stating he is an employee of the bank, end the conversation immediately.
  • Your Smart-ID or PIN code generator PINs should not coincide with any part of your phone number or the sequence of numbers.
  • Always compare control number and read “see what you sign” if available.
  • By entering PIN2 of Smart-ID you are usually confirming a payment or an agreement. Be extra careful when doing it.
  • You will get an SMS when new Smart ID account is created. Contact bank immediately if it wasn’t you who created Smart ID.

When shopping online, be prudent with your personal and financial data. Properly assess the threats, which you may encounter on the internet. We recommend to ensure protection of personal devices and always follow these safety tips:

  • Shop in reliable shops only. It is always safe to buy goods and services in well-known Lithuanian and foreign e-shops with a good reputation. Take a critical approach to unknown sellers and try to find out more information about their activity. Study public internet feedback about a specific online shop. Find out whether the website presents detailed contact data of its administrator (address, phone, email, etc.), and make sure it does not contain various errors in their links (additional words or letters, strange symbols), popup windows, advertisings, a great number of links instead of informative content.
  • Be cautious about discounts. You have found a high-quality product offered at a particularly low price? Before making a payment order, be sure that the company that offers the product really exists and is trustworthy. Be careful about advertisements in social networks. They may lead you to a fake online shop.
  • Safe shopping by card. When shopping in foreign e-shops, the most common way of payment is by card. In this case you will have to indicate the details of your payment card. If an online shop participates in international security programmes, special logos such as “MasterCard SecureCode”, and “Verified by Visa” for Visa cards are used in this shop. You may be redirected to internet bank to confirm payment transaction by logging in. Learn more about “Safe online shopping” programme here. Before making payment in online shop, please evaluate safety of such online shop and study public internet feedback about its activity.
  • Safe payment via electronic banking system. When shopping in Lithuanian online shops, usually you will be redirected to Swedbank internet bank account. You will recognise it from the Swedbank logo and internet bank address: https://www.swedbank.lt/banklink confirms that payment is made directly through the bank system. After you enter your login details, the website will automatically display the generated payment form.
  • Third party providers. As of 14/09/2019, when you shop online, you might be offered to use payment initiation service, offered by payment institution (PISP), other than the bank, to pay for goods or services. If you choose to initiate payment from your account, kept with the bank, you might be asked to fill in the payment order form in the PISP’s environment, and give your consent to transfer data, necessary for performance of payment transaction, and later to confirm payment order with the Swedbank internet bank authentication mean. If you have noticed any transaction in the account statement, not authorised by you, inform us immediately by calling 1844 (for private clients) or 1633 (for business clients).

It is important for us at Swedbank that our customers can feel safe and secure when managing their monetary affairs with our electronic channels. Therefore, we seek to ensure the highest security level in IT systems. Despite this, an error may slip by. If you have found a security flaw, we would like to hear more about it to be able to correct the problem as soon as possible.

How do you report?

Send an email to us in your local language at responsible-disclosure@swedbank.com. Optionally, you can use our public PGP key to protect the information you send over. Make sure to have included the following information:

  • Detailed description of the vulnerability containing such info as URL and type of vulnerability;
  • The necessary information that we need in order to reproduce the problem;
  • If applicable, a screenshot of the vulnerability you have found;
  • Contact information, name and surname, email, phone number, and your public PGP key (if you have one).

This personal data submitted by you will be processed by Swedbank in order to inform you about the analysis of IT security flaws noticed by you and their correction, and, if necessary, to contact you regarding the revision of the information submitted by you. More information about Swedbank’s data processing procedure is available in the Swedbank Principles of Processing Personal Data.

What can you report?

You can report security flaws that you have found in any of our services. Examples of security flaws are cross-site scripting, flaws in encryption or flaws with security implications in logic controls. The reporting service is not designated for other logical errors, errors in texts, questions about our services, questions about the security of our services or similar.

What can you expect from Swedbank?

We will confirm that we have received your description, continuously keep you updated while we process the issue, and inform you when the issue is fixed. Claims for compensation as a condition for sending in a vulnerability are not accepted.

What is required from you?

It is important for both us and our clients that you follow good practice, i.e. that:

  • You do not use the vulnerability to access or attempt to access information that does not belong to you;
  • You do not use the vulnerability to remove or modify information;
  • You do not affect the availability of our services;
  • You give us an opportunity to fix the reported vulnerability before going public with it.

Can you file a report anonymously?

Yes, but then we cannot respond back and keep you updated on the status.

PGP key

Use this PGP key if you want to send us an encrypted e-mail. But using it is not required.

Key ID: 0x0AD6CCAF

Control code: 2D14 4030 6D4B 68C3 F286 3AC6 333B E8E4 0AD6 CCAF

Swedbank logo

Jūsų Internet Explorer naršyklė nebepalaikoma.

Prašome naudoti Google Chrome, Mozilla Firefox ar Microsoft Edge naršykles.

Nuo 2021 03 23 nebebus galima jungtis prie „Swedbank“ interneto banko naudojantis naršykle „Internet Explorer“.

Taip pat nebebus galima tvirtinti ar vykdyti mokėjimų iš „Swedbank“ kituose tinklalapiuose naudojantis „Internet Explorer“.

Siūlome Jums naudotis naršyklėmis „Google Chrome“, „Mozilla Firefox“ ar naujausia „Microsoft Edge“ versija. Norėdami sužinoti, kaip įdiegti naršykles spauskite čia.

С 23.03.2021 Интернет-банк Swedbank недоступен в браузере Internet Explorer.

С помощью Internet Explorer невозможно авторизоваться или осуществлять платежи через Swedbank на сторонних веб-страницах.

Вместо браузера Internet Explorer мы рекомендуем использовать браузеры Google Chrome, Mozilla Firefox или Microsoft Edge. Инструкции по установке упомянутых браузеров можно найти здесь.

From 23.03.2021 Swedbank Internet Bank and Banklink is no longer available using Internet Explorer browser.

It is not possible to authorize or make payments from Swedbank on other web pages using Internet Explorer.

Instead, we suggest using Google Chrome, Mozilla Firefox or the newest version of Microsoft Edge. To find out how to install the suggested browsers, please click here.

Swedbank
  • Jūsų įrenginio operacinė sistema ir interneto naršyklė yra pasenusi ir nėra palaikoma Swedbank interneto banke. Prašome atnaujinti operacinę sistemą bei interneto naršyklę arba kreiptis į IT specialistus techninės pagalbos.
  • The operating system of your device & your browser are too outdated to be supported by Swedbank Internet Bank. Please, update the operating system & browser or turn to IT specialist for technical help.
  • Ваш браузер или операционная система недостаточно современны для использования в интернет банке Swedbank. Пожалуйста обновите операционную систему и браузер или обратитесь за технической помощью к ИТ специалисту.

Thank you for the visit!

We hope that Internet bank measured up to your expectations. If you have any comments or proposals, please send them to verslas@swedbank.lt

For security reasons, please close the browser window!

Как защитить свои деньги от мошенников?

  • Никогда никому не называйте свой номер пользователя, PIN-коды и информацию по карте.
  • Ни в коем случае не подтверждайте операции или попытку авторизации, которые не инициировали вы сами.
Подробнее