top of page

The Catch-22 of Modern Member Communications

  • Writer: John San Filippo
    John San Filippo
  • Jul 20
  • 4 min read

By John San Filippo

 

For credit unions, the challenge of protecting members from fraud has evolved into a frustrating catch-22. As fraudsters become increasingly sophisticated at mimicking legitimate credit union communications, financial institutions are finding it harder than ever to reliably engage with their own members.

 

Jim Stickley
Jim Stickley

With members constantly warned to beware of emails, text messages and phone calls, how can credit unions effectively communicate with their members without creating excessive friction? “This is the million-dollar question,” Jim Stickley, CEO of Stickley on Security and Mahalo Banking, told Finopotamus. He recalled a conversation with a credit union that illustrated this precise dilemma. “They said, ‘It’s really hard because we tell our members we will not call them. We don’t really want to call them, because then we’re teaching them bad habits, but at the same time, there are situations where it seems like we should call.’”

 

This communication breakdown leaves small-to-midsize credit unions incredibly vulnerable, he noted. For a smaller institution, the financial fallout can be devastating. “If you’re a small mom-and-pop credit union—let’s say that you’re $150 million in assets—you’re tiny,” Stickley explained. “You don’t have the resources to weather a big storm. And then you’ve got Reg E, which says you’re supposed to give the money back to anybody that’s a victim. You pay a lot of money before insurance finally kicks in, and these credit unions are just getting absolutely decimated by it.”

 

Anatomy of a Region-Based Spoofing Attack

 

The threat often begins with caller ID spoofing – where a phone’s caller ID displays a credit union’s legitimate phone number – a tactic that has existed for a long time but remains highly effective. While application stores like Google Play and the Apple App Store no longer allow users to download spoofing apps, Stickley claimed that motivated fraudsters can still easily bypass these restrictions by writing and sideloading their own applications.

 

Once equipped, criminals rarely need hyper-targeted data to launch a successful campaign. Instead, they often rely on a regional shotgun approach. Stickley, a San Diego resident, provided an example: “If I’m a criminal and I want to target San Diego County Credit Union, I just do a blast to all 619 area code text numbers. Odds are, there’s going to be a lot of people that have San Diego County Credit Union because they’re in San Diego and it’s a 619 area code. The people that don’t have it ignore it, so they don’t care, and the people that do have it, some of them fall victim.”

 

When fraudsters leave voicemails, they typically display the credit union’s actual number on the caller ID to establish trust but instruct the member to call back via some other toll-free number that routes directly to the criminal’s cell phone. “Please call me back at this direct 800 number so you’ll go right to the fraud department,” Stickley said, mimicking the typical fraud script. “When a person gets that voicemail, they saw it came originally from the credit union, so therefore it must be okay. And the 800 number leads them to believe it must be professional.”

 

The Art of the Social Engineering Dance

 

What makes these modern criminals so dangerous is their extreme patience and professional demeanor. They rarely rush the victim or lead with a blunt request for passwords. Stickley shared an incident where Mahalo Banking COO Denny Howell received a fraudulent text message claiming to be from a credit union (ironically, one that Mahalo partners with). Howell called the number back on speakerphone to observe the fraudster’s methodology.

 

“The guy was so good,” Stickley recalled. “He didn’t just start out by saying, ‘Give me your login, give me your password.’ Instead, he did this whole song and dance about suspicious activity: Did you make this charge? Did you make this charge?”

 

The scammer carefully manipulated the conversation by pretending the account credentials had already been compromised by an outside party. “He’s like, ‘It looks like they started changing some of your credentials. Let me verify something with you. The current login is like D, X, Y, Z, something, something. Was that the login you’ve used in the past?’” When Howell said no, the fraudster seamlessly pivoted: “‘I thought so. It looks like they changed it. What was the login you used before? I’ll change it back for you.’” The criminal used the exact same routine to extract the password.

 

Stickley added that the fraudster was courteous and professional. “I can see how people fall victim because it sounded perfectly legitimate and the guy was so calm. And he was so patient.”

 

Proactive Defense and Automated Chaos

 

Looking ahead, Stickley expects the fraud landscape to be dominated by automation and artificial intelligence. AI prompts are replacing manual hacking, enabling bad actors who lack coding skills or English fluency to spin up sophisticated malware, automated voice recognition systems, and localized text campaigns.

 

“All of it’s just automated. All of it’s done through AI. That’s your future,” Stickley warned. “And they’re not just spoofing phone numbers anymore; they’re spoofing voices,” warned Stickley. “When you spoof the voice of an actual employees, you can have one employee thinking they’re talking to another employee and it won’t even be them. The future’s chaos.”

 

According to Stickley, the safest approach for members is to be suspicious of all incoming communications, regardless of medium. “The safest rule of thumb for a member is to hang up, pull out their debit or credit card, and call the trusted member service number printed directly on the back of the plastic,” he advised.

 

For credit unions, building safety habits requires shifting away from embedding direct callback numbers or links in text alerts. If an institution must call a member, Stickley recommends instructing the member to call the main line and use a specific internal extension. “Yes, it’s an extra step – it’s extra work – but at least it’s being done securely,” Stickley said.

 

Furthermore, digital banking platforms are moving toward proactive, zero-trust containment strategies, Stickley said. He highlighted a new fraud prevention tool called TrueMember that Mahalo is rolling out where suspected accounts are automatically placed into a restricted “safe mode” sandbox rather than a hard lockout. This allows the user to safely view histories and transfer funds internally but blocks external money movement entirely. “A criminal gets put in the sandbox that just freaks them out, and there’s nothing they can do about it,” Stickley said. “It doesn’t matter how much the member gives up their information, the fraudster still can’t do anything. They’re stuck in the box.”

 
 
bottom of page