Skip to main content

Audience:

Operators

Fraud obligations

Fraud attacks grow more complex every day. It's important to know how Swan works to keep you and your users safe, as well as how to prevent, react to, and report suspicions of fraud.

Review the page covering common types of fraud to understand the types of fraud your users might face.

Trust Center

Visit Swan's Trust Center for live information about Swan's security. Understand security measures in depth, review policies, and find answers to frequent security questions.

Swan protects you and your users

Your protection is Swan's priority. Consider the following ways Swan strives to keep you and your users safe.

AreaProtection
Contact with your usersSwan never calls your users unexpectedly. If a user receives an unplanned phone call from Swan, strongly encourage them to hang up, then inform you and Swan immediately.
To keep communication with you and your users secure, Swan prefers that both you and your users open tickets instead of emailing Support. The partner and end-user support forms initiate a secure way to communicate about sensitive topics.
Swan might ask your user to verify their name or phone number to confirm their identity. Any other requests for sensitive or account information occur through secure tickets and exclusively for valid reasons, such as an enhanced transaction review.
PaymentsSwan offers single-use virtual cards (SUVs). Consider prioritizing issuing SUVs as it's more difficult to use them fraudulently.
You and your users can save trusted beneficiaries. Only eligible account members can send credit transfers to unsaved beneficiaries.
When making online payments, you and your users must complete 3-D Secure (3DS), an extra security layer when paying online. Please note that Mastercard might bypass 3DS if they decide a payment is low risk.
Authentication and ConsentTo access Swan platforms, you and your users must log in. If there's no activity for a set time period, you're automatically logged out to ensure the security of your account.
Swan uses a mix of biometrics, passcodes, and one-time passwords to secure access to Swan platforms.
You and your users must consent to all sensitive operations.
One time every 24 hours, your users are required to acknowledge a fraud warning before consenting to a transfer.

You, your users, and Swan each have a direct relationship due to the three-party partnership model. As a result, Swan contacts your users directly, when necessary, respecting strict privacy guidelines.

Managing fraud

For your users

The Swan Support Center includes several articles written for your users to help them reinforce their safety online. The information mirrors the information shared here, but it's adjusted for the end-user experience. Each article also includes how to report fraud.

Prevent

Preventing fraud is a critical responsibility shared by you, your users, and Swan. Follow these tips to strengthen your product integration and help your users avoid falling victim to fraud.

🧠 Know what fraud looks like.

Fraud often looks close to the real thing, but not quite. Any time a communication feels suspicious, evaluate it closely, applying the actions described in this section.

Learn about different types of fraud and how they're attempted. Review the page covering common types of fraud, and stay informed about new ways fraudulent individuals are trying to trick people.

⏳ Don't respond urgently.

Fraudulent individuals try to pressure you and your users into believing that their request is urgent and must happen immediately. Don't fall for it. Instead, follow established processes. Don't let fraudulent individuals convince you to bypass processes due to urgency.

💬 Use a secondary communication channel.

If you're concerned about a request, it's never a bad idea to confirm with the person or organization who sent the request in another way. Don't hesitate to contact them through another communication channel.

If they called you, email them. If they emailed you, call or text them. You could also contact them on a social media platform you know they use and control.

🔎 Double-check.

If a request feels suspicious, it never hurts to double-check. Check for typos or errors in names, websites, email addresses, and messages.

Fraudulent websites often make small changes to the URL to appear legitimate. You can easily miss these changes.

  • Check for missing letters, especially in site names. For example, swn.io instead of swan.io.
  • Identify lookalike letters or characters, such as a lowercase “l” instead of an uppercase “I”, or a “0” instead of an “O”. For example, swan.i0 instead of swan.io.
  • Check for extra characters, such as hyphens or added symbols in domain names. For example, sw-an.io or swan-io.com instead of swan.io.
  • Spot incorrect domain endings. Look for an incorrect suffix, such as .com or .org, in place of the correct .io. For example, swan.com instead of swan.io.
Check the URL

When requests include a link, always check the full URL character by character. Before you open the link, hover over it and look at the bottom of your screen to make sure it's real and safe. If you're unsure, open a new tab or window and search for the website yourself instead of using the provided link.

If you receive a phone call, consider whether it sounds authentic.

🔐 Protect account information.

You and your users have a lot of control around protecting your account information. Use unique passwords and passcodes every time. Store them in a secure password manager.

Consider making multi-factor authentication (MFA) or two-factor authentication (2FA) mandatory for your product, and activate it for personal use for any app you can. Help your users understand that activating MFA or 2FA is like adding a second lock to a door, for which the key is a one-time password texted to you or a code from a secure app. While MFA and 2FA add an extra step to logging in, they increase online safety significantly.

Pairing strong password hygiene with MFA or 2FA keeps your information much safer.

Never share login information using insecure channels, like text message or email. If you need to share login information with someone you trust, use your password manager's built-in sharing feature.

☑️ Stay up-to-date

Keep the software on your computers, phones, and other devices up to date. Software providers regularly improve built-in safety measures, so take the time to install updates.

Review Swan's Changelog regularly and update your integration accordingly so your product remains secure.

note

Putting these tips into practice can help you and your users to prevent fraud as online fraudulent activity becomes increasingly prevalent.

React

If you or your users suspect fraud, please react immediately. Remember, Swan never contacts you or your users to transfer money outside of established Support channels. As a Swan Partner, you also shouldn't contact your users to transfer money.

Communication channels

If a request feels urgent, your users should contact the requester using a second, previously known communication channel. For example, if your user receives an email request, they should call the requester using a phone number they already have, not a phone number provided in the original email.

Swan invites you and your users to be SAFE, not sorry (borrowing from the Yale University Information Security Office). Encourage the following behavior from your users, and practice it yourselves.

ActionExplanation
S
See something suspicious?
Pay attention to how you feel about a request, and encourage your users to pay attention, too.

  • Do you feel fearful or scared?
  • Is the requester pressuring you to act urgently or quickly?
  • Does the request feel questionable or suspicious?
If the answer to any of these questions is yes, take a step back before responding. Trust how you feel.
A
Act quickly
Report the incident to Swan right away. Don't wait, don't be embarrassed, and don't let someone talk you out of your gut feeling about the incident.

However, don't respond quickly to the request. Wait to transfer funds or provide information until it's confirmed to be a legitimate request.
F
Follow instructions
Provide Swan with all requested information as quickly as possible. Stay actively responsive as Swan follows up on the incident.
E
Exercise discretion
Stay cautious until you know the account is secure. Reset passcodes, limit account membership permissions, and do anything else you feel might protect you until the incident is resolved.

Report

If your users are victims of fraud with their Swan payment accounts, they must file a fraud dispute with Swan. You can also alert Swan to suspected fraudulent activity.

Critical

Reporting fraud to Swan is urgent and mandatory.

Swan processes fraud disputes based on criticality. All fraud disputes are analyzed, but they're not all accepted. Swan responds as quickly as possible.

Share the dedicated Support Center article to help your users file their fraud dispute:

Common types of fraud

The common types of fraud introduced on this page can impact individuals and companies, leading to damaged reputations, financial loss, and wasted time for you, your users, and Swan.

While the potential types of fraud seem endless, this page explains certain types to which Swan users might be more vulnerable. Please review this page thoroughly, including the tips to combat each type of fraud. Additionally, review the fraud protection guidance above, covering how Swan protects you and your users and how to prevent, react to, and report fraud.

Account takeover (ATO)

ATO fraud occurs when fraudsters gain control of a victim's payment account and use it to perform unauthorized actions.

Tips to combat ATO fraud
  • Keep account login information secure.
  • Use strong, unique passwords and passcodes.
  • Don't share account details by email, phone call, or text message.
  • Set up multi-factor authentication (MFA) or two-factor authentication (2FA) as an extra layer of security in case credentials are compromised.
  • Only access the account from trusted and secure networks.

Card

Those committing card fraud steal virtual card details, such as card numbers and card verification values or codes (CVVs or CVCs), or actual physical cards. Then, they use that information to make payments online or by phone, where the purchaser's physical card or presence isn't required.

Types of card fraud include remote purchase fraud, card-not-present (CNP) fraud, and any activity with lost, stolen, or misplaced cards.

Tips to combat card fraud
  • Only enter card details on websites with a secure connection.
  • Only enter card numbers and security codes into fields designed for those numbers. Don't enter card details in free-text fields, which are open for any type of text input.
  • Block (cancel) lost or stolen cards immediately. If you use Swan's Web Banking, send your users the Support Center article about blocking cards.
  • Prioritize issuing single-use virtual cards for non-recurring online payments. These cards are more difficult to use fraudulently.

Chief Executive Officer (CEO)

CEO fraud is a cybercrime where individuals impersonate a company's CEO or other top executives. It's a type of business email compromise (BEC) that results in authorized push payment (APP) fraud.

These individuals send convincing emails to company employees. The emails appear to require immediate, urgent attention. In the email, they might ask the employee to transfer funds, provide access to secure portals or documents, or otherwise reveal confidential information about the company.

Consider the following example of a CEO phishing attack:

Subject: Urgent financial matter (confidential)

Hi Alex,

There's been an urgent development, and we need to pay an invoice immediately. I'm in a critical meeting and can't send this transaction myself. Could you please handle it right away?

includes transfer details

Let me know when it's done.

Thanks,
Jules
CEO, MyBrand

Tips to combat CEO fraud
  • Confirm the email address. Is there a spelling error or typo in the executive's name? Are there extra characters, letters, or numbers in the domain name?
  • If you've received other emails from this executive, does this email look like the others? Are there slight differences in style, spacing, and voice?
  • Even when a request comes from an executive, never bypass established security measures.
  • Contact the executive using another established channel. If you received an email, for example, try calling them or sending them a direct message on the company's messaging platform.

Invoice and billing

Invoice and billing fraud involves the use of fake invoices to trick companies.

Fraudulent individuals might send companies fake invoices that appear to be from the company's regular suppliers. These invoices often look authentic, complete with logos and other details. However, the bank account details included on the invoice belong to the fraudulent individuals rather than a legitimate supplier.

Tips to combat invoice and billing fraud
  • Establish and respect rigorous processes, including purchase verification systems, payment validation processes, transaction verification methods, and more.
  • Regularly verify supplier credentials.
  • Maintain strong, direct lines of communication with suppliers and contact them directly in case of suspicion.

Phishing, vishing, and smishing

Phishing, vishing, and smishing involve fraudulent individuals impersonating legitimate organizations, such as companies or governmental agencies, contacting you by email, phone, or text message. All three are types of authorized push payment (APP) fraud.

  • Phishing → email
  • Vishing → phone call
  • Smishing → text message

They attempt to steal sensitive information, including user names and passwords, government ID numbers, financial information, and more. These emails, phone calls, and text messages can be quite convincing. For example, email and text messages often link to websites that look almost identical to an organization's real website.

Tips to combat phishing, vishing, and smishing fraud
  • Don't provide information or funds urgently.
  • Contact the organization directly. Use a different communication channel to ask them about the suspicious message. For example, if they contacted you by phone, send an email. If you received a text message, call them.
  • Check links before you open them. Fraudulent websites often use small URL changes to impersonate legitimate sites. Double-check for any spelling errors, typos, added characters, letters, or numbers in the link.
  • Open websites directly in your browser instead of clicking links included in an email or text message.
  • Enable multi-factor authentication (MFA) or two-factor authentication (2FA) for added security if your credentials are compromised.