

Do not open suspicious texts or emails or click on links within them. Fraudsters impersonate companies to get consumers to click links and provide personal information. Clicking on links can also infect your device with malware.
A password is the first line of defense against cybercriminals. We recommend creating a complex password that is difficult for others to guess but easy for you to remember. Use a different password for each site.
Monitor your accounts regularly, respond to fraud alerts, and report unauthorized transactions promptly.
Auto-install updates. One of the most important controls to protect against ransomware is updating your devices and apps, including browsers (ie: Internet Explorer, Chrome, Edge, etc).
One of the most common ways that computers are infected with ransomware is through social engineering. Remember to exercise common sense with suspicious email, websites, and other scams. If it seems suspect, it probably is.
Be unpredictable. There are two common password attacks, brute force and dictionary attacks. Both involve trying a sequence of numbers and/or common words like 123456, hence, trying to crack a password using “brute force” or common “dictionary” words. To minimize this type of exposure, don’t make your passwords predictable.
Be creative. Related to being unpredictable, consider creating a phrase and use the first or second letter of each word, or substitute a special character for letters and/or numbers. You can use a password generator which provides creative and secure password options.
Be long. The longer the password, the more possible combination, and permutations of the password there are, and thereby the safer they generally are. However, don’t forget the first two tips, because long common words and sequences of numbers are still easier to crack!
Be selfish. Believe it or not, one of the more common reasons passwords are compromised is because people share their credentials. Quite simply – never, ever share your password(s)!
Be mindful. Think before you click. Phishing is where you receive an email or text message asking for you to confirm your details or take some other action where you need to enter your personal credentials. These types of acts are becoming increasingly sophisticated and can look very legitimate, like an email from someone you know. As a good rule of thumb, unless you make a request, don’t ever enter your credentials. Or, if you have any doubts, contact the organization requesting the information directly.
Be unique. You should use different passwords for different logins – yes, a different password for every login. Having a unique password for all your accounts helps prevent that if or when one is compromised the others remain protected. Pro tip: If you can’t remember all your passwords, consider using a secure password manager.
Use the built-in firewall on your computer.
Turn on automatic updates for ALL software you use, including your internet browser(s).
Use antivirus and anti-malware software and keep it current.
Create a long phrase for your password instead of a short password.
Don’t open suspicious attachments or click unusual links in email, tweets, posts, online ads, messages, or attachments.
Browse safely. Don’t visit illicit sites. They may contain malware or a download that contains malware.
Refrain from streaming or downloading movies, music, books, or applications that are not from a trusted source. Pirated material may include malware.
Avoid malware and viruses by only using external devices you own or receive from a trusted source.
.exe Files: .exe files are executable files - meaning that they can run a program; while .exe files are not inherently malicious, they can be used to install malware on your computer; there's no reason for an .exe file to be shared via email, so if you receive one, you should delete it.
- .exe files can also be disguised in .zip folders - if you receive an email with a .zip, and open the folder to find an .exe, you shouldn't run the file.
- Be careful, some attachments might show the icon for a document, PowerPoint, etc., but they still have the .exe extension.
- Just because a file isn't an .exe, doesn't mean it's not malicious - there have been instances of macro-viruses that hide themselves inside of Office Documents.
Strange "To" Field: if the email has a long, alphabetical list of recipients, or if the "To:" field is blank, then the email is probably illegitimate, and the attachment shouldn't be opened.
Vague Subject Line/Body: if the subject line or the body text is vague, then the attachment probably is illegitimate.
Missing Salutation: most legitimate emails have a salutation.
Poor Grammar/Spelling: legitimate emails are carefully proofread before they're sent out; if the email has a lot of spelling/grammatical errors it's probably not legitimate.
Sense of Urgency: (i.e. - "this attachment will expire in 24 hours”, “you have an unpaid invoice") most illegitimate emails try and create a sense of urgency so that the recipient will download and run the attachment without carefully looking at it.
Remember attackers/bad actors rely on user interaction. Their goal is to try to trick users into opening a malicious document to exploit system vulnerabilities. Stay alert, stay safe!
If you receive a phone call, text, email, or letter with this type of request, it is a scam. If someone tells you they are from The Dime Bank and you are unsure, ask for their name and phone number, hang up, and call us immediately at 570-253-1970 or toll free at 1-888-4MY-DIME (1-888-469-3463). If the call was truly from The Dime Bank, you will reach us by calling us back on our published phone numbers.
Please help us safeguard your information. We’re here to help you in any way we can.