
New: A Statement on Fraud from Our Chairman & CEO
Read Michael Scaief’s perspective on today’s fraud environment and why fraud prevention has become a shared responsibility for every individual, family, and business.

A caller knows your name. They know the business you own. They know who you work with, where you bank, and they can read off your home and work addresses.
None of that information came from your bank, and much of it may have been publicly available long before the phone call began.
Many people are surprised when a fraudster already knows personal details about them. In many cases, that information wasn’t obtained by hacking a bank account or breaking into a computer.
Instead, it was gathered from sources already publicly available or exposed through publicly reported, non-banking, data breaches. Several of the largest data breaches in recent years have exposed billions of personal records, and understanding that significant amounts of personal information may already be available can help explain why modern fraud attempts often sound so convincing.
One of the biggest misconceptions in fraud prevention is believing that someone who knows personal information must be legitimate.
Today, that assumption is no longer safe.
Information that is publicly available—or exposed through publicly reported data breaches—should never replace independent verification. Whenever someone asks for credentials, account access, payment approval, or sensitive information, verify who they are before taking action.
Access additional resources and practical lessons to help support you and safeguard your family at TRB's Fraud Prevention Resource Center.
Learn MoreOver the past several years, a series of large, publicly reported data breaches involving organizations outside the banking industry have exposed billions of records containing names, addresses, telephone numbers, email addresses, dates of birth, and other personal information.
Incidents such as the National Public Data breach and the “Mother of All Breaches” (MOAB) demonstrate the scale of information now available to criminals. A single breach rarely provides everything a fraudster needs.
Instead, criminals combine information from multiple sources, including public records, company websites, professional networking sites, social media, and publicly reported data breaches, to build detailed profiles of the people and businesses they intend to target.
That preparation helps explain why an unexpected phone call, email, or text message can sound remarkably convincing.
Every day, individuals and businesses share information for legitimate reasons. Businesses publish websites and employee contact information. Professionals maintain networking profiles. Property ownership is often part of the public record. Local organizations publish announcements, biographies, and community involvement. Social media often shares milestones, family events, travel, hobbies, and other personal information.
In addition to public information, criminals also have access to information exposed through publicly reported data breaches unrelated to your financial institution. Those breaches may include names, addresses, telephone numbers, email addresses, or other personal information that can later be combined with publicly available records. Individually, none of these sources tells the complete story. Together, they can reveal much more than most people realize.
Information that may already be available includes:
Individually, none of these sources tells the complete story. Together, they can reveal much more than most people realize.
The internet has made information more accessible than ever before. That doesn’t mean you should stop participating online or remove every public reference to yourself or your business.
It does mean recognizing that information a caller already knows about you should never become the reason you trust them.
Verification remains one of the simplest and most effective ways to protect yourself, your family, and your business.