CAFT Safety
Stay Protected from CAFT Cyber Attacks
What is CAFT?
Customer Automated Funds Transfer (CAFT) is a web-based
solution that allows a business to manage payments. CAFT
is compatible with most accounting software and provides
the option to enter data manually online.
-
Initiate direct deposits, such as payroll or accounts payable
-
Collect payments such as loans, accounts receivable, strata/condo fees, donations, and club fees/dues
What do I need to know?
CAFT is a web-based application, therefore accounts could be exposed to cyber fraud if the business or employee's computer system becomes compromised.
-
Check the CAFT Activity Log and History File information.
-
Contact Access Credit Union.
-
Change your CAFT password immediately.
-
If you have been compromised, follow the security
procedures of your company.
As a CAFT user, you are responsible for:
- Protecting your passwords and User IDs.
- Managing your CAFT transactions.
- Verifying file totals prior to file processing.
- Releasing files in a timely manner.
- Reviewing CAFT email notifications upon receipt.
- Reviewing your Activity Log.
- Reviewing your History File.
- Verifying all NAFT reports.
- Verifying account settlement to the settlement register (AFTR0010).
- Contacting us about any changes to Originator information.
- Immediately notifying us of any unusual activity.
What can I do to protect myself?
- Enhancing cyber security practices:
- Limit administrative rights on users' workstations to help prevent the inadvertent downloading of malware or other viruses.
- Ensure virus protection and security software and the operating systems/applications on your computer are updated regularly.
- Implementing internal controls (segregation of duties, dual authorization, setting CAFT limits).
- Reviewing transaction files for accuracy.
- Reviewing CAFT email notifications.
- Reconciling banking transactions daily.
- Talking to an insurance provider about Social Engineering coverage.
Best Practices
CAFT Controls
Use the right website
Please do this by typing in the legitimate CAFT site directly:
https://www.caft.paymentsanytime.com.
Keep your information safe
Don't click links
TIP: CAFT system emails don’t have links! There may be a text file attached if you have processed a transaction recently. These attachments end in .txt.
Cyber security is everyone’s responsibility!
Remember the following to keep your information safe:
-
Create a difficult to guess password using a combination of letters and numbers and never share your User ID or passwords.
-
Logout of any secure accounts, such as online banking, when finished. DO not just close the browser window.
-
Lock or logout of your computer when unattended.
-
Never access your Access Credit Union accounts or services using open/free WiFi (e.g. coffee shops, public libraries, hotels, etc.). If you must access these services in a public location, opt to use data instead.
-
Be mindful of phishing scams: never open an attachment or links from unexpected emails, even if they look legitimate.
Additional Resources
Contact Us
Contact us to learn more.