BDC offers its clients services via the BDC Connex website, access to which is protected by a username and password. BDC is committed to ensuring the security of this service, in order to fully protect the personal information of its clients.
BDC would like to alert you to a technique used by scammers to try and obtain company or personal information. While BDC has not yet been the target of such a scam - called "phishing" - we still want to warn you about this fraudulent practice.
Beware of scams!
Here is how phishing usually works:
- You receive an email that seems to come from BDC.
- The email sender address, moreover, appears to be valid (it includes the word "bdc").
- The subject of the email concerns your account.
- The email may include the BDC logo, as well as a hyperlink purporting to connect you to the BDC Connex website.
- The email invites you to access the BDC site for a specific reason (for example, to keep your account active, to benefit from a special offer, etc.).
Note that, in reality, BDC accounts will not expire by a given date due to inactivity, nor do we send out special financing offers via e-mail. By clicking on the hyperlink found in such an email, you may very well fall into the phisher's trap! The scammer will be sure to have his site decked out in the BDC colours, include our logo, etc.
Falling into the trap
- Contrary to what the hyperlink included in the scammer's email seems to indicate, you will not actually be redirected to the BDC Connex website (www.connex.bdc.ca), but rather, to the phisher's site.
- Once you enter your username and password on the phisher's site, he can then save these for his own fraudulent use. Note that, since the scammer has no details about your BDC account, he will then display an error page alluding to a technical error. You will most likely not suspect a thing. With your username and password in hand, the phisher can then go to the real BDC Connex site, enter your access codes and access your account… in your name.
BDC, like all other financial institutions, cannot protect you from such traps, as we have no way of preventing scammers from contacting you directly.
Avoiding the trap
Here are some safeguards to bear in mind with regard to your BDC Connex account:
- If you receive an email that appears to come from BDC asking you to immediately access your account, do not reply to the message and do not click on the embedded hyperlink. You should be highly suspicious of any email asking you go to the BDC Connex site and access your account. Should such a situation occur, send the questionable message to info@bdc.ca (include your area code and telephone number if you want us to call you back) or call 1 877 232-2269 to notify us and check whether the e-mail in question was actually sent by BDC.
- Never send personal or banking information via email, which is not a secure means of communication. BDC offers special Web forms for this purpose (at www.bdc.ca and http://www.connex.bdc.ca/). These forms protect the enclosed information through use of a 128-bit encryption feature.
- Make sure to install and update antivirus software, as well as a firewall, to protect your computer from viruses, worms and spyware.
- Scammers frequently use email attachments to access your computer. These will often seem to come from people that you know, as hackers will ferret out the names and email addresses of friends and family members to send you emails that will not set off any warning bells.
- Please report any phishing attempts to BDC, as this will help us thwart scammers' attempts to access personal information. You can easily report any scams by forwarding messages you receive to info@bdc.ca.
- If you believe that other people may know your password, we recommend that you change it. You can do this on the BDC Connex website, by first clicking on "My Account" then on "Change my password". Frequently changing your password is an excellent security measure. Don't forget to choose a password that others will be unable to guess.
BDC client communications
BDC's communications are, for the most part, carried out via letter or telephone. The only email BDC may send you with regard to your BDC Connex account is an initial message, subsequent to your request for online account activation, to provide you with a temporary password. You can then choose to receive your password by telephone or email (this email would not, however, include your access code).