Phishing Alert
BBVA no longer markets in Belgium, or from Belgium, loans or savings products to individuals or small businesses, nor does it use direct customer acquisition strategies. More information.
Secure passwords
E-commerce
Cyber attacks
Net Cash security
PSD2 Security
BBVA takes all measures to ensure secure online banking transactions by means of a Secure Password system.
Your access password for BBVA Net is a private password that must be kept safe. They are stored in our internal systems using non-reversible encryption, so that nobody at BBVA can find out what they are.
BBVA will never request your BBVA Net credentials or any other personal or banking details by email or SMS. If you receive a message of this type, please do not provide any information through these channels.
Web browsers offer the option of saving usernames and passwords of websites that require these. BBVA recommends that you never save your passwords to our Remote Banking service in a computer or a tablet. These devices can be the target of cyber attacks and your passwords may be exposed.
BBVA recommendations
BBVA recommendations
Some of the most common computer viruses and threats to cybersecurity are:
BBVA recommendations
Measures from BBVA
The service
1. User administration:
BBVA Net Cash is a multi-user application. It has multiple user profiles that the company can allocate to its staff according to its operational structure.
A specific administrator profile specifies and administers the company users of BBVA Net Cash. There may be one or various administrators with different degrees of delegation (without powers or with joint and several or joint powers). Every user is allocated a profile that is defined with the most possible detail.
To authorize transactions, the options are:
This structure allows a group of users as restrictive as the company wishes, in order to guarantee at all times that:
2. Monitoring of activities:
Users can monitor the entity's transactions in BBVA Net Cash through:
3. User credentials:
BBVA Net Cash has a two-step security process, which essentially consists of a token to validate on the group of users and sign off transactions. The system will ask you to enter a six-digit (single use) security code generated by the device. The token can be physical or installed on your cell phone (by downloading the BBVA Net Cash app).
The password must be changed upon the first access: to prevent user impersonation, when you first connect to BBVA Net Cash you must change your password.
Block user:
4. Identification and authentication:
Traceability of transactions: accesses and completed transactions are recorded in automated transaction records that collect the completed transaction, the date and time thereof and the user that executed it, to determine the validity of the recorded transactions.
Information on the last connection:
Cookies active only while you are logged in: cookies located in the user's operating system, which are necessary to safely browse any website, are active only while the user is connected to BBVA Net Cash and are deleted when the user logs off.
Automatic timeout: as an additional security measure, after 10 minutes of inactivity in BBVA Net Cash, the user's session is ended and they are logged off the system.
5. Compliance with national and international rules:
In all its services, BBVA complies with the rules and regulations of the countries in which it operates. BBVA's commitment to those regulations is contained in the Code of Conduct, which is mandatory for all employees.
Technology
1. Confidentiality and integrity
Of all user credentials:
of communications:
Of information:
2. Physical security of Data Processing Centers
BBVA's Data Processing Centers are equipped with broad physical security measures to protect data processing systems, including but not limited to the following:
By having two fully operational Data Processing Centers, BBVA guarantees information safeguarding and recovery should it ever be necessary.
3. Security architecture:
In order to ensure maximum security in the design of its systems, BBVA has established specific security architecture especially for systems offering online services to its customers.
Specifically, and to minimize online exposure, it maintains exposure only to the presentation layer (performing user authentication functions, authorization of access to web applications and secure monitoring of sessions) through reverse proxy.
4. Specific protection systems:
Continually updated firewalls and antivirus and anti-intruder systems:
Activity log of all components: BBVA has logs in all remote banking systems and applications for all critical components, which provide support to phishing detection services and forensic analysis of suspicious or reported fraudulent activities or transactions.
Regular service review, applying the latest attack techniques: systems supporting remote banking services are regularly reviewed using vulnerability analysis tools.
Internal and external audit: BBVA systems and processes are subject to regular security audits by the independent audit department and by specific external auditors and financial or compliance audit firms.
Measures for the user
Protection of your user credentials
Protecting your computer
Secure internet access and browsing practices
Viruses and common attacks
Computer viruses are programs whose sole purpose is to install themselves on a user's computer without their permission or knowledge. There are several types of virus, but they usually all have this in common: they propagate and spread in the same computer and through the network.
It is easy to unknowingly contribute to spreading of viruses, by forwarding emails with infected attached files. All users must work togetherand the Internet to prevent it from spreading.
There are several types of virus, including:
Phishing:
The sending of an email that impersonates a very well-known organization and asks the user for information (address, bank details, passwords, etc.). For the user to give the information, they are often asked to click a link in the email and, once they are on the fake website, enter the requested information.
It basically works as follows:
1. Spam is sent out informing BBVA Net Cash users that they need to confirm their login details.
2. The message includes a link to a page from which to confirm their information. Sometimes, the link starts a download of malware.
3. The user clicks on the link that takes them to a “similar" page to the authentic BBVA Net Cash page, and they confidently enter their information.
4. As the page is false and controlled by the fraudsters, they are the ones who actually receive the user's information, and thus have access to the user's account.
Although BBVA will never ask you for your BBVA Net Cash log in by email, here are some tricks to help you to catch this kind of attack:
- Sometimes, the logo is distorted or stretched. They usually also include spelling mistakes or odd expressions.
- They address you as "dear customer” or “dear user” rather than your actual name.
- They warn you that your online banking account/service will be closed unless you reconfirm your login details immediately.
- The tone of the email is threatening.
- The text refers to “security commitments” or “security threats” and requires immediate action.
- The URL is not https:// and the security padlock does not appear in the browser box. False links include this kind of icon within the window to deceive you.
Ransomware:
It is a lucrative kind of tech crime. They are usually disguised as “package delivery services” or any other credible excuse, and are spread by email with links that install infected programs or download infected files. This virus blocks access to your computer's files and demands a ransom which once paid is supposed to provide a password to unlock them.
Below is a series of tips to protect yourself from ransomware:
Trojans:
They enter a personal computer and conceal themselves in a program. They transform the computer's behavior so that everything that it does can be seen on the criminal's computer. To prevent your computer from being infected by a Trojan, follow the same instructions as above for ransomware:
Hoaxes:
These are emails containing false gossip for the sole purpose of circulating and propagating low quality information online.
In general, they are not too harmful and are easy to delete.
To prevent these attacks, follow our recommendations and inform us of any suspicious situation or communication:
As soon as you inform us, BBVA Net Cash's customer service will launch its anti-fraud protocol: a group of specialists will be allocated to your case.
If your suspicions are confirmed, you are advised to:
In all confirmed cases, the login password of the affected user will be changed.
Measures for the user
Protection of your user credentials
Protecting your computer
Secure internet access and browsing practices