Skip to main content

August 2026 Compliance Journal

Page 1

Compliance Journal August 2026

Special Focus The Long Tail of PPP Why Bank Customers are Being Targeted Again Jeff Otteson, vice president of sales, with the Midwest Bankers Insurance Services (MBIS) offers the following information about how scams involving Paycheck Protection Program (PPP) information work, why the fraudsters are so convincing, steps banks can take to help mitigate the fraud, and insurance considerations. The PPP may have ended, but the information it generated continues to create opportunities for fraudsters. Businesses that received PPP loans are now being targeted through highly personalized bank-impersonation schemes. Using publicly available PPP loan information, criminals can identify a business, its loan amount and, in many cases, the bank associated with the loan. That information gives a fraudster enough credibility to make an unexpected call, text message, or email sound legitimate. This is not simply another generic phishing campaign. It is a targeted social-engineering attack built around real information and a trusted banking relationship. How the Scam Works The Small Business Administration maintains a public, loan-level dataset covering disbursed PPP loans. Fraudsters can combine that data with business websites, social media, and other public records to develop a convincing profile of a potential victim. A fraudster may know: • The business’s legal name and address; • The amount of its PPP loan; • The lender associated with the loan; • The names of owners, executives, or accounting employees; and • The bank’s treasury-management or fraud-department terminology The criminal then contacts the business while impersonating an employee of its bank. Caller ID may be spoofed so the call appears to originate from the bank’s actual telephone number. Emails and text messages may use the bank’s name, logo, and branding. The purported reason for the contact can vary. The customer may be told that: • A suspicious ACH or wire transfer is pending; • Someone attempted to access the company’s online banking account; • A check or electronic payment must be verified; • The account must be frozen to prevent additional fraud; • A security update is required; • The bank needs to confirm the customer’s credentials; or • A one-time passcode is needed to stop or reverse a transaction.


Turn static files into dynamic content formats.

Create a flipbook
August 2026 Compliance Journal by wisbank - Issuu