Password Standard Requirements
When setting your passwords, please ensure adherence to the following guidelines. To be valid and secure, your password must include the following features:
- It must not consist of consecutive or repeating numbers (such as 123456 or 111111).
- Your password must consist of only numbers and be six digits long.
- Avoid using easily predictable numbers such as your Turkish ID number, customer number, phone number, or birthdate.
- Your new password should be different from the last three combinations you have used.
- Personal information or phone numbers should not be used as a Single Password.
- Do not create passwords using sequential keys on the keyboard (such as 123456 or 147258).
Email Security Considerations
Do not trust emails that use the name and logo of Kuveyt Türk to request your personal or financial information (such as credit card, account, or customer numbers). We would like to remind you that Kuveyt Türk will never ask for your personal information through emails, even if you receive emails claiming to be from Kuveyt Türk. These emails are phishing attempts by third parties.
If you encounter such a situation, do not provide your personal/financial information and avoid clicking on any links provided. Verify individuals who present themselves as Kuveyt Türk personnel in their email by calling the Kuveyt Türk Customer Contact Center at 444 0 123.
- Do not open emails or attachments from unknown sources or those whose reliability you are unsure of.
- If the email is not related to you or expected, do not click on any links or files within it.
- You may read the email content but avoid clicking on any link or file in it.
- Do not respond to spam, chain, or fraudulent emails.
- Be cautious of e-mails that specifically ask you to download files or fill out forms.
- Only enable notifications for your personal email on trusted websites.
What are Social Engineering Attacks?
Phishing attacks are executed using social engineering techniques. Social engineering is the process of acquiring information by deceiving individuals, rather than relying on technology.
Social engineering attacks are not isolated incidents but rather extend over a certain period. They aim to infiltrate a person's personal security circle by imitating certain aspects of their daily life. Therefore, having general awareness is the best defense against such attacks.
Characteristics of Social Engineering Attacks
- They exploit human vulnerabilities.
- They provide the easiest access to information.
- They include methods of persuasion, intimidation, and coercion
- They do not necessarily require technical knowledge.
Types of Social Engineering Attacks
- Phishing: A method of communication via email that either contains alarming messages or appears to originate from a trusted source (such as a bank or a friend's email address from whom you expect news).
- Smishing: A type of information theft conducted via SMS, where the recipient is urged to click on a link or make a payment.
- Vishing: A method where the scammer impersonates a government official such as a police officer, prosecutor, or judge to obtain information for financial transactions from the victim over the phone.
Precautions Against Social Engineering Attacks
Your customer number, Single Password, card information, and one-time password used in phone banking transactions are known only to you, not even your Kuveyt Türk customer representative. Therefore, do not share these details with anyone.
- Always investigate any unusual activities in your email, other communication networks, or bank account. Take immediate action if you have any suspicions.