Recognize the Red Flag
Any unsolicited request for your login credentials, secure access code, or personal information is an immediate red flag, even if the caller or sender appears legitimate.
Cyber threats and fraud tactics continue to evolve through artificial intelligence, sophisticated phishing, and social engineering. While Ford Interest Advantage (FIA) maintains rigorous institutional safeguards, protecting your Demand Note is a shared responsibility. Please review these essential guidelines.
Ford Interest Advantage will NEVER contact you unsolicited by phone, text, or email and ask for your login credentials or One-Time Secure Access Code (SAC).
Please follow our immediate action protocol for phishing and social engineering:
Any unsolicited request for your login credentials, secure access code, or personal information is an immediate red flag, even if the caller or sender appears legitimate.
Do not reply, click embedded links, or share any personal or note details. Even replying “Stop” or asking questions confirms your contact information is active to attackers.
Hang up the phone or close the message immediately. Report the attempt to Investor Services at 1-800-462-2614 (Monday-Friday 8:30 a.m. to 7:00 p.m. ET).
Phishing and Impersonation:
Fraudsters impersonate legitimate organizations via phone, email, or text to steal credentials, access devices or intercept transactions.
Note Takeover and SIM Swapping:
Attackers use stolen credentials, malware, or unauthorized mobile number transfers (sometimes called SIM swapping) to intercept secure access codes, bypass authentication, and redirect funds.
Social Engineering and Coercion:
Fraudsters manufacture panic, secrecy, or urgency to rush victims into bypassing security controls and authorizing irreversible payment methods (like wire transfers, gift cards, or cryptocurrency).
Never Share Security Access Codes or Approve Unexpected Multi Factor Authentication (MFA) Prompts:
Never disclose verification codes to anyone or approve login/authorization notifications you did not personally trigger—even if the requester claims to represent your bank, tech support, or Ford Interest Advantage.
Use Strong Credentials and Multi Factor Authentication (MFA):
Secure every portal with a unique password and enable biometric passkeys (like Face/Touch ID) or MFA wherever available. Never reuse passwords across sites.
Set a Carrier Port-Out Freeze:
Contact your mobile provider to block unauthorized transfers of your phone number to another carrier or SIM card (SIM swapping), which attackers use to intercept MFA codes.
Verify Wire Instructions:
Wires are generally irreversible once processed, and fraudulent transfers may not be recoverable. Confirm all recipient instructions via a trusted, independent phone number before submitting.
Prioritize Digital Payments and Guard Checks:
Use electronic transfers over paper checks when possible. Securely store mobile-deposited checks until they clear, shred them immediately after, and treat blank checkbooks like cash. Fraudsters can use bank details from your checks to create unauthorized transactions without your knowledge.
Deny Remote Access:
Never download remote desktop software and never grant remote access to your computer or mobile device to anyone who contacts you unsolicited. This is a way to steal your login credentials, like user IDs and passwords, to important applications.
Keep Software and Systems Current:
Enable automatic updates across your operating system, browser, and security software to patch known vulnerabilities that attackers exploit to steal credentials.
Navigate and Connect Securely:
Type official website addresses directly into your browser rather than clicking links; avoid unknown QR codes and public Wi-Fi; lock mobile devices with a PIN; and log off and close your browser after each session.
Monitor Note Activity:
Regularly review statements and transactions for discrepancies. Immediately report any unauthorized activity, unrecognized profile updates like phone number or email address changes or altered banking details to Investor Services at 1-800-462-2614.
Enable Real-Time Alerts:
Turn on text, phone, or email notifications in Online Access for all transfers, logins, and security profile changes to detect and report unauthorized activity immediately.
Guard Personal Data:
Limit personal details on social media that attackers harvest to solve security challenge questions.
First 24 - 72 Hours is Critical
If you suspect your credentials, device, or FIA Note has been compromised, take immediate action as outlined below—the first 24 hours are critical to stop further unauthorized access.
Your security is our priority, and we appreciate your vigilance in helping safeguard your investment. If you have questions or notice anything unusual, please contact Investor Services at 1-800-462-2614.
This communication is provided for general cybersecurity awareness and educational purposes only and does not constitute formal legal, regulatory, or compliance advice.
Ford Credit — NMLS #3018