Security recommendations
Types of fraud to be aware of
Digital Channels
When browsing the Internet, it is essential to be mindful of security precautions in order to protect yourself, ensure the safety of transactions and safeguard your personal data.
Here you can find some essential security rules to follow when using your computer, mobile phone or tablet, especially when accessing online banking services such as novobanco Online or the novobanco App.
Your online banking security. What novobanco does for you:
-
Use of online bankingAuthentication and customer identification through Direct Channels security codes, namely:
Registration number
PIN
Cartão Matriz - Master Card digits
Strong authentication system – “Additional Security”
A strong authentication system that requires confirmation of transactions involving financial movements, through:
Push notifications validated in the novobanco App, or
A one‑time disposable code, generated and sent in real time to the customer’s mobile phone via SMS
Access protection
Automatic suspension of access after a defined number of consecutive failed attempts using Direct Channels credentials (registration number and PIN)
Maximum session duration and automatic logout after a period of inactivity in novobanco Online
-
Secure internet communicationsSecure website using HTTPS
SSL encryption with SHA256RSA technology to protect information and communications
-
Systems monitoringnovobanco has a monitoring team that continuously analyses systems, accesses and transactions carried out through the bank’s Digital Channels.
-
Online privacy
novobanco is committed to protecting your privacy and does not use or disclose your data to any external entity for commercial purposes.
Fraud Alerts
Online safety precautions
Protect your computer
Not keeping your antivirus up to date is almost the same as not having one at all.
An antivirus protects your computer against malicious attacks by scanning installed programs and even emails received in your inbox.
The use of a firewall system on computers connected to the Internet is strongly recommended.
Across the Internet, there are automated processes controlled by intruders constantly scanning IP addresses in search of vulnerable computers.
Firewall systems provide effective protection against this type of reconnaissance and intrusion attempt.
Most cyberattacks exploit security vulnerabilities in commonly used applications.
If your software is not properly updated, the number of exploitable weaknesses increases.
Make sure to regularly update your operating system and internet browser.
To improve your computer’s security, always use properly licensed software.
Do not install programs unless you can guarantee the reliability of their source.
Not all software is what it claims to be, and many programs may simply enable third parties to access your personal information.
Smartphone and tablet security
Protect your device with a password, PIN or biometric authentication.
These devices can easily be lost or stolen, so securing access is essential.
Install applications only from official and trusted app stores, such as:
App Store
Google Play
App Gallery
Always check the permissions requested by apps before installing them and only allow what is strictly necessary.
Set usage restrictions to prevent:
Installation of unknown applications
Execution of programs you do not recognise
This is especially important when devices are shared or used by children.
Always update your operating system and installed applications.
Not installing updates increases the risk of cyberattacks and malicious app installation.
Free Wi‑Fi networks and public hotspots make internet access easier but also facilitate the work of cybercriminals.
Avoid using public Wi‑Fi when accessing:
Online banking
Online shopping
Social networks
Any site requiring sensitive personal information
Be extra careful with links received from unknown or suspicious contacts.
Do not click on:
Messages
Images
Promotional content of unknown origin
Delete the message and block the sender.
If the message claims to be from a legitimate entity, confirm its authenticity directly before accessing any link.
Also be cautious if an SMS asks you to reply with personal data. This may not be malware but a method used to collect contacts for spam campaigns.
Safe Internet Use
Nowadays, the internet is used not only for work, but also for leisure and to communicate with friends.
For this reason, it is increasingly important to know how to identify risks and protect devices from unauthorised access to personal data and information.
The use of computers or smartphones to access the internet should be done responsibly, paying particular attention to the information shared on social networks.
Avoid sharing information such as your full name, address, phone or mobile number, or email address on social networks or websites claiming to represent your bank or other services.
If a website asks you to enter sensitive information:
Check the URL to make sure the page genuinely belongs to the organisation and is not a fraudulent domain (for example, NBbanco.com or g00gle.com)
If payment information is requested, look for the lock icon in the browser to confirm a secure connection
Many profiles belong to unknown users, or even to friends whose accounts have been compromised.
So‑called hoaxes are false messages that may refer to topics such as:
Supposedly ill children
Changes to social network rules
Missing persons
Lottery prizes
Contests offering electronic devices or shopping vouchers
Always verify whether an ad or contest is legitimate before engaging with it.
Because online games are especially popular with younger users, some are used as a way to collect passwords and personal information.
Some job offers promise easy money with little effort.
In certain cases, candidates are asked to use their bank accounts as intermediaries to transfer money abroad. These funds may come from illegal sources and may result in harm to third parties.
Avoid using public computers, such as those in internet cafés, to make online purchases.
These devices may be infected with malware or monitored by third parties.
Avoid using:
Birth dates
Names
Other personal references
These are usually the first combinations malicious actors attempt.
Email messages and their attachments are often used to spread viruses or provide a gateway for hackers to access your computer.
If you receive an email whose sender or subject you do not recognise, that contains links and/or attachments, requests private or confidential information, or includes overly attractive job offers, be immediately suspicious.
You are likely being targeted by a scam, commonly known as phishing.
Phishing attacks have evolved rapidly to adapt to current realities. The most recent attacks are often linked to malicious software that installs itself when you click on links or open attachments in emails.
You should delete the message without opening it, even if the subject line appears appealing.
Precautions to take with your online banking data
Ensure the security of your data and the confidentiality of your transactions when using online banking.
Protect your Cartão Matriz - Master Card and access credentials
Never enter all the digits of your Cartão Matriz - Master Card.
The matrix digits are a second‑level security code used to perform transactions on digital channels.
novobanco will never ask for more than 3 matrix digits, under any circumstances, nor will it ever send emails requesting the full matrix data.
Never share your login credentials.
novobanco will never request your mobile phone number to access Online Banking.
Keep your access data confidential, do not share it with anyone, not even people you trust, and do not write it down on paper.
Always keep your Direct Channels Card (Cartão Matriz - Master Card) with you and prevent third parties from accessing it.
Linha Direta - Direct Line contacts
When using the Linha Direta - Direct Line service, your access details are usually entered by you into an automated system.
Only in exceptional cases may an operator request them.
If this happens, make sure no one around you can hear or see the information you are providing.
If you receive a call from the Linha Direta - Direct Line without having requested it, remain alert and never share your access credentials or any information that could put your funds at risk.
Be alert to suspicious behaviour
Be cautious if you notice changes in the appearance or login procedures of novobanco Online.
For example:
Being asked for more access data than usual
Login pages opening in separate or unusual windows
If in doubt, contact the Linha Direta - Direct Line immediately.
Be suspicious of pages containing spelling or grammatical errors, or language that suggests it was written by someone unfamiliar with novobanco’s usual terminology. This may indicate a fraudulent page.
Safe access practices
Avoid accessing novobanco Online from public or shared computers, unless it is an official NBnet terminal at a novobanco branch.
Change your access PIN regularly.
Use a PIN that is different from those used on less secure websites.
Avoid easily guessed combinations, such as:
Dates of birth
Telephone numbers
When entering your access details, make sure no one is watching.
After finishing your session, always log out by clicking “Logout”.
Always ensure you are on the official novobanco website by checking for the closed padlock icon in the browser address bar.
Click on it and confirm that the “Issued to” field displays sec.novobanco.pt.
Account monitoring
Regularly monitor your accounts.
Get into the habit of checking the date and time of the last access to novobanco Online.
PUB | NOVO BANCO S.A. | Registered no. 7 at Banco de Portugal