Wise Account Security and Fraud Questions and Answers 1 — Questions and Answers
Question 1: A user receives an email with the Wise logo that urgently warns of 'unauthorized activity' on their account. The email asks them to click a link to 'verify their identity immediately' or risk account suspension. Which of the following is the most secure action to take?
- Ignore the email, open a new browser window, manually type 'wise.com', and check their account for any notifications. (Correct answer)
- Reply to the email asking for more specific details about the unauthorized activity.
- Click the link and enter their login details, as the email appears to be from Wise.
- Forward the email to a friend who also uses Wise to see if they received a similar message.
Correct answer: Ignore the email, open a new browser window, manually type 'wise.com', and check their account for any notifications.
This scenario describes a common phishing attempt. Scammers create emails that mimic legitimate companies to trick users into revealing their login credentials. The safest course of action is never to click links in unsolicited or suspicious emails. Instead, a user should always navigate directly to the official website by typing the address manually to ensure they are on the legitimate site before logging in.
Question 2: Which of the following is the MOST secure method for setting up two-step verification on a Wise account?
- Receiving a code via text message (SMS).
- Using a Passkey with biometric authentication (fingerprint or face ID). (Correct answer)
- Getting a verification code via a phone call.
- Answering a personal security question.
Correct answer: Using a Passkey with biometric authentication (fingerprint or face ID).
While all forms of two-step verification add a layer of security, Passkeys and authenticator apps are considered more secure than SMS or phone calls. Passkeys are resistant to phishing and cannot be intercepted in the same way SMS codes can be. They use cryptographic key pairs, where a private key stays securely on your device, making it extremely difficult for an attacker to compromise your account remotely.
Question 3: A Wise user suspects that their account has been compromised after noticing a transaction they did not authorize. After immediately freezing their card in the app, what is the CRITICAL next step they should take?
- Wait 24 hours to see if the transaction is reversed automatically.
- Change their registered email address.
- Contact Wise support immediately to report the unauthorized activity and secure the account. (Correct answer)
- Post about the issue on social media to warn other users.
Correct answer: Contact Wise support immediately to report the unauthorized activity and secure the account.
If unauthorized activity is suspected, it is crucial to contact Wise immediately after taking preliminary steps like freezing the card. The Wise support team can take further action to suspend the account, investigate the fraudulent transaction, and prevent additional losses. Delaying contact can give an attacker more time to cause damage.
Question 4: To comply with financial regulations and prevent fraud, Wise is required to verify a user's identity. Which of the following is a key part of this standard verification process?
- Asking the user for their social media account passwords.
- Requiring the user to purchase a 'verification subscription'.
- Having the user share their screen with a support agent.
- Requesting a photo of a government-issued ID and sometimes a selfie of the user holding it. (Correct answer)
Correct answer: Requesting a photo of a government-issued ID and sometimes a selfie of the user holding it.
Wise, like other financial institutions, must verify user identities to combat financial crime. The standard process involves collecting documents like a government-issued photo ID (passport, driver's license) and may also require a 'liveness check' in the form of a selfie to ensure the person matches the ID. Wise will never ask for social media passwords or require payment for standard verification.
Question 5: A user receives a phone call from someone claiming to be from 'Wise Fraud Prevention.' The caller states there is a problem with a recent transfer and asks the user to provide their password and the 2-step verification code they just received to 'cancel the fraudulent payment.' What should the user do?
- Provide the information as requested to stop the fraud quickly.
- Ask the caller to verify their identity by providing the user's last transaction amount.
- Hang up immediately and report the incident to the official Wise support channels. (Correct answer)
- Give them the password but not the 2-step verification code.
Correct answer: Hang up immediately and report the incident to the official Wise support channels.
Legitimate Wise employees will never ask for a user's password, full card number, or 2-step verification codes. This is a social engineering tactic used by scammers to gain full access to an account. The correct action is to end the communication immediately and report the attempt through official channels found on the Wise website or app, as the user's phone number may be targeted by fraudsters.
Question 6: Which of the following is an officially supported Wise security feature designed to help users identify legitimate emails from the company?
- A daily email summary of all account logins.
- A Secure Communication Code that the user sets, which is then included in genuine emails from Wise. (Correct answer)
- Sending security-related messages exclusively through postal mail.
- A system where all Wise emails come from a '@wise-security.com' address.
Correct answer: A Secure Communication Code that the user sets, which is then included in genuine emails from Wise.
Wise offers a feature called a 'Secure Communication Code.' Users can set a unique, private code in their security settings. This code will then be included in most automated and marketing emails sent by Wise, allowing the user to quickly verify that the communication is authentic and not a phishing attempt. Legitimate Wise emails will come from addresses ending in '@wise.com'.
A user receives an email with the Wise logo that urgently warns of 'unauthorized activity' on their account.
The email asks them to click a link to 'verify their identity immediately' or risk account suspension.
Which of the following is the most secure action to take?