Security

At QNB Invest, instead of the SSL-40 bit encryption used by other organizations in the e-business market, a 128-bit encrypted security program is utilized—a standard preferred and used by most brokerage houses in Turkey for enhanced security.

In addition to browser-level encryption, encryption is also performed on the server side to ensure the complete security of our institution and our clients.

For security purposes, QNB Invest prevents the passwords entered by users during login from reflecting on the screen or being seen by others by utilizing stars (masking) in password fields.

To guard against situations where a user leaves their computer while using the QNB Invest internet branch or mobile application, the system automatically logs out based on user preference, thereby preventing unauthorized access. Additionally, to ensure security, login notifications are sent to the user via SMS, also subject to user preference.

You can optionally use a One-Time Password (OTP) when logging into the QNB Invest internet branch or mobile application. In the OTP application, after logging in with your Customer/TR ID Number and Password, a one-time password is sent to your registered mobile phone; access to the site is granted only after entering this code on the subsequent screen.

Your password is the key that grants access to QNB Invest. If your password falls into the hands of others, it means your accounts also fall into their hands. Do not share your password with anyone.

Avoid setting your password using easily guessable numbers and letters, such as names, birth dates, or the founding years of sports teams you support, and change it regularly.

Do not note down your password in places visible to others in your workplace, office, or shared workspaces, nor save it on your computer or browser. Ensure that no one can see what you are typing when entering your password on the screen. When you finish your transactions, close your page by clicking the "Secure Logout" button.

Do not save personal information, identity details, or passwords on your computer or mobile devices. Do not write this information on cards, keep it in your wallet, or save it in your mobile phone's contacts.

Set different usernames and passwords for every channel. Do not use passwords for banking transactions that you use on social media or e-commerce sites.

Never respond to emails that use the QNB Invest name and logo to request personal and financial information (such as account, customer, or credit card numbers).

Cyber attacks can become active through vulnerabilities found in your software. Software companies release updates and "patches" to close these vulnerabilities. You can maintain your security against attacks designed to gain unauthorized access to your personal computer by performing regular updates. Update your computer's security vulnerabilities at regular intervals. For Microsoft environments, visit [http://windowsupdate.microsoft.com](http://windowsupdate.microsoft.com). Use licensed software; do not download free software from unknown sources and avoid using pirated software.

Do not log into QNB Invest from public computers or internet cafes. Connect only from computers that you are certain are secure.

Tens of thousands of viruses circulate on the internet; these can render your computer unusable and steal your personal information. Anti-virus software can scan for existing viruses and identify new ones.

To detect malicious software and prevent it from infecting your electronic devices, install a licensed anti-virus program and perform regular scans. Additionally, update your licensed anti-virus program regularly with its new versions.

Activate your phone's screen lock or keypad lock feature and use a password/PIN to prevent 3rd parties from using your device when it is not under your control.

Turn off your phone's Bluetooth and Airdrop features when not in use. Disabling these features prevents unauthorized access to your phone that could occur without your awareness. Do not accept files from unknown sources received via Bluetooth.

Keeping your phone's operating system up to date improves device performance while providing protection against malware. Grant the necessary permissions on your phone for automatic downloading of operating system updates.

Do not use unlicensed or pirated software, or applications with unknown sources, on your computer and mobile devices.

Download mobile applications only from official stores like Apple App Store, Google Play, and Windows Store. Applications downloaded from other sources may contain malware.

Regarding application and transaction security, verify the access and authorization requests of the applications you use on your computer and mobile devices.

You can protect your computer from unwanted attacks and access by using a Firewall. Utilize Firewall solutions for your personal computer or corporate connection.

Do not connect to wireless networks in public areas if you are unsure of their security. Remember that networks with low security and open public access can be exploited by malicious individuals.

Enable the Network Address Translation (NAT) feature on your firewall device.

Strengthen your network with a reliable encryption protocol and a strong network security password. Using special characters in your password for wireless network security increases its strength.

Ensure that your computer's firewall setting is turned on, keep security software updated, and regularly perform browser updates.

You can provide network security by updating the software versions of your devices that provide internet access.

Communications conducted via email over the internet are not a secure method. Do not use the same passwords for your email programs as those for your QNB Invest internet branch or mobile application.

Do not click on links in email messages, and do not enter any information requested on pages reached via these links. Emails sent by our institution link only to informational pages, not to pages requesting that you enter sensitive data.

If you receive emails that appear to be from QNB Invest but you suspect are fraudulent, please notify us by calling the Investor Support Line at 0212 336 73 73. Never provide your identity information (ID card, Internet Banking account, Credit Card, etc.) to any email requesting it. QNB Invest never asks its customers to provide or update their information via email. If you receive an email requesting your information, report the situation to the Investor Support Line at 0212 336 73 73 without opening the email.

Do not open messages from unknown senders; delete them without downloading. Do not execute any file attached to an email to run an application. Run a virus scan on files received via email before downloading them.

In parallel with the increase in internet usage in recent years, there has been a rise in internet fraud, and various methods have begun to emerge. The online fraud methods you should protect yourself against are explained below.

1) Phishing:

This is one of the most common and dangerous cybercrimes. The purpose of these attacks is to steal information used by individuals or institutions to conduct financial transactions.

The fraudster(s) send fake emails, prepared to look as if they are from a bank, card company, or financial institution, to all email addresses they can obtain. The subject of the email often includes statements intended to urge customers to update their information or change passwords, and contains links to websites that are exact copies of the official institution's pages. Some customers, unaware of the danger, respond to the emails by filling in the requested information. As a result, the customer's personal information and passwords are stolen by the fraudsters.

What information is stolen through the Phishing method?

* Credit, debit/ATM card numbers/CVV2

* Passwords and passcodes

* Account numbers

* User codes and passwords used for logging into Internet Banking

2) Advance Fee or "419 Fraud":

Emails are sent promising a generous reward to the recipient in exchange for assistance in transferring incredibly high-value funds, usually in US Dollars. These funds may be claimed to be anything from company profits, accumulated bribes, or unspent government funds to unclaimed money belonging to a deceased person.

Fraudsters are after bank information. Transfer operations usually require the recipient to make a payment for fees, taxes, or bribes to complete the process. This is the Advance Fee. Such payments are lost.

A recent development involves convincing the recipient that the funds are ready for transfer by directing them to a fake bank website and showing a specific account with a balance of tens of millions of dollars. This money does not actually exist.

It is also common for the recipient's bank information to be used in other scams.

3) Lottery Scams:

A letter or email is sent notifying the recipient that they have won a lottery prize. The recipient must respond to obtain the money. Bank information is then requested so the money can be transferred. Additionally, a processing fee may be requested. This fee will be lost if paid. Furthermore, any bank information provided will likely be used in other frauds.

4) Virus Hoax Emails:

Most virus warning emails sent are merely deceptive messages intended to cause concern and create confusion.

5) Programs like Trojans, Key-loggers, and Screen Loggers:

Viruses known as Trojans serve the purpose of remotely controlling a user's computer. Generally, they consist of two separate modules. While the first module allows malicious users to remotely access and control customer computers, the second module creates a backdoor to establish a connection between the hacker and the customer's computer.

Trojan-style programs are not installed on a computer unless the user permits it. Files with .ini or .exe extensions received over the internet may harbor these small Trojan programs.

A Key-logger can fundamentally be defined as a small program that regularly transfers data to someone else over the internet without the owner's knowledge. Malicious individuals send these programs to remote computers in various ways, either by using a known key-logger or creating a small one themselves. After performing its own installation on the remote computer, a key-logger usually starts working discreetly and transmits the recorded data to the hacker at programmed intervals. It typically captures and transfers all keystrokes.

A Screen Logger works on the same basic logic as a key-logger. However, the data transmitted by screen logger programs is not limited to keystrokes but also includes screenshots. Upon a mouse click on a point on the screen, the screen logger simultaneously captures an image of the entire screen or a small part (usually a small rectangle centered on the mouse) and transmits these to a fixed address over the internet.

Through programs like Trojans, key-loggers, and screen loggers, malicious users attempt to seize customers' personal information.