Your Cookies are Disabled! NationalNotary.org sets cookies on your computer to help improve performance and provide a more engaging user experience. By using this site, you accept the terms of our cookie policy. Learn more.

Protecting Notaries and signers from data breaches and online fraud

A lock with fingers

The epidemic of cybercrime has made nonpublic personal information (NPPI) a hot topic — and that is especially true for Notary Signing Agents and everyone else working in the mortgage lending industry.

While protecting a borrower’s personal information has always been a priority, lenders, title companies and settlement services firms have ratcheted up their efforts to keep NPPI out of the wrong hands. Virtually every piece of information you receive — from the closing confirmation to the loan package — should be considered sensitive information.

How Signing Agents treat that information has never been more crucial. Items such as the borrower’s phone number, loan amount, interest rate and email addresses now fall under the umbrella of NPPI. Just knowing that a person is refinancing and who their lender is could be considered NPPI. There are a number of practices we should follow to help keep our customer’s information safe and protect ourselves from suffering a data breach. They fall under two broad categories.

Email and phishing fraud prevention practices for Notaries

Email is one of the most common ways cybercriminals attempt to gain access to sensitive information. Fraudulent emails can look remarkably similar to legitimate messages from title companies, lenders, signing services and other familiar businesses. Some may even appear to come from a person you have worked with before. Before clicking a link, opening an attachment or responding to a request for information, take a moment to carefully examine the message.

  • Check the sender’s complete email address — not just the name displayed in the “From” field. A familiar name can be paired with an unfamiliar or fraudulent email address.
  • Look closely at the domain name for misspellings, added letters, substituted characters or slight variations. For example, a fraudulent address may replace a letter with a similar-looking number or add a word to a legitimate company’s domain.
  • Be cautious when the sender’s name does not match the actual email address or when someone who normally uses a company email address suddenly contacts you from a personal account.
  • Review the message for spelling mistakes, grammatical errors, unusual formatting or language that does not sound like the person or company supposedly sending it. Although fraudulent emails have become more sophisticated, inconsistencies may still be a warning sign.
  • Be suspicious of unexpected urgency, threats or pressure to act immediately. Scammers often try to prevent recipients from taking the time to verify a request.
  • Do not click on links simply because the message appears to come from a familiar company. Hover over the link, when possible, to preview its destination. When in doubt, open your browser and navigate to the company’s known website independently rather than using the link in the email.
  • Treat unexpected attachments — including PDFs, Word documents, spreadsheets, ZIP files and electronic signing invitations — with caution. Even an attachment that appears to be a closing package, confirmation or invoice could contain malicious software.
  • Before opening an attachment, confirm that you were expecting it and that the sender intended to send it. Save questionable files without opening them and scan them with updated antivirus or security software. Never disable security features or enable macros simply because an attachment instructs you to do so.
  • When available, retrieve documents directly through the title company’s, lender’s or signing service’s secure portal rather than through an unexpected email attachment.
  • Independently verify any unexpected request for NPPI, login credentials, payment information, banking changes, document redirection or updated shipping instructions. Contact the company using a phone number or email address you already know — not the contact information supplied in the questionable message.
  • If you receive an unexpected message from someone you know, do not assume it is legitimate. Their email account may have been compromised. Contact them separately to confirm the request.

If something about an email feels unusual, stop and verify it. A few minutes spent confirming the sender could prevent the exposure of a signer’s information, the compromise of your email account or a much larger financial loss.

Technology practices to prevent online fraud and privacy breaches

Computers, mobile devices and the internet have been a boon to business transactions the world over. But the convenience and efficiency of technology has also made it easier for criminals to target high-value transactions, such as mortgage originations. So the companies that contract with NSAs expect us to be diligent. The following practices will go a long way toward meeting those expectations:

  • Never take a picture of a borrower’s ID. I cannot stress this enough. You should never store any personal information about a consumer on your phone. It could accidentally be saved to a SIM card or your Dropbox account, or you may just forget to delete it. If your phone is hacked or stolen, a thief will get a photo of someone’s driver’s license. Many Notaries email the photo of the license from their phone. If you use a public Wi-Fi network or unencrypted email, that email could easily fall into the wrong hands.
  • All emails with NPPI should be either encrypted or password-protected.
  • Never send documents back to title companies or the lender by email unless they are password-protected. If you don’t have the ability to do so, then faxing is the better option.
  • Pay close attention to the emails you receive from the title company, lender or anyone else involved in the loan. Does the sender’s address look correct? Does the signature line look correct? Are they asking you for something that seems a bit off? When in doubt, call the sending party and verify.
  • Use a long, unique password or passphrase for every business account. Never reuse the same password for your email, document platforms, banking accounts and other services.
  • Consider using a reputable password manager to generate and securely store unique passwords.
  • Enable multifactor authentication on your email, document portals, cloud storage, accounting software and any other account that contains business or signer information. Whenever available, use a passkey, security key or another phishing-resistant authentication option.
  • Change a password immediately if you believe it has been exposed, reused on a compromised account or accessed by someone else. Do not approve an unexpected multifactor authentication request.
  • All technology items should be password-protected, including computers, smartphones and tablets.
  • Your computer should be set to lock out automatically after a short interval of time, such as 15 minutes.
  • Install, use and regularly update anti-virus and anti-spyware software on every computing device you use. This protects your information from viruses, spyware and other malicious code.
  • Install patches to your operating systems and applications. Software providers regularly identify vulnerabilities in their products and release patches and updates to correct these problems. Make sure to apply all updates as they are released.
  • Back up your data. Computers die, hard disks fail, people make mistakes and malicious programs can destroy data. Important information should be backed up regularly so you can recover any lost data quickly. It’s best to set up automated back-ups, and many security software products offer this function.
  • Make sure to encrypt the data on your smartphone. Many phones offer encryption options, and there are numerous apps available for download.
  • Do not use public Wi-Fi access because it is typically not secure. You should also hide your home Wi-Fi network and change the default password to a more secure one.
  • Protect your Internet connection. If you have a broadband Internet connection, make sure the router includes a firewall. However, when you connect to the Internet, install firewall software on every computer you use.
  • Many NSAs are tempted to print or copy loan packages at Staples, OfficeMax or other retail stores. But most printers and copiers have hard drives that store information long after you have departed. That allows multiple parties to access your borrower’s information.
  • Limit access to any technology you use for work. That includes keeping your home computer and other devices secure from your own family. They might inadvertently do something that exposes NPPI. It’s also a good idea to avoid surfing the web on the same computer you use for work because that can increase exposure to viruses, malware and other cyberattacks, which could lead to a potential breach.
  • Never post a signer’s personal information on social media. I have seen Notaries asking for assistance on social media about how a document should be executed and inadvertently failing to redact all the signer’s information. Imagine if that were your personal information on the Internet for the whole world to see. 
  • Keep business and personal email separate whenever possible. Using a dedicated business email account can make unusual messages easier to recognize and can limit the exposure of business information if a personal account is compromised.
  • Do not automatically forward business email or closing documents to a personal account. Forwarding can place NPPI outside the company’s approved security environment and create additional copies of sensitive information.
  • Review cloud-storage sharing permissions regularly. Remove files and revoke links when they are no longer needed, and avoid creating public links to folders containing signer or transaction information.
  • Enable automatic security updates whenever possible. This includes updates for your operating system, internet browser, PDF reader, email application, smartphone and document-signing software.
  • Develop a basic incident-response plan. Know whom you will contact, which passwords you will change and how you will preserve information if your email, computer or business account is compromised.

Low-tech practices for Notaries to prevent online fraud and privacy breaches

Not every risk comes from a cybercriminal. And not every data breach involves the internet. A borrower’s NPPI can be compromised by a variety of old-fashioned lapses.

  •  Any documents you print, such as the closing confirmation or loan package, should be stored securely in a locked cabinet — but only as long as you need them. Once those documents are no longer necessary, dispose of them using a shredder or reputable shredding service. A loan package in your trash can is a data breach waiting to happen.
  • Use caution with utilizing outside services such as computer repairmen, shredding services and copier repair companies. Make certain you have fully vetted them, and limit their access to what could be considered NPPI.
  • Never share details of a closing with someone outside of the transaction. Saying something as simple as, “Hey I closed a loan for Mrs. X. Remember her? She was our old lunch lady,” could be considered a breach of information.
  • Make sure you handle all of your packages yourself, and keep them secure until you drop them off. Never leave them with a receptionist who keeps a stack of packages on their desk or with a friend who is going to drive by FedEx anyway. Documents should be locked in the trunk of your car or in a locked file cabinet at all times. Try to use a FedEx or UPS location instead of a drop box whenever possible.

Try to find potential weaknesses and tighten up your security. A data breach could have disastrous results — from destroying your reputation, to a financial loss for your customers to a potential lawsuit. Most breaches of technology are not covered under your E&O insurance and the expense of defending a lawsuit could be exorbitant, and potentially close the doors on your business. Don’t let that happen to you. One of the best ways to approach protecting your customer’s information is to treat it as though it were your own.

Quick Checklist for NPPI Protection

Technology Practices:

  • Encrypt all emails and files containing NPPI.
  • Avoid storing borrower information on personal devices.
  • Use strong, unique passwords and change them every 180 days.
  • Keep all devices password-protected and set to auto-lock after 15 minutes.
  • Install and update antivirus, anti-spyware, and firewall software.
  • Avoid public Wi-Fi; use a secure VPN if necessary.
  • Back up data regularly with automated tools.
  • Apply software updates and patches as soon as they’re available.

Low-Tech Practices:

  • Store printed documents securely and shred them when no longer needed.
  • Keep loan packages in a locked trunk or cabinet until delivery.
  • Avoid sharing borrower details with anyone outside the transaction.
  • Vet third-party services (e.g., shredding or repair) before use.
  • Personally deliver packages to secure FedEx or UPS locations, avoiding drop boxes.

Professional Habits:

  • Verify email requests with the sender before sharing sensitive information.
  • Never photograph borrower IDs or documents.
  • Stay informed on cybersecurity best practices and industry updates.

Emergency Preparedness:

  • Develop a response plan for potential data breaches.

Contact your hiring entity or state Notary agency for guidance on privacy concerns.

If you have questions about a potential privacy issue during a notarization, the best course of action is to reach out to your hiring entity to determine what needs to be done. You can also contact your state Notary regulating agency or the NNA.

Marcy Tiberio is the 2025 Notary of the Year and owner of Professional Notary Services, Inc., in Rochester, New York. She can be reached at marcy@professionalnotaryservices.biz.


Related Articles:

Notary Trends: Thumbprints and privacy issues


Additional Resources:

NSA Privacy and Security Self-Assessment Test

Common data security terms


4 Comments

Add your comment

Betty

04 Jul 2023

My atty has instructed me to keep my briefcase where I transport loan documents, in my trunk and never leave a FedEx or UPS mailing envelope in sight in my locked car. Thieves can believe that they contain checks and will break in and steal them. Everything goes into my car's trunk until I drop.for shipment.

Jerry Lucas

03 Jul 2023

NIST security standards do not recommend changing passwords unless a security breach is known or suspected. Many users have hundreds of accounts. It is a waste of time to change hundreds of strong unique passwords that use high entropy. I switched to BitWarden, a very popular password manager. They have free or paid versions. Encryption should be AES 256 or stronger. As quantum computers become more available, they will be able to quickly crack weaker encryption algorithms. Use Post Quantum Cryptography (PQC) where available. It is designed to be resistant to quantum computer attacks. Stop using free snoop mail an snoop storage from Big Tech. They are reading your email and files. Use encrypted email and cloud storage such as ProtonMail and ProtonDrive.

Jerry Lucas

21 Jun 2021

Whenever available, use two-factor authentication (2FA), so using a password alone is not enough to log in to an account. Use a long, strong, unique, random password for each account. Store passwords in an encrypted password manager such as LastPass.

Barbara Holland

21 Jun 2021

We are required to take pictures of IDs all of the time. Designers don't have copy machines so we have to take a picture and either email it to the company or come back home loaded on our computer and print the copy ourself to put in the package. So why are these companies asking us to take pictures

Leave a Comment

Required *

All comments are reviewed and if approved, will display.

Close