Your Security. Our Priority.

A Few Words on Security

We work hard to protect your confidential information and privacy when dealing with us online. A secure login process and strong encryption are only the first steps in helping to prevent others from accessing your account information online.

When you connect to the Internet, the Internet also connects back to you. Even before you connect to the Bank's web site, someone out there could potentially get access to your computer. Also, as you surf the Internet, there is a trail of information left behind.

The Canadian Banking Association and American Banking Association offers monthly fraud prevention tips via e-mail. Find out what you can do to protect yourself by signing up today to receive their tip of the month.

Back to top

100% Online Banking Guarantee for Personal Banking Customers

Our promise: We will reimburse you 100% for any losses to your Personal Banking accounts resulting from unauthorized transactions through Online Banking.

To ensure reimbursement under this guarantee, there are a few steps you’ll need to take to protect your debit card and your online banking password as outlined in our Electronic Banking Services Agreement.

These steps include:

You may not be reimbursed if you did not comply with the steps listed above or if you knowingly disclosed your password or debit card and it resulted in losses.

For more information on how BMO protects you when you bank online, please review How BMO Protects You. You can also learn more about how you can safeguard your computer.

Back to top

Security Considerations for Safe Online Banking, Investing, Credit Card and Insurance services

What We Do

Some of the security measures we have in place to help protect you when using our Online Banking, Investing, Credit Card and Insurance services include:

Back to top

Security Considerations for Safe Online Banking, Investing, Credit Card and Insurance services

What We Do

Some of the security measures we have in place to help protect you when using our Online Banking, Investing, Credit Card and Insurance services include:

What We Don’t Do

What You Can Do

Here are some of the security measures you can take to protect your confidential information when you use the Internet:

1. For Online Banking, Online Investing, Credit Card and Insurance Security

Do The Following:

Avoid the following:

2. For General Computer Security

Take these steps:

Avoid the following:

3. For General Financial Services Security

Do the following:

Avoid the following:

Remember:

Back to top

Beware of software downloads with offers of "free services"

Organizations that capture information about usage and buying behaviour patterns on the Internet are now emerging. Some of these organizations monitor individual Internet activity through software downloaded to your personal computer or on a public computer you use.

This includes everything you type on your computer: your card numbers, account numbers and passwords. It also includes the personal and confidential information on the secure pages that you browse and the personal and confidential information you provide when you use our otherwise secure online applications (e.g. loan applications, mortgage applications and online account opening applications).

You may have knowingly downloaded this software in exchange for free services, or you may be unaware that it is on your PC (for example, if you download several software programs bundled into the same download).

"Beware" of downloading software with offers of "free email virus protection" or a "no cost Internet accelerator" or other such enticements if you have to give up your privacy and the security of your online financial transactions. These offers can result in a third party company monitoring your Internet activity.

Understand the risks – don’t compromise your privacy and online security

Some of these companies monitor all of your Internet behaviour, including your normal web browsing and the activity you may have through secure sessions, such as shopping or filling out an online application form that may contain your personal financial information.

When you access our secure online services (e.g. Online Banking, Online Investing or Online Credit Cards services) on PCs that have this monitoring software installed, your otherwise secure session information runs through third party computers and gives the third party access to your confidential information.

We do what we can to provide you with a safe and secure online environment. We also need you to take the appropriate measures to secure your personal computing environment. We strongly recommend that you avoid using computers with third party monitoring software installed when you conduct your online financial transactions with us to safeguard your privacy.

Removing Third Party Software from your computer

Removing such software from your PC can be difficult. We suggest that you install and run spyware detection software*. For more information on removing spyware from your PC, search the keyword "spyware removal" through any of the following:

"Marketscore" and "Netsetter" are two known examples of Internet usage monitoring programs. Although they may not strictly qualify as "spyware", we do not recommend that you use PCs to conduct financial transactions with us when "Marketscore" and/or "Netsetter" software is installed.

*Please note that removing third party software from your PC can be difficult. You may want to consult a trusted third party that specializes in computer maintenance and repair for assistance.

Back to top

How to Protect Yourself from "Phishing" and Email Scams

You may have experienced or read about recent incidents of unsolicited email messages masquerading as legitimate companies that trick recipients into divulging personal and financial information.

These "phishing" (also called "brand spoofing") emails send you to web sites pretending to be legitimate companies that ask for your personal and financial information.

At no time do members of BMO Financial Group request personal or financial information by sending out unsolicited emails. You should never send personal identification numbers or other personal confidential information by email as it is not a secure method of contact.

How The Scams Work

A common email scam uses unsolicited email to deceive consumers into disclosing confidential personal information. The deceptive email suggests clicking on a link or attachment for any one of the following reasons:

After clicking on an attachment or link from the unsolicited email, the user is taken to a bogus site that requests confidential personal information, which could include:

How to Identify the Scam

There are some commonalities that can help you identify the scams:

To ensure delivery of Emails be sure to follow these best practices:

  1. Login to your BMO customer profile and update your Email address with your primary Email address (the one you most frequently use)
  2. Once an initial Email is established, add the BMO Email address to your Email address book so that BMO is a trusted sender for your provider

How To Help Protect Yourself

It is important to understand that there are ways in which you can help protect yourself from email fraud and web sites that request your personal or banking information:

BMO Bank of Montreal Online Banking: 1 8 8 8 7 2 5 9 8 0 1
BMO InvestorLine: 1 8 8 8 7 7 6 6 8 8 6
BMO Nesbitt Burns: 1 8 7 7 8 7 3 7 6 6 4
BMO Mutual Funds: 1 8 0 0 6 6 5 7 7 0 0
BMO Private Wealth U.S. 1 8 0 0 8 4 4 6 4 4 2
U.S. Digital Banking: 1 888 340-22651 8 8 8 3 4 0 2 2 6 5
BMO MasterCard: 1 8 0 0 2 6 3 2 2 6 3

Back to top

Secure Email Encryption

BMO Financial Group never requests personal or financial information through unsolicited emails. For further assistance, contact your Customer Service Centre using published phone numbers (e.g. on the back of your credit/debit card or published on bmo.com or bmo.com/en-us/).

BMO Financial Group is committed to providing you with a secure banking environment that protects your personal and financial information. Recently, we introduced an email function to scramble (i.e., encrypt) any personal, financial, or confidential information that we send you through email. Email encryption transmits and stores information in a format that is only accessible to parties with the correct password.

When you receive your first secure email from BMO Financial Group, you are asked to visit a website to register a username and password. This one-time registration process is simple and only takes a few minutes to complete. After registration, you can read and respond to any secure email. Any responses or new messages are also encrypted. You cannot register in advance at this site; you must wait until you receive your first secure email.

All secure emails from BMO Financial Group require you to login to the website before you can read it. You can also compose new secure email messages to other recipients at BMO Financial Group by visiting the website (https://secureportal.bmofg.com). There is no charge for this secure email service.

If you receive suspicious emails from BMO Financial Group, call the sender to confirm its authenticity. For more information about BMO Financial Group' s encrypted email service, visit our list of frequently asked questions.

Back to top

How to Protect your Debit Card and PIN

Canadians use debit cards millions of times a day at banking machines and point-of-sale terminals to access their accounts and make purchases.

About debit card usage:

Taking steps to protect your debit card and PIN will help reduce your own risk of being a victim of fraud.

Here are some tips to help protect your debit card and PIN:

  1. Change your PIN often to protect your financial information. You can now change the PIN on your BMO FirstBank Card and BMO MasterCard at any BMO ATM, 24 hours a day, 7 days a week.
  2. Use your hand or body to shield your PIN when you are conducting transactions at an ATM or at a point-of-sale terminal.
  3. Never let your banking card out of your sight when conducting a transaction at a point-of-sale terminal. Always remember to take your banking card and transaction record with you once your transaction is completed.
  4. Regularly check your statements and balances to verify all transactions have been properly documented. If entries do not accurately reflect transaction activities, for example, if there are missing or additional transactions, you should contact your BMO Bank of Montreal branch immediately.
  5. If your banking card is lost, stolen or retained by an ATM, notify your BMO Bank of Montreal branch immediately.
  6. Your banking card and PIN are the keys to your account(s). Never disclose your PIN to anyone … not even us. You are the only person who should know it.
  7. Memorize your PIN - it's your electronic signature. If you suspect that someone knows your PIN, change it immediately or contact your BMO Bank of Montreal branch to cancel the card.
  8. When selecting your PIN, never use obvious information - such as, your telephone number, date of birth, address or social insurance number for Canadian residents and social security number for U.S. residents.

For further information, you can also visit the following sites:

Canadian Bankers Association
Interac®* Association
American Bankers Association

Back to top

Extended Validation (EV) SSL Certificate

Over the next several months, BMO will be upgrading the security of our websites with extended validation (EV) SSL Certificates to further protect you from fraudulent activity. Customers using Internet Explorer 7 or Firefox 3.0.4 (or later versions) will notice the following:

image of two U R L address bars stacked on top of each other. First address bar has the words ‘bank of Montreal C A in the top right corner. Second address bar has the words ‘phishing website’ in the top right corner.

If you do not see the updated green address bar, you can continue to be assured that your online session with us is just as secure as it has always been. If you are not using the browsers listed above, or the site has not been updated to EV, legitimate BMO websites will have the following:

image of a web page with the U R L address bar and a padlock icon in the I frame.

For more information about Extended Validation SSL Certificates, visit our list of frequently asked questions.

Back to top