Online Security

H&R Block Bank works diligently to keep your account and personal information secure. H&R Block Bank strives to maintain and/or exceed all physical, electronic, and procedural safeguards per the financial industry standards to protect our clients' personal information.

We protect your account and personal information by:

  • Only placing it on secure pages of our Web site.
  • Requiring you to use a username and password of your own choosing to enter the secure pages of our Web site.
  • Using up-to-date security technology (e.g., firewalls) to protect our network and systems from external attacks.
  • Enabling our servers with Secure Sockets Layer (SSL) technology that prevents unauthorized individuals from viewing any non-public personal information that you may provide or view during a session on the secure pages of our Web site. (To know that you are on a secure page, look for the padlock icon in the bottom right-hand corner of your screen.)
  • Employing Verisign's digital certificate of services to authenticate your identity every time you access the secure pages of our Web site.

Security Tips

Internet Scams: Pharming & Phishing

"Pharming" is the process of redirecting Internet domain requests to false Web sites to collect personal information. Information collected from these sites may be used to commit fraud and identity theft.

"Phishing" is a term used to describe an attempt by someone to obtain your personal or financial information by deception or fraud. Phishing most commonly occurs by spam e-mails or pop-up messages. Someone may send a message pretending to be from H&R Block Bank to hundreds of thousands of people. The sender may only expect one or two people to actually respond to the e-mail or pop-up. The e-mail or pop-up could even contain H&R Block Bank logos and might even resemble an actual H&R Block e-mail. As part of a phishing attempt, there is usually a Web site created that attempts to mimic a real H&R Block Web site. The goal of a phishing attempt is to trick you into clicking on a link in the e-mail or pop-up and to visit a fake Web site and provide your username, password, or other personal or financial information. Once the person collects your username or password they could then access your H&R Block Bank user account, or use your information for other improper purposes such as identity theft.

We have provided the following guidance to help you distinguish between phishing attempts and legitimate H&R Block Bank e-mail communications.

We have provided the following guidance to help you distinguish between phishing attempts and legitimate H&R Block Bank e-mail communications.

  • We will not send e-mails to you urgently requesting information of any kind.
  • We strongly suggest that you do not share your username, password or account information with anyone.
  • All of our Internet sites in which you are asked to enter personal or financial information are protected via HTTPS. Verify that the "padlock" icon on your browser is present when entering information of this nature.
  • Use common sense. If the timing or content of an e-mail seems odd, be suspicious.

Frequently Asked Questions

How can I detect a fraudulent e-mail?

It's often hard to detect a fraudulent e-mail. That's because the e-mail address of the sender often seems genuine (for example, support@hrblock.com), as do the design and graphics. There are, however, telltale signs. Fraudulent e-mail often tries to create a false sense of urgency. Some will suggest you must provide personal information immediately to protect your account or to avoid having your tax return rejected.

How can I be sure that I am receiving a legitimate H&R Block Bank e-mail?

  • If we request information, we always direct you back to hrblockbank.com.

If you have any doubt, don't click on a link in an e-mail. Instead, type the URL (e.g., www.hrblockbank.com) directly into your Internet browser navigation bar.

How can I help protect myself?

We want your online experience to be enjoyable and worry-free. H&R Block Bank uses high levels of encryption and other security procedures. We also want to make you aware of several simple security tips to keep in mind:

  • Use a strong password. Choose passwords that are difficult for others to guess, and use a different password for each of your online accounts. Use both letters and numbers and a combination of lower case and capital letters if the passwords or PINS are case sensitive.
  • Leave suspicious sites. If you suspect that a Web site is not what it purports to be, leave the site immediately. Do not follow any of the instructions it presents.
  • Be alert for scam e-mails. These may appear to come from a trusted business or friend, but actually are designed to trick you into downloading a virus or jumping to a fraudulent Web site and disclosing sensitive information.
  • Don't reply to any e-mail that requests your personal information. Be very suspicious of any e-mail from a business or person that asks for your password, Social Security number, date of birth or other highly sensitive information, or one that sends you personal information and asks you to update or confirm it.
  • Open e-mails only when you know the sender. Be especially careful about opening an e-mail with an attachment. Even a friend may accidentally send an e-mail with a virus.
  • Be careful before clicking on a link contained in an e-mail or other message. The link may not be trustworthy. If you are in doubt about a link, type the URL (from the table above) into your browser's address bar to ensure that you are going to a genuine H&R Block Web site.
  • Do not send sensitive personal or financial information unless it is through a trusted Web site that uses encryption. You will know if a Web site uses encryption if your Web browser displays a closed padlock symbol at the bottom and the web address begins with "https". The "s" indicates a secure connection.
  • Do not send sensitive personal or financial information via e-mail. Regular e-mails are not encrypted.
  • Do business only with companies you know and trust, and don't hesitate to contact them if you question an e-mail that seems odd or asks for personal information.
  • Phony "look-alike" Web sites are designed to trick consumers and collect their personal information. Make sure that Web sites on which you complete transactions post privacy and security statements, and review them carefully.
  • Make sure your home computer has the most current anti-virus software. Anti-virus software needs frequent updates to guard against new viruses.
  • Make sure you download the anti-virus updates as soon as you are notified that a download is available.
  • Install a personal firewall to help prevent unauthorized access to your home computer. This is especially important if you connect to the Internet via a cable modem or a digital subscriber line (DSL) modem.
  • Monitor your transactions. Review your order confirmations, and credit card and bank statements as soon as you receive them to make sure you're being charged only for transactions you made.

As your trusted financial partner, H&R Block Bank is committed to keeping your information safe.

Other Resources:

Federal Trade Commission:
Stop Think Click 
Federal Trade Commission: Your National Resource About ID Theft 

Federal Deposit Insurance Corporation
Don't Be an On-line Victim: How to Guard Against Internet Thieves and Electronic Scams 

Need Live Support? 1-800-HRBLOCK (1-800-472-5625) or Find An Office