Back to blog

The Scourge of Fake Bank Advisor Scams

JA
Jean-Baptiste Artignan
CEO
April 12, 20245 min read
The Scourge of Fake Bank Advisor Scams

In a world where technology has transformed the way we conduct financial transactions, scams perpetrated by fake bankers have become an ever-present threat. These scams, often carried out over the phone, exploit people’s trust to steal their personal information and, above all, their money. As these scams doubled in 2023, raising awareness about the techniques used and the right behaviours to adopt has become essential.

Collecting personal data

It all begins with collecting bank customers’ personal data in order to appear credible during the call. There are several ways to obtain this information:

  • Phishing: Scammers send fraudulent emails or SMS messages claiming to be genuine bankers. Most often, they ask recipients to provide personal information such as account numbers, bank card numbers, passwords, or Social Security numbers under the pretext of account verification or a security update.
  • Fake websites: Fake bankers create websites that closely mimic those of real banks. These sites may look authentic at first glance, but they are actually designed to steal users’ login credentials. The customer logs in using their banking credentials on this malicious site, believing it to be the official website. The information can then be retrieved very easily.
  • Credit card fraud: Some scammers use skimming devices to copy customers’ credit card information when they make transactions or withdrawals at ATMs. This information is also collected to contact customers later.

FOCUS ON SKIMMING

Skimming refers to a fraud method that primarily targets bank cards, generally carried out at ATMs. Although it emerged in the 2000s, this practice is still very much relevant today. Nowadays, it is evolving and can apply to other contexts, using methods other than ATMs, such as contactless payments. Skimming involves copying the information stored on the magnetic stripe of your bank card using a device inserted into an ATM. This device, known as a “skimmer,” records card numbers, card verification values (CVVs), and expiry dates. Once this data has been collected, fraudsters find ways to obtain your PIN, often by using a hidden camera in a fake overhead panel or by installing a fake numeric keypad.

There is also “web skimming,” a type of attack that involves stealing sensitive information from websites. To do so, attackers inject a piece of code or malware into the payment page of an e-commerce website.

The modus operandi

Once the basic information needed to make the fake banker credible has been collected, scammers call customers. This is made even more realistic because scammers are able, using software, to spoof the bank’s phone number (a technique known as phone spoofing). They pose as bankers or fraud department representatives trying to reach them because fraudulent activity has been detected on their account.

The victim feels confident because the fake banker already knows their first name, last name, and date of birth. Fake bankers try to convince victims to disclose their financial information by using pressure and urgency. The scammer explains that the only way to stop the fraud is to provide the account passwords and card codes.

If the attacker is already in possession of the bank card numbers (often stolen through phishing), they will generate a real-time transaction while on the call with their victim. They will then ask the victim to approve the transaction in their smartphone app or through a received SMS message, claiming that it is an action intended to cancel a fraudulent transaction. In reality, it is a genuine payment made by the scammer that the victim is about to confirm.

Through trust and, above all, haste, the customer provides scammers with all the information they need to access their bank account. Scammers exploit the crisis situation to put pressure on the victim. They claim that action must be taken quickly to prevent money from being stolen and to block these fraudulent transactions.

How to protect yourself against fake banker scams

To protect yourself against scams carried out by fake bankers, it is essential to adopt strong security practices:

  • Verify authenticity: Before providing personal or financial information online, make sure to verify the identity of the financial institution. Visit its official website by manually entering the address into your browser’s address bar rather than clicking links in emails or text messages. The same applies to the identity of the person calling you. Even if the situation feels urgent, it is best to hang up and call your bank yourself to check whether the banker who contacted you really works there. You can even visit your bank directly.
  • Be wary of requests for personal information: Be skeptical of unsolicited requests for personal information. Legitimate banks will never ask their customers to provide sensitive information by email or phone. They are aware of these scams and will therefore never behave in this way.
  • Monitor your accounts: Regularly monitor your bank accounts and credit card statements for any suspicious activity. Report any unauthorized transaction to your bank immediately.
  • Use security technology: Protect your devices with reliable antivirus and antimalware software to reduce the risk of malware infection. In addition, enable your bank’s security notifications and transaction alerts to be informed in real time of any suspicious activity on your account.

In conclusion, scams carried out by fake bankers represent a serious threat to individuals’ financial security. By adopting rigorous security practices and remaining vigilant for potential warning signs, consumers can significantly reduce their risk of falling victim to these sophisticated scams.

BlueSecure offers cybersecurity awareness solutions that help identify phishing attempts via emails, SMS messages, and phone calls, helping raise your level of vigilance in both your personal and professional life. Feel free to contact us to find out more.

To explore the topic further, here is a video by Micode, who infiltrated a network of SMS scammers and discusses the entire technical aspect:

By

JA

Jean-Baptiste Artignan

CEO

Share this article