Mobile Voice Scams Drive Bank Transfer Fraud Surge

Help Net Security · Medium sophistication
Last updated October 1, 2026

Researchers report a sharp rise in scam victims at hundreds of financial institutions, with many scams starting on mobile devices. The article walks through a real scam session where a victim, guided by a phone call and remote access software, nearly sent a high-risk transfer to a new payee. It also highlights how scammers coach victims to ignore bank warnings.

Key findings

  • Reported victims of employment scams “more than tripled” (258% rise) across “more than 370 banks and other financial institutions in 21 countries.”
  • “Nine of every 10 scam sessions now start on a mobile device.”
  • A documented scam session involved an active phone call, remote access software, and behavior consistent with the victim reading payment details aloud to a scammer.
  • Scammers coach victims to resist bank intervention: “The bank will try to stop you. Don’t listen to them. They don’t understand.”
  • Financial sextortion targets minors with relatively small demands (e.g., “$100, $200 or a gift card”) but severe impact.

Who’s being targeted

  • Commonly targeted roles: Fraud operations, Retail banking / branch staff, Contact center agents, Digital banking product owners, Customer education / communications teams.
  • Affected industries: Banking, Financial services, Fintech / P2P payments.
  • Attack channels: vishing.
  • Impersonated: Unspecified scammer on an active phone call (identity not stated), Unspecified scammer on the phone (identity not stated).

Awareness takeaways

  • Train staff and customers that scammers often instruct victims to ignore bank warnings; treat that as a major red flag and slow the transaction down.
  • Add awareness messaging: never stay on a phone call while setting up a new payee or sending money, hang up and verify using a trusted number/channel.
  • Educate teams to treat first-time beneficiaries and out-of-pattern transfer amounts as high-risk indicators that warrant extra verification.
  • Include financial sextortion in awareness programs for families/younger customers: small dollar demands can still be high-risk and urgent.

Red flags to watch for

  • Pressure to ignore the bank’s warnings or intervention
  • Victim is on an active phone call while performing the transfer
  • Transfer goes to a first-time beneficiary and is “well outside the customer’s history”
  • Typing account numbers in unusual chunks with pauses (as if reading aloud)
  • Unusual delay/idle time during sensitive steps
  • Repeated tapping in the same place during review (possible confusion or coercion)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re on your phone, in your banking app, and a voice says: “The bank will try to stop you. Don’t listen to them. They don’t understand.” That’s a real scam script. Nine out of ten of these now start on mobile. The caller keeps you on the line, walks you through adding a brand-new payee, even has you type the account number in little chunks as they read it out. Here’s the tell: you’re on a live call, sending money to a first‑time beneficiary, for an amount way outside normal, and the app pops up warnings you’re being scammed, but the voice tells you to ignore them. If you’re ever on a call and they want you to move money or set up a new payee, here’s the rule: hang up immediately, then call your bank back using the number on their official site or app.

Similar attacks

Interpol Busts Romance, Crypto & Sextortion Rings

Interpol Busts Romance, Crypto & Sextortion Rings

Interpol said an eight-month operation across 22 countries led to 58 arrests tied to cyber-enabled financial fraud, including romance scams, cryptocurrency/investment scams, and business email compromise. Authorities described how scammers build trust with victims (including minors) on social and…

August 25, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Fake IT Support Drives Pix Fraud in Brazil

Fake IT Support Drives Pix Fraud in Brazil

A financially motivated group called Breeze Comet targeted Brazilian financial and retail organizations by impersonating IT support and convincing staff to install remote-access tools. After gaining access, the attackers moved into internal payment systems (like Pix/STR/Boleto) and executed…

September 1, 2026
Bank Imposter Calls Trick Victims Into NFC Card Relay

Bank Imposter Calls Trick Victims Into NFC Card Relay

Researchers reported a real-world phone scam where criminals impersonated a victim’s bank and coached the victim into installing an Android app. The installed remote-access malware let the fraudster silently add a second NFC relay app that streamed the victim’s payment card data to a fake terminal,…

August 14, 2026
Fake Avast Renewal Page Feeds a Support Scam

Fake Avast Renewal Page Feeds a Support Scam

Malwarebytes found a convincing fake “Avast Premium Security” renewal page targeting users in Belgium, claiming a €129.99 renewal and pushing visitors toward a cancellation flow. The real goal is to harvest a victim’s name, email, and mobile number so scammers can call next while posing as support…

September 17, 2026
Fake Avast Renewal Page Lures Victims Into Calls

Fake Avast Renewal Page Lures Victims Into Calls

Researchers found a realistic-looking fake Avast renewal page that claims a subscription renewed for €129.99 and pushes victims to “cancel” by entering their name, email, and mobile number. The charge is fake, and the real goal is to collect contact details so scammers can follow up with a phone…

September 16, 2026