The article describes real-world social engineering aimed at both consumers and financial firms, including phone-based attacks on hedge funds and a turnkey scam kit that impersonates Tesla to steal cryptocurrency. The kit uses a professional-looking fake presale website with urgency tactics (countdown timers and fake progress bars) to push victims into handing over their wallet recovery phrase or sending crypto directly to scammers.
Key findings
- BioCatch reports impersonation scams targeting U.S. consumers “more than doubled between 2025 and 2026.”
- Investment scams are described as the biggest driver of losses, using “spoofed websites and fake broker platforms to create a false sense of urgency.”
- Reuters reports phone-based social engineering attempts against hedge funds and private equity firms, including Point72, Two Sigma, and Citadel.
- Malwarebytes uncovered a $500 turnkey kit linked to threat actor “xrep” that impersonates Tesla in a fake cryptocurrency presale.
- The Tesla-branded kit uses personalization (victims’ X profile pictures), fake progress bars, and countdown timers to pressure quick action.
- Victims are funneled into either sharing their “12-word recovery phrase” (wallet takeover) or sending crypto to scammer-controlled addresses.
Who’s being targeted
- Commonly targeted roles: Retail banking customers, Wealth management / investor relations, Hedge fund and private equity employees, Finance operations, IT helpdesk / service desk, Fraud prevention teams.
- Affected industries: Banking, Hedge funds / private equity, Cryptocurrency investors / financial services consumers.
- Attack channels: website, vishing.
- Impersonated: Tesla, Internal IT/helpdesk or a trusted service provider (not specified in article).
Awareness takeaways
- Train staff and customers to treat unsolicited investment opportunities as high-risk, especially when they create urgency with fake websites and dashboards.
- Make it a hard rule: never share a crypto wallet recovery phrase, anyone asking for it is trying to take over the wallet.
- Prepare employees for phone-based social engineering by requiring identity verification and call-back procedures before discussing access or account/security changes.
- Assume scammers can buy professional ‘scam kits’ and will look legitimate; focus training on behavioral red flags, not just “poor spelling” cues.
Red flags to watch for
- Any “investment” asking for a wallet recovery phrase is a takeover attempt
- Urgency pressure via countdown timers / progress bars
- Personalization designed to build trust (e.g., using your profile picture) without proof of legitimacy
- Unsolicited phone requests tied to system access or urgent security issues
- Caller pressure to bypass normal verification steps
- Requests for sensitive information that would allow system access
Read the video transcript
You see a slick Tesla crypto presale site, your X profile photo on it, countdown ticking down. Looks legit, right? Behind that page is a $500 turnkey scam kit, used to impersonate Tesla and push you into one of two things: typing your 12-word wallet recovery phrase, or sending crypto straight to their address. Here’s the catch: real investments never ask for a recovery phrase. That’s the master key. BioCatch says these impersonation scams have more than doubled, and scammers now buy pro-grade kits instead of making sloppy sites. If any “investment”, Tesla or otherwise, asks for your 12-word recovery phrase, stop. Close the site. Then report it to security.