Financial Phishing Alive and Well and BLOCKED in 2023
Photo by Nikita Belokhonov

Financial Phishing Alive and Well and BLOCKED in 2023

Phishing and SMiShing attacks are looking more professional by the day. Criminals are using classic multi-channel marketing tactics to get their campaigns into your mobile inbox in every way possible. We see MMS, SMS, and RCS attacks stay on-net and over inter-carrier routes via SIM Farms and OTT exploits.

Our machine learning inference API detects fraud in images and in text across any channel. As first quarter 2023 comes to a close we will have detected and blocked nearly 200 million spam and fraud messages from reaching your mobile company and your phone. The predominant class of attacks we see are financial in nature, such as crypto key requests, fake password reset links, low fund alerts, and imposter help desk call backs.

Criminals also love to create false urgency-- if they can scare you with an official-looking text, the more you'll trust the perp to help you solve your problem. Here's a recent snapshot of campaigns we've detected and blocked.

[Chase Bank] Your OTP Code is 83079241.If you didn't request for code, secure your account ( #<REDACTED FRAUDULENT PHISHING LINK> )

  • While this looks semi-legit, when you go to the link I redacted, you'll enter your banking credentials and your account might be taken over. You must enable two-factor authentication for your banks ASAP to prevent this from happening to you.

Free Msg BofA: Recently, we discovered unusual activity or updates on your account that we believe may be unauthorized. For your security, Bank of America monitors all transactions to protect your account from misuse; You will not be able to use the ATM/Debit/Credit Card linked to this account for withdrawals or purchases until you verify your information. Visit us at <REDACTED FRAUDULENT PHISHING LINK> to secure your account.

FirstBank Trust: Your FirstBank Trust account has been temporarily suspended due to suspicious activites. Click on the link below to reactivate and verify your account to continue using.?

PNC Bank Alert:Your account is now under review. You are required to validate some details at this time to avoid any interruptions in your service; <REDACTED FRAUDULENT PHISHING LINK> Msg&Data Rates May Apply.

  • Like the previous example, these three try to get you to enter your credentials on an imposter website. The criminal employs the notion that a state of emergency will reduce your capacity for rational thought.

Need funds for the new year? Get an offer & funded in 24-48hrs! Apply Online <REDACTED FRAUDULENT PHISHING LINK> TxtSTOPtoEnd

Michael, We can help you return to CoIIege with a 6895.oo EducationaIGrant and other aid. It does not have to be repaid. <REDACTED FRAUDULENT PHISHING LINK>

  • Loan scams are still an effective way for criminals to get your personal information. Not only will you not get any money, your information will be sold and possibly used by more complex scams involving identify theft.

New Tax Relief programs have just launched to help you eliminate your back taxes and get a fresh start, call now for more info <REDACTED PHONE NUMBER> Reply STOP to CA...

  • Tis the season for the classic tax relief scam. While there are many legitimate companies that help you repay taxes, the offers you get on your phone are most likely from an imposter call center looking to steal your social security number.

Skepticism is an essential human instinct-- it will help you protect your keys, your wallet, and your credentials. Stay vigilant my friends. If you have some recent examples of text, picture or voice scans, please let me know.

Paul Walsh

My purpose is to make the internet safer through a radically new, human-centric approach to security. Most tech firms and security companies license my patents for mobile app security.

1 年

Same old same old phishing. Not a single thing has changed in years when it comes to the fact no system can detect dangerous URLs that we don’t know about yet. We need everyone to switch to Zero Trust for URL Authentication.

要查看或添加评论,请登录

社区洞察

其他会员也浏览了