A dramatic increase in banking and financial scams has been observed globally, with a 65% rise in scam activity over the past year, according to data from BioCatch. Financial institutions serving nearly 350 million consumers across five continents have reported explosive growth in various scam types, including a tenfold increase in SMS-based phishing (smishing) attacks. Voice phishing (vishing) attempts have doubled, romance scams have risen by 63%, and investment scams have climbed by 42%. Purchase scams remain the most common form of fraud, with a 14% increase in attempts. The Global Anti-Scam Alliance estimates that consumers now lose over $1 trillion annually to scams, a figure that continues to escalate. Much of this surge is attributed to organized criminal operations exploiting the financial system, as noted by the U.S. Department of the Treasury. Scammers are leveraging current events and government programs, such as New York State’s inflation refund initiative, to launch targeted phishing campaigns. These campaigns often impersonate official agencies, urging recipients to provide sensitive payment information under the threat of losing their refunds. The phishing messages typically originate from foreign numbers and direct victims to fake websites designed to harvest personal data, including Social Security Numbers and bank account details. In the private sector, attackers are targeting users of popular financial platforms like Robinhood, sending convincing text messages that warn of suspicious account activity and prompt users to log in via fraudulent links. These fake login pages are crafted to closely mimic legitimate sites, and after stealing credentials, some even redirect victims to the real site to avoid suspicion. Additionally, credential phishing campaigns are evolving rapidly, with scammers impersonating Google Careers to target Google Workspace and Microsoft 365 users. These emails, sent in multiple languages and using frequently changing sender details, lure recipients into multi-step traps involving fake verification pages and credential harvesting sites. Attackers abuse legitimate services such as Salesforce and Recruitee to distribute these phishing emails, and the malicious domains are often newly registered to evade detection. The sophistication and adaptability of these scams make them increasingly difficult for both individuals and organizations to detect and prevent. Financial institutions and cybersecurity experts emphasize the need for heightened vigilance, robust anti-phishing training, and advanced fraud detection technologies to combat this growing threat. The widespread nature of these scams underscores the importance of cross-sector collaboration and public awareness to mitigate financial losses and protect sensitive information. As scammers continue to refine their tactics, the risk to consumers and businesses remains high, necessitating ongoing adaptation of security measures. The convergence of social engineering, technical deception, and exploitation of current events highlights the evolving landscape of financial cybercrime. Authorities and industry leaders are calling for increased investment in behavioral biometrics and real-time fraud monitoring to stay ahead of these sophisticated threats. The ongoing battle against banking and financial phishing scams is expected to intensify as attackers leverage new technologies and social trends to expand their reach.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Researchers reported a phishing scam using fake Google job offer emails to target Google Workspace and Microsoft 365 users. The campaign used employment-themed lures to harvest credentials or otherwise compromise business email accounts.
A reported industry finding said banking scams increased 65% worldwide over the previous year, indicating a broader escalation in financially motivated fraud activity. No more specific event date is provided beyond the publication timeframe.
Scammers were still distributing fraudulent Robinhood security alert messages designed to create urgency and steal account credentials or other sensitive information. The article frames this as an ongoing campaign active at the time of publication.
Phishing campaigns began abusing New York’s inflation refund program as a social-engineering theme to trick recipients into clicking malicious links or divulging personal and financial information. The reporting indicates the scam was active by the time it was published.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcehackread.com
Open sourcemalwarebytes.com
Open sourcemalwarebytes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.