Credit unions and financial institutions are facing a surge in sophisticated fraud schemes that leverage social engineering and AI-driven tactics to compromise payment security. Attackers are increasingly using phishing, vishing, and smishing to harvest credentials and one-time passcodes, enabling account takeover and card-not-present fraud. Imposter scams, such as fraudulent calls and urgent messages, pressure victims into making instant, irreversible transfers through crypto ATMs or quick-pay apps. Security leaders emphasize the importance of real-time monitoring, member education, and advanced authentication methods—including tokenization and biometrics—to counter these evolving threats and protect members without degrading user experience.
Criminal organizations, including groups operating out of China, have orchestrated large-scale scams by sending deceptive texts about overdue tolls or postal fees to trick individuals into divulging credit card details. Stolen card numbers are then installed in digital wallets like Google and Apple Wallets in Asia and shared with U.S.-based accomplices to make fraudulent purchases. These operations have resulted in over $1 billion in losses over three years, highlighting the global scale and technical ingenuity of modern payment fraud. Early reporting by victims and rapid response by financial institutions are critical to stopping fraudulent transfers and involving law enforcement to mitigate losses.

See the actors and campaigns active against you right now.
1 event from the most recent confirmed update back to the earliest known activity.
References published on October 28-29, 2025 discuss social engineering used to obtain people's credit card details and emphasize that earlier reporting can help credit unions stop fraudulent transfers more quickly. The provided content does not include enough detail to identify any earlier discrete incident, victim, or remediation event beyond these published discussions.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.