The FBI has issued a warning about a significant increase in account takeover (ATO) fraud schemes, with cybercriminals impersonating financial institutions to steal money and sensitive information. Since the beginning of the year, over $262 million in losses have been reported from more than 5,100 complaints. Attackers use social engineering tactics—including texts, calls, and emails—to trick victims into revealing login credentials, multi-factor authentication codes, or one-time passcodes. Once access is gained, criminals reset passwords, lock out account owners, and quickly transfer funds, often to cryptocurrency wallets, making recovery difficult.
The FBI highlighted that these schemes are becoming more sophisticated, with tactics such as search engine optimization (SEO) poisoning, where fraudulent ads mimic legitimate e-commerce or financial sites to lure victims. The warning comes ahead of the holiday season, a period when such scams typically increase. The agency urges heightened vigilance, especially as cybercriminals exploit fears of fraudulent transactions and use impersonation of both financial institution staff and law enforcement to manipulate victims into providing sensitive account information.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
Amazon separately alerted its roughly 300 million customers to brand impersonation scams during the holiday shopping period. The warning highlighted attackers posing as Amazon or customer support to steal credentials and one-time codes as account takeover activity intensified around Black Friday.
Around the same period, security researchers reported hundreds of malicious holiday-themed domains, thousands of lookalike domains, and growing use of generative AI to make phishing lures and scam sites more convincing. They also noted large volumes of stolen e-commerce credentials for sale on the dark web and increased mobile phishing activity targeting shoppers.
Ahead of the 2025 holiday shopping season, the FBI publicly warned that cybercriminals were increasingly impersonating financial institutions and using phishing, SEO poisoning, spoofed sites, and fake support interactions to hijack accounts. The agency said stolen funds were often moved quickly to criminal-controlled accounts linked to cryptocurrency wallets.
Beginning in January 2025, the FBI says it received more than 5,100 complaints tied to account takeover fraud, with reported losses exceeding $262 million. The activity involved social engineering, phishing, fake fraud alerts, and credential theft leading to rapid fund transfers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcethehackernews.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.