A sophisticated social engineering scam has been reported in which fraudsters impersonate Chase bank representatives to deceive potential victims. The scam begins with a caller claiming to be from Chase, who reassures the target by stating that the bank would never ask for personal information or passwords, thereby establishing a false sense of security. The caller then provides the victim with seemingly official details, such as two 'cancellation codes' and a lengthy case number composed of four letters and ten digits, to further legitimize the interaction. As the conversation progresses, the caller offers to transfer the victim to a supervisor, a tactic designed to mimic standard customer service procedures and enhance the appearance of authenticity. After a brief pause, a second individual, introducing himself as 'Mike Wallace,' joins the call and requests the case number, reinforcing the illusion of a structured escalation process. This 'supervisor' then explains a fabricated scenario involving a new account, Zelle transfers, and activity in Texas, suggesting that an attempted withdrawal needs to be reversed. The scam is engineered to capture the victim's full attention and trust, making them more susceptible to following the fraudsters' instructions. The narrative highlights how even individuals who are generally aware of scam tactics can be drawn in by the convincing nature of such schemes. The use of specific banking terminology and procedural language is intended to lower the victim's guard. The scam leverages the authority and familiarity of customer service hierarchies to manipulate targets. The inclusion of detailed case numbers and codes is a psychological tactic to create a sense of legitimacy and urgency. The fraudsters' approach demonstrates a high level of planning and understanding of typical banking interactions. The scam specifically references Zelle, a popular peer-to-peer payment service, as part of the fraudulent scenario. The incident serves as a warning that social engineering attacks are becoming increasingly sophisticated and can affect even those who consider themselves vigilant. The reporting of this scam underscores the importance of verifying the identity of anyone claiming to represent a financial institution, especially when unsolicited contact is made. The case also illustrates the need for ongoing education and awareness regarding the evolving tactics used by cybercriminals in the financial sector.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
U.S. officials warned that scammers are spoofing banks, Zelle, and even the FBI to pressure victims into transferring money to fraudulent 'safe' accounts. The report highlighted losses suffered by at least two customers, including a Chase customer who lost nearly $40,000 and a Huntington Bank customer who sent $5,000 via Zelle.
Online Threat Alerts warned about scam calls spoofing Wells Fargo’s official number, with fraudsters claiming suspicious account activity to pressure victims into transferring funds, sending money via Zelle or wire, or revealing one-time codes. The report also noted possible attempts to capture victims’ voices for abuse against voice-authentication systems and advised customers to verify through trusted bank contact channels.
Two references published on September 30, 2025 point to coverage titled "Details of a Scam," indicating public reporting about a scam. No underlying incident details, victim information, or dated real-world developments are provided in the supplied content.
The Register reported on a banking scam in which criminals used social engineering and knowledge about victims to convince them to move money themselves, framing the transfer as protective action. The coverage documented an early form of the bank-spoofing fraud pattern later highlighted in 2025 and 2026 warnings.
5 references tracked. Mallory keeps watching after this page renders.
foxbusiness.com
Open sourceonlinethreatalerts.com
Open sourceschneier.com
Open sourcesecurityboulevard.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.