Bank Scam: How Impostors Pose as Bank Officials to Steal Money
- Criminals are using social engineering tactics to impersonate bank officials and steal funds from account holders, according to reporting from El Colombiano.
- The fraud typically begins with a contact from an individual claiming to be a bank employee.
- Once the victim is engaged, the scammers request private information.
Criminals are using social engineering tactics to impersonate bank officials and steal funds from account holders, according to reporting from El Colombiano. These scammers typically contact victims via phone or messaging apps, claiming there is an urgent issue with the user’s account to coerce them into revealing sensitive credentials or transferring money.
The fraud typically begins with a contact from an individual claiming to be a bank employee. According to El Colombiano, these perpetrators often use psychological pressure, informing the victim of a supposed unauthorized transaction, a blocked account, or a required security update to create a sense of urgency.
Once the victim is engaged, the scammers request private information. El Colombiano reports that this includes passwords, one-time passwords (OTP) sent via SMS, or the answers to security questions. In some instances, the criminals direct the victim to a fraudulent website that mimics the official banking portal to capture login data in real time.
Another common variation of the scam involves the request for a direct transfer. The imposters claim the funds must be moved to a “safe account” or a “temporary holding account” to protect them from the alleged security breach. Once the transfer is completed, the funds are immediately moved through a network of accounts to prevent recovery.
Financial institutions emphasize that they do not request passwords or security codes through phone calls or text messages. El Colombiano notes that legitimate bank officials will not ask customers to transfer money to third-party accounts for security purposes.
To identify these scams, El Colombiano suggests looking for specific red flags, including:
- Requests for sensitive data like passwords or OTPs.
- Urgent or threatening language regarding account closures.
- Instructions to move money to an external account for “protection.”
- Links sent via SMS or WhatsApp that lead to non-official domains.
The reporting indicates that these attacks often rely on “vishing” (voice phishing) and “smishing” (SMS phishing). By manipulating the victim’s emotions—specifically fear and urgency—the scammers bypass technical security measures by convincing the user to voluntarily hand over access keys.
If a user suspects a fraudulent call, El Colombiano advises hanging up immediately and contacting the bank through official, verified channels, such as the number listed on the back of the physical debit or credit card or by visiting a physical branch office.
