CPO Magazine - News, Insights and Resources for Data Protection, Privacy and Cyber Security Leaders
CPO Magazine - News, Insights and Resources for Data Protection, Privacy and Cyber Security Leaders
  • Home
  • News
  • Insights
  • Resources
Hacker talking on the phone showing bank staff impersonated in account takeover
Cyber SecurityNews
·4 min read

FBI Warns Bank Staff Impersonation Is on the Rise, Over 5,100 Account Takeover Cases in 2025

Scott Ikeda·November 28, 2025

The FBI has issued a warning about a spike in financial account takeover crimes, after fielding over 5,100 complaints thus far in 2025. Attackers are commonly impersonating bank staff and mocking up replicas of financial institution websites to obtain credentials, and in some cases are ensnaring victims via legitimate-seeming search engine ads.

Bank staff impersonation targets all types of individuals and organizations

The FBI warns that the account takeovers are indiscriminate, with both individuals and organizations of all types and sizes being targeted. The key thread is the impersonation of bank staff via text messages, emails and phone calls. In some cases, the fraud begins with an ad purchased from a legitimate search engine that looks like the ads the financial institution normally runs. Since January 2025 the FBI Internet Crime Complaint Center (IC3) has fielded over 5,100 complaints of this type, totaling over $262 million in observed losses.

Whatever the exact approach, the end goal is to trick the account owner into turning over login credentials and multi-factor authentication codes. Once they have access to the account, the attacker initiates a password reset and takes full control. They then drain the accounts in a number of ways, most commonly via wire transfers or purchases of cryptocurrency.

One common approach that the FBI notes is for the attacker to send messages indicating a potentially fraudulent series of purchases has been made and that the victim needs to log in urgently to address them. The criminals sometimes not only impersonate bank staff, but take the extra step of posing as a law enforcement official assigned to take information from the victim including their sensitive account details.

The phishing websites that victims are directed to are mocked up to look like legitimate bank and payroll websites. Account takeover victims may get directly to these from a “SEO poisoned” search engine ad, without making contact with a scammer posing as bank staff at all. These ads are targeted at users looking for the legitimate website URLs via search engine.

IC3 website itself has been impersonated as part of account takeover attempts

A previous warning issued by the FBI in September addressed a smaller and more specific slice of these account takeover groups: ones that are bold enough to spoof the IC3’s own fraud reporting website as part of their bank scams. This caper relies mostly on paid search engine ads that lead to poisoned links, mocked up to look like the real IC3 site. However, these sites may ask for more specific and sensitive information than the real site requests as part of the complaint process (such as financial account login information or a Social Security or bank card number). A more subtle approach by the attackers is to clone the IC3 site directly, but then have a fraudster follow up pretending to be an FBI agent and asking for more sensitive details in direct communications. It is also possible that these phishing sites could attempt to pass malware that logs keystrokes or raids internet browsers for stored passwords.

The FBI warning does not delve into the technical particulars of these bank scams beyond this, but in general phishing is seeing major spikes thanks to a combination of new AI assistance tools and the broader availability of simplified “phishing kits” aimed at inexperienced criminals. AI now helps to not only translate to foreign languages in a polished way, but also study and mimic the normal communication structure and style of particular financial institutions to make messages look even more legitimate. It also helps the less technically adept to more closely copy the legitimate webpages they spoof to capture sensitive information. The phishing kits make this even easier by providing amateurs with ready-to-use website templates and messages; some of these are also now offering live support from a more advanced hacker as part of their subscription packages.

Phishing and scamming always ramp up during the holiday season, running from roughly Thanksgiving and Black Friday in the US through Christmas a month later, due to the natural uptick in shopping and increased amount of funds flowing through retailers. While everyone must be aware of these sorts of account takeover attempts, small businesses also especially need to be wary of increased targeting by hackers looking for known and unpatched vulnerabilities in e-commerce systems. WooCommerce, Adobe/Magento, Oracle and other big e-commerce names all currently have documented exploitable vulnerabilities that require proactive updating or patching.

The FBI recommends that everyone step up regular monitoring of their financial accounts for odd activity during this season, particularly if they have any unusual security-related interactions or messages come in. Any first contact initiated by people claiming to be bank staff should also be independently verified. This is also a good reminder to bookmark the known safe URLs of any financial sites, and to enable MFA on these accounts when available. However, the FBI warning shows that MFA is far from a failsafe if it consists of a text message or email code. If an account takeover does happen, the FBI advises immediately contacting your financial institution to have any transfers reversed or recalled as well as requesting a Hold Harmless Letter (or Letter of Indemnity). Victims should also then report the incident at www.ic3.gov. Contacting the impersonated company may also help, as they have legal standing to request immediate action be taken against phishing pages or phony ads making use of their name.

Jim Routh, Chief Trust Officer at Saviynt, also advises considering passwordless alternatives: “The large majority of ATO accounts referenced in the FBI announcement occur through compromised credentials used by threat actors intimately familiar with the internal processes and workflows for money movement within financial institutions. The most effective controls to prevent these attacks are manual (phone calls for verification) and SMS messages for approval. The root cause continues to be the accepted use of credentials for cloud accounts despite having passwordless options available.”

 

Tags
Account TakeoverBank Staff
Scott Ikeda
Senior Correspondent at CPO Magazine
Scott Ikeda is a technology futurist and writer for more than 15 years. He travels extensively throughout Asia and writes about the impact of technology on the communities he visits. Over the last 5 years, Scott has grown increasingly focused on the future landscape of big data, surveillance, cybersecurity and the right to privacy.
Related
Backlit hand using tablet with abstract glowing digital skull showing bad bots and account takeover and API attacks
Cyber SecurityNews

Bad Bots Account For 30% Of Internet Traffic and Are More Frequent in Account Takeover and API Attacks

May 30, 2023
Facebook screen in the hands of a woman showing account takeover of Facebook profiles
Cyber SecurityNews

An Effective Account Takeover Trick Is Helping Scammers Steal Thousands of Facebook Profiles

May 3, 2023
Army of bots showing eCommerce retailers and account takeover, DDoS and API attacks
Cyber SecurityNews

62% of Security Incidents on eCommerce Retailers Originate from Bots, Including Account Takeover, DDoS and API Attacks

November 11, 2022
Logo of TikTok in the reflection of a broken mirror showing TikTok hack and account takeover
Cyber SecurityNews

“One-Click” TikTok Hack Discovered That Put 2 Billion App Users at Risk, but No Reports Yet of Account Takeover in the Wild

September 8, 2022
Disney store window showing account takeover of social media
Cyber SecurityNews

Disneyland Account Takeover Highlights Lax Security for Social Media Accounts

July 13, 2022
Iran flag on a black keyboard showing spear phishing for account takeover
Cyber SecurityNews

Iranian Spear Phishing Operation Targeting US and Israeli Government Figures, Email Account Takeovers Lead to Impersonation Campaigns

June 23, 2022
Bunch of rough shape keys showing user credentials sold on dark web
Cyber SecurityNews

Over 24 Billion Compromised User Credentials Circulating on the Dark Web Market

June 22, 2022
Boy and father playing games showing account takeover via phishing and social engineering
Cyber SecurityNews

EA Confirms Account Takeover Attacks Compromising High-Profile Gamers via Phishing and Social Engineering Attacks

January 20, 2022
- Advertisement -
- Advertisement -

Latest

Hands using laptop with brain hologram showing shadow AI and data governance

Shadow AI: How to Fix Today’s Leading Data Governance Problem

Man with headphones showing data breach of music platform

AI Music Generating Platform Suno Data Breach Affects over 55 Million People

Chick-fil-A chicken restaurant showing data breach from credential stuffing attacks

Fast Food Restaurant Chain Chick-fil-A Suffers Data Breach from Credential Stuffing Attacks

Hands on laptop showing data breach

Cosmetics Giant Estée Lauder Discloses a 10-Month Old Data Breach

- Advertisement -
- Advertisement -
- Advertisement -
- Advertisement -

Learn More

About
Contact
Our Advertising
Privacy Policy
Cookie Policy
Terms of Use

CPO Magazine

News, insights and resources for data protection, privacy and cyber security professionals.

Learn More

About
Contact
Our Advertising
Privacy Policy
Cookie Policy
Terms of Use

Categories

Data Privacy
Data Protection
Cyber Security
Tech
Digital
Insights
News
Resources
Press Releases

© 2025 Rezonen Pte. Ltd.
CPO Magazine - News, Insights and Resources for Data Privacy, Protection and Cybersecurity Leaders
  • Home
  • News
  • Insights
  • Resources
    Start typing to see results or hit ESC to close
    Data Breach U.S. Cyber Attack Regulations Ransomware Attack
    See all results