FinCrime Intelligence

  • Home
  • Solutions
    • Compliance Audits
    • Risk Assessments
    • Training Programs
    • Fraud Detection Software
  • Certifications
    • ACAMS
    • ACFE
    • ICA
  • News, Trends & Risks
Follow us
  • LinkedIn
  • YouTube
Search

Switch to the dark mode that's kinder on your eyes at night time.

Switch to the light mode that's kinder on your eyes at day time.

Login
Menu

FinCrime Intelligence

Login
in News, Trends and Risks

Inside the Fake Bank Alert: How Smishing Campaigns Turn Security Warnings into Financial Loss

Fraudulent “new device” messages targeting Santander and NatWest customers reveal how criminals combine impersonation, credential theft, social engineering and mule accounts to compromise modern banking controls.

by FinCrime Intelligence April 29, 2023, 8:46 pm 37 Views 1 Comment

  • 0share
  • Facebook
  • Twitter - X
  • Pinterest
  • LinkedIn
Inside the Fake Bank Alert
Smishing Campaigns: Anatomy of Bank Impersonation and Account Takeover

Santander and NatWest customers were warned in 2023 about fraudulent text messages claiming that a transaction had been detected from a new device. Recipients were told they needed to verify the activity to continue using online banking, with an embedded link directing them to a counterfeit website designed to collect login credentials and personal information.

The wording was simple, but the attack model was not. A banking smishing campaign can combine brand impersonation, sender-ID manipulation, cloned websites, real-time credential interception, one-time-passcode theft, account takeover and the rapid movement of funds through mule accounts. What appears to the customer as one suspicious text may be the first visible stage of a larger fraud operation.

For a FinCrime audience, bank impersonation is not only a communications-security problem. It sits at the intersection of cyber-enabled fraud, identity compromise, unauthorised transactions, authorised push payment fraud, mobile-device security and money laundering.

The warning therefore remains relevant beyond the original campaign. Criminals continue to exploit trust in financial institutions while adapting their methods to stronger authentication, improved transaction monitoring and changing reimbursement rules.

Listen the podcast

https://fincrimeintelligence.com/wp-content/uploads/2023/04/Inside-the-Fake-Bank-Alert.mp3

Watch the video

Why the “new device” message works

A message stating that a payment or login has been detected from a new device creates immediate uncertainty. The customer does not recognise the activity, but believes delay could allow money to leave the account or online access to be suspended.

A scam may use the bank’s name, familiar formatting and a plausible security event. It may even appear inside an existing message thread because sender identities can be spoofed or abused through business-messaging infrastructure.

The presence of a recognised brand or conversation history is therefore not proof of authenticity. The relevant question is whether the customer initiated the action and whether the request can be verified independently through the official banking application, website or telephone number.

From smishing to account takeover

The embedded link usually leads to a website that reproduces the bank’s login page. Its address may contain the institution’s name with extra words, altered characters or a misleading subdomain. On a mobile screen, the full domain may not be obvious.

The page requests login and personal information, which more advanced operations relay to the criminal in real time.

As the victim enters credentials, the fraudster attempts to access the genuine account. If the bank sends a one-time code or approval request, the fake site asks the customer to provide or confirm it.

The customer believes they are cancelling suspicious activity. In reality, they may be authorising a login, registering a device, creating a payee, provisioning a card to a digital wallet or approving a payment.

This distinction matters because authentication does not eliminate social engineering. It proves that a credential or approval was supplied, but not necessarily that the customer understood the action.

When the message becomes a telephone scam

A fraudulent text may direct the recipient to call a number rather than open a website. The person answering adopts the language of a bank fraud department, provides a case reference and asks security questions to make the interaction appear procedural.

The caller may then claim that payments are pending or that the customer must move money to a protected account. No legitimate bank requires a customer to transfer funds to a secret “safe account”.

Caller identification cannot resolve the risk. Telephone numbers can be spoofed so an incoming call appears to originate from a bank, police force or government agency.

The reliable response is to end the contact and reconnect independently. Customers can use the number printed on their card, the official banking application or, for participating UK institutions, call 159 to reach their bank safely.

Unauthorised fraud and APP fraud

Bank impersonation attacks can produce two different outcomes.

In unauthorised fraud, the criminal uses stolen credentials or account access to make a transaction the customer did not approve. In authorised push payment fraud, the customer instructs the bank to send money but does so because they have been deceived about the recipient or purpose.

The distinction affects investigation, reimbursement and the evidence required. It also shows why scam prevention cannot sit solely inside account-takeover controls.

UK Finance reported that criminals stole £1.28 billion through payment fraud in 2025. Unauthorised losses declined, but APP losses rose to £576.4 million. The divergence reflects a wider shift from defeating systems directly to manipulating legitimate users.

Impersonation fraud declined during the year, but remains a high-impact typology. Telecommunications-originated scams represented a smaller share of APP cases than online-originated scams, yet accounted for a disproportionately large share of losses.

Why phishing links remain valuable

A phishing page can serve several purposes beyond stealing an online-banking password.

The data may support identity theft, card fraud, credential stuffing or targeted follow-up calls. The site also identifies which victims hold valid accounts and are willing to engage, allowing criminals to prioritise higher-value targets.

Stolen credentials can also be sold to other actors, while specialised groups provide phishing kits, call operations and mule accounts as modular criminal services.

The final payment is therefore only one component of the chain. Effective disruption requires action against fraudulent domains, messaging accounts, call infrastructure, receiving accounts and the onward movement of proceeds.

The mule account is the conversion point

Once an account is compromised or a victim is persuaded to transfer money, the fraudster needs somewhere to receive it. That role is performed by a mule account belonging to an individual, business or synthetic identity.

Funds are moved onward quickly, divided between accounts, withdrawn as cash, spent through cards or converted into cryptoassets. Speed reduces the chance of recall and distances organisers from the original victim.

This makes the receiving institution as important as the sending bank. A payment warning may prevent one loss, but identifying the recipient network can protect multiple potential victims.

What a resilient personal control stack looks like

The first control is independent navigation. Customers should not use links, telephone numbers or QR codes contained in unexpected banking messages. They should open the official application directly, type the known website address or contact the bank through a trusted number.

The second is transaction-specific authentication. One-time codes and approval prompts should be read in full. The amount, payee and action must correspond exactly to something the customer initiated. A code should never be disclosed to an unsolicited caller.

The third is account hygiene. Banking and email accounts should use unique passwords and multifactor authentication where available. Remote-access software should never be installed at the request of an unexpected caller. A genuine bank does not need to control a customer’s device to cancel fraud.

Customers should enable transaction alerts, monitor contact-detail changes and review devices registered to their accounts. Unexpected wallet-provisioning or new-device notifications should be reported immediately.

Suspicious texts can be forwarded to 7726. Anyone who has entered credentials, disclosed a code or approved an unexpected action should contact their bank immediately rather than waiting for a fraudulent transaction.

What banks need to detect

A resilient banking control stack cannot rely on one indicator. A new device, password reset or payee may each be legitimate. Risk becomes clearer when several events occur together.

Institutions should connect changes in device, IP address, geolocation, telephone number, password, payee profile and transaction behaviour. A new-device enrolment followed by a password reset, rapid payee creation and high-value transfer is more meaningful than any event alone.

Behavioural analytics can identify unusual hesitation, navigation, copy-and-paste activity or a customer acting while apparently coached. Call-centre intelligence may reveal that the customer is repeating scripted explanations or refusing to end another telephone call.

Payment interventions should be specific. Generic warnings are often clicked through. More effective prompts describe the typology, ask whether anyone instructed the customer to conceal the payment’s purpose and create space for independent verification.

Recipient-side analytics are equally important. New accounts receiving payments from unrelated customers, rapid pass-through behaviour, common devices and linked beneficiary networks can indicate mule activity.

Reimbursement changes incentives, not the threat

Since 7 October 2024, eligible victims of in-scope APP scams made through Faster Payments and CHAPS have benefited from mandatory reimbursement protections, generally up to £85,000 per claim.

The rules provide an important consumer safeguard, but reimbursement does not prevent criminal proceeds from entering the fraud economy. A victim may be financially restored while the criminal network retains the stolen funds.

The framework therefore increases pressure on both sending and receiving payment service providers to prevent scams, intervene appropriately and control mule-account exposure.

It also reinforces the need for fair treatment where a customer technically authorised a transfer while operating under sustained deception.

The wider ecosystem matters

The fraud journey often begins before a bank sees a payment. A malicious advert, search result, social-media account, text message, domain or telecoms service may provide the initial access to the victim.

UK data for 2025 showed that most APP cases originated online, while telecommunications accounted for a smaller but financially significant share. This supports a whole-system response rather than placing responsibility solely on customers and banks.

Ofcom’s 2026 measures to strengthen disruption of scam messages and spoofed calls reflect that direction. Mobile providers are expected to collect and act on scam intelligence, while broader initiatives seek faster sharing of malicious URLs, telephone numbers and account indicators.

Banks, payment firms, telecoms providers, online platforms and law enforcement each hold different fragments of the attack chain. Effective prevention depends on connecting them quickly enough to stop value moving.

Inside the Fake Bank Alert
How Smishing Campaigns Turn Security Warnings into Financial Loss

What this means for financial crime leaders

The Santander and NatWest warning began with a familiar text: a transaction from a new device required verification. Its wider significance lies in the criminal operating model behind that message.

Modern bank impersonation fraud combines cyber compromise with human manipulation. Criminals use stolen data to create credibility, trusted brands to trigger action, fake interfaces to collect credentials and mule networks to convert deception into transferable value.

Customer education remains necessary, but it cannot carry the control burden. Institutions need integrated device intelligence, authentication context, behavioural monitoring, recipient analytics and rapid cross-industry data sharing.

The strongest programmes will not ask only whether a customer authenticated a payment. They will ask whether the surrounding behaviour suggests that the customer understood the transaction, acted independently and intended to pay the actual recipient.

A suspicious text is not merely an attempt to steal a password. It is an entry point into a coordinated fraud and laundering chain. Disrupting it requires banks to connect communications risk, account security, payment behaviour and mule infrastructure before a fabricated security alert becomes a real financial loss.

Account TakeoverAPP FraudAuthorised Push Payment FraudBank Impersonation FraudBehavioural Analyticsconsumer protectionCredential TheftFinancial Crime Intelligencefraud preventionMobile Banking SecurityMule AccountsNatWestOne-Time PasscodesOnline Banking FraudPayment FraudPhishingSantandersmishingsocial engineeringTransaction Monitoring

What do you think?

7 Points
Upvote Downvote
  • 0share
  • Facebook
  • Twitter - X
  • Pinterest
  • LinkedIn

Newsletter

Want more News like this?

Get the best Articles straight into your inbox!

Don't worry, we don't spam

See more

  • Previous article The Impersonation Economy: How Criminals Turn Trusted Identities into Financial Loss
  • Next article The Anatomy of Elder Fraud: How Criminal Networks Exploit Trust, Fear and Financial Security

You May Also Like

  • Manufactured Trust
    in News, Trends and Risks

    Manufactured Trust: How iSpoof Industrialised Bank Impersonation Fraud

  • Beyond the Stolen Card
    in News, Trends and Risks

    Beyond the Stolen Card: How Modern Credit Card Scams Exploit Digital Identity

  • The Impersonation Economy
    in News, Trends and Risks

    The Impersonation Economy: How Criminals Turn Trusted Identities into Financial Loss

  • The Criminal Supply Chain

    Trending

    in News, Trends and Risks

    The Criminal Supply Chain: What GozNym Revealed About Industrialised Cybercrime

  • The Anatomy of Elder Fraud
    in News, Trends and Risks

    The Anatomy of Elder Fraud: How Criminal Networks Exploit Trust, Fear and Financial Security

  • The Hidden Infrastructure of Holiday Fraud

    1 Shares

    in News, Trends and Risks

    The Hidden Infrastructure of Holiday Fraud: How Travel Scams Turn Bookings into Financial Loss

More From: News, Trends and Risks

  • Emulators in FinCrime

    Hot

    1 Shares

    Emulators in FinCrime: How Virtual Devices Are Industrialising Fraud

    by FinCrime Intelligence July 12, 2026, 1:00 am

  • AI-Powered Polymorphic Attacks

    Hot

    AI-Powered Polymorphic Attacks: The Machine-Speed Threat Reshaping Financial Crime Defence

    by FinCrime Intelligence July 4, 2026, 5:52 pm

  • Money Mule Accounts and Account Leasing

    Trending Hot

    1 Shares

    Money Mule Accounts and Account Leasing: The Hidden Infrastructure Enabling Financial Crime

    by FinCrime Intelligence March 7, 2026, 2:11 am

  • Authorized Push Payment Fraud or Customer Abuse

    Authorized Push Payment Fraud or Customer Abuse? Managing Disputed Transfers in FinCrime Operations

    by FinCrime Intelligence January 5, 2026, 2:39 am

  • AI-Driven SAR Drafting in Financial Crime Compliance

    Hot Popular

    AI-Driven SAR Drafting in Financial Crime Compliance: Real Cases, Real Possibilitie

    by FinCrime Intelligence December 14, 2025, 4:14 pm

  • Emerging Fraud Threats

    Trending

    1 Shares

    Six Emerging Fraud Threats Reshaping the Financial Crime Landscape

    by FinCrime Intelligence December 14, 2025, 12:40 am

Leave a ReplyCancel reply

Your email address will not be published. Required fields are marked *

GIPHY App Key not set. Please check settings

One Comment

  1. FinCrime IntelligenceAuthor says:
    August 1, 2026 at 9:20 pm Copy Link of a Comment

    The warning issued to Santander and NatWest customers illustrates how a simple fraudulent text can serve as the entry point to a much broader financial-crime operation. Criminals use convincing security alerts to capture credentials, intercept authentication codes, manipulate customers into approving payments and move stolen funds through networks of mule accounts.

    For customers, the most effective defence is independent verification. Unexpected banking messages should never be answered through the link or telephone number provided. The bank should instead be contacted through its official application, website or a trusted number. One-time codes and approval prompts must also be treated as transaction credentials and never disclosed to unsolicited callers.

    For financial institutions, customer education alone is insufficient. Effective prevention requires the integration of device intelligence, behavioural analytics, account-change monitoring, payment context and recipient-side mule detection. Banks must assess not only whether a transaction was authenticated, but whether the customer understood the action and was acting independently.

    Ultimately, modern bank impersonation fraud exploits the gaps between communications, identity and payment controls. Closing those gaps requires coordinated action from banks, payment providers, telecommunications companies, online platforms and law enforcement before a fabricated security warning becomes a genuine financial loss.

    0
    Reply

Don't Miss

  • Exploiting E-commerce Platforms

    Trending Hot Popular

    5 Shares

    Exploiting E-commerce Platforms: How Amazon and eBay Became Vehicles for Money Laundering

    by FinCrime Intelligence July 26, 2025, 10:48 am

  • Emulators in FinCrime

    Hot

    1 Shares

    Emulators in FinCrime: How Virtual Devices Are Industrialising Fraud

    by FinCrime Intelligence July 12, 2026, 1:00 am

  • Ad Money Laundering

    Trending Hot Popular

    Ad Money Laundering: How Large Advertising Payments Can Conceal Illicit Funds

    by FinCrime Intelligence November 4, 2025, 8:39 pm

The Impersonation Economy

The Impersonation Economy: How Criminals Turn Trusted Identities into Financial Loss

The Anatomy of Elder Fraud

The Anatomy of Elder Fraud: How Criminal Networks Exploit Trust, Fear and Financial Security

Newsletter

Get the best Articles straight into your inbox!

Don't worry, we don't spam

Trending Now

  • Emulators in FinCrime

    Emulators in FinCrime: How Virtual Devices Are Industrialising Fraud

  • AI-Powered Polymorphic Attacks

    AI-Powered Polymorphic Attacks: The Machine-Speed Threat Reshaping Financial Crime Defence

  • Money Mule Accounts and Account Leasing

    Money Mule Accounts and Account Leasing: The Hidden Infrastructure Enabling Financial Crime

  • Authorized Push Payment Fraud or Customer Abuse

    Authorized Push Payment Fraud or Customer Abuse? Managing Disputed Transfers in FinCrime Operations

  • AI-Driven SAR Drafting in Financial Crime Compliance

    AI-Driven SAR Drafting in Financial Crime Compliance: Real Cases, Real Possibilitie

  • Emerging Fraud Threats

    Six Emerging Fraud Threats Reshaping the Financial Crime Landscape

About FCI

FinCrime Intelligence is a dedicated platform focused on tackling the growing complexity of financial crime through insightful content, professional resources, and practical tools for compliance and risk professionals.

Through in-depth news coverage, industry analysis, and expert commentary, we help organizations stay informed on critical issues including fraud, money laundering, cybercrime, sanctions evasion, terrorist financing, bribery, and corruption. Our goal is to support institutions in strengthening their defenses and meeting regulatory expectations in an increasingly high-risk environment.

We also offer access to leading anti-financial crime certifications from… (Read More)

Join Us on YouTube

Stay ahead of financial crime! Subscribe Now for expert insights, breaking news, and real-world solutions!

Recent Articles

  • Emulators in FinCrime: How Virtual Devices Are Industrialising Fraud
  • AI-Powered Polymorphic Attacks: The Machine-Speed Threat Reshaping Financial Crime Defence
  • Money Mule Accounts and Account Leasing: The Hidden Infrastructure Enabling Financial Crime
  • Authorized Push Payment Fraud or Customer Abuse? Managing Disputed Transfers in FinCrime Operations
  • AI-Driven SAR Drafting in Financial Crime Compliance: Real Cases, Real Possibilitie
  • Six Emerging Fraud Threats Reshaping the Financial Crime Landscape

© 2026 by FinCrime Intelligence

  • Terms and Conditions
  • Privacy Policy
  • Contact Us
Back to Top
Close
  • Home
  • Solutions
    • Compliance Audits
    • Risk Assessments
    • Training Programs
    • Fraud Detection Software
  • Certifications
    • ACAMS
    • ACFE
    • ICA
  • News, Trends & Risks
  • LinkedIn
  • YouTube
  • 0share
  • Facebook
  • Twitter - X
  • Pinterest
  • LinkedIn
close

Log In

Sign In

Forgot password?

Forgot password?

Enter your account data and we will send you a link to reset your password.

Back to Login

Your password reset link appears to be invalid or expired.

Log in

Privacy Policy

To use social login you have to agree with the storage and handling of your data by this website.

Accept

Add to Collection

  • Public collection title

  • Private collection title

No Collections

Here you'll find all collections you've created before.

Hey Friend!
Before You Go…

Get the best Articles straight into your inbox before everyone else!

Don't worry, we don't spam

Close

Newsletter

Don’t miss out on new posts!

Don't worry, we don't spam

Close