Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Security Education Videos Scams & Phishing Your Security Mobile Security Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
Accounts Drained By Zelle Smishing Scam
Facebook   X   LinkedIn   Email

Accounts Drained By Zelle Smishing Scam

March 21, 2025

From time to time, scammers come up with a new tactic using new technology, new events, or whatever they can to continue tricking us into giving up our personal or confidential information. Over the past few years and with the increasing use of texting and SMS messaging, a newer one in the bag of tricks has been coined as “smishing.” Because it’s text, it often catches people off guard and causes them to react quickly, which is exactly what you shouldn’t do.

Often, various scams arrive via the data service on a smartphone. However, it can also be iMessage, which is the text messaging service that Apple uses over WiFi. But whatever the app is called, the term applies to any type of text messaging, including What’sApp, Facebook Messenger, and other chat programs.

Phishing is a method cybercriminal used for decades to try to dupe people out of information, and if they are really successful, login credentials or payment card details. Often, phishing comes via email and includes a link or attachment that when clicked, leads someone to fill confidential information into a form or install malware that steals data off the device. Researchers at Experian found that adults from 18-24 send over 2,022 text messages per month from their mobile devices for an average of 67 per day! That’s valuable information for the cyberthief just waiting to cash in. In a recent scam, users are sent a text message that appears to be from their financial institution attempting to confirm a Zelle transaction. However, that phone number is spoofed by the cybercriminal. A message might say something like “Did you attempt a Zelle Payment of < some amount>? Reply YES or NO or 1 to stop alerts.”  In other cases, the text may want the user to confirm identity by reading or sending back a supposed code. If the user replies, money is transferred directly out of their account to the scammers.

While phishing and even smishing have been around a while, there is a recent scam that intends to steal money using the newer digital payment services, such as Zelle.

Zelle, launched in 2017, is often embedded into banking apps and links to a user's banking account. It allows members to send money to other people instantly. All it takes is an email address or phone number. In 2019, the company reported that users of the service transferred $119 Billion.

Federal regulations require financial institutions to reimburse customers whose money is fraudulently stolen from an account. But that doesn’t mean it’s no risk or no cost. The financial institutions incur costs for every fraud that often gets passed onto the members and customers. Therefore, it’s to everyone’s benefit to avoid becoming a victim of these types of scams in the first place.

  • If you don’t know the sender, aren’t expecting a message with a link or attachment, or just aren’t sure a link is safe to click, don’t click it. Instead, contact the sender independently of the received message and ask about it.
  • Don’t react quickly to any message, whether text, voice, or email that threatens something bad may happen if you don’t. Take a breath. Go to your financial institution’s website or app and log in there. Never click links in messages for financial related details.
  • If you don’t initiate the phone call to your financial institution, don’t send information. Instead, log in to your account using the app or the banks official website and check on your accounts. Making a quick phone call using a number you find or know also works. Don’t use information sent to you in unsolicited messages.
  • Remember that financial institutions do not ask you to verify or update details via text or email. Go directly to the official app or website to do this.
  • It’s not rude to just not reply to suspicious emails or texts. In fact, it is recommended you do just that.
  • Report fraud via smishing to the FCC. There is a form on the agency’s website. This helps the FCC combat these types of crimes and potentially protect others.

A few other common smishing scams include the following:

  • A text message arrives that appears to be from the target’s financial institution requesting that a link be clicked that will go to a website to address and resolve an issue with the account or payment card. If it’s clicked, malware is installed and email address, contact list information, and other data is stolen.
  • A text message claims the user signed up for some sort of service and will be charged unless a link is clicked. The result is again malware getting installed and data stolen from the device.
  • The user is sent a text claiming he or she has won a prize of some sort. Often, it’s a gift card. A link must be clicked to claim the prize. The link directs to a website where personal information is requested, but the victim never gets the prize, of course. Instead, the information is used for spamming or efforts to steal additional information such as financial account credentials.

Can Hackers Take A Bite Out Of  Your Mobile Pay Solution?

Mobile Security

Can Hackers Take A Bite Out Of Your Mobile Pay Solution?

With the many digital payment options available today, finding the most secure providers can be a challenge. The popularity of digital wallets has grown over time and writing checks and even using plastic cards for payments are quickly becoming the dinosaurs of our non-digital past. Many users now own mobile wallets and pay for goods and services. And using Apple Pay, Google Pay or another service for those transactions may offer peace of mind knowing your payment data is safe and out of the reach of hackers. READ FULL STORY

Financial Fraud Evolves As Fraudsters Ramp Up Their Attacks

Your Security

Financial Fraud Evolves As Fraudsters Ramp Up Their Attacks

Cybercriminals are stepping-up to the surge in opportunities for financial fraud. The new products and services that financial institutions (FIs) offer to compete for customers, gives fraudsters new avenues to exploit. Expanding banking options give FIs the ability to battle for customers with their marketing approach. But for many FIs and their clients, bad actors are also responding to these banking options. For all the wrong reasons, they too appreciate additional channels for banking, but only as an opportunity to expand their fraudulent attacks. READ FULL STORY

Shimming Right Along To Skim Your Payment Card Number

Education

Shimming Right Along To Skim Your Payment Card Number

By now, most of us have at least one or two EMV (Europay, MasterCard, Visa) cards. These are the payment cards that were touted as far more secure than the ones with the magnetic strips on the backs. And indeed, if you ask Visa these cards have resulted in a 75% decrease in fraud in the three years since they were introduced. Cybercriminals are of course finding ways to take advantage of the EMV cards too. Now, there are reports of a new way to skim. READ FULL STORY

Online Banking Smishing Scam

Mobile Security

Video Icon Online Banking Smishing Scam

Text message scams are on the rise and in this Today Show segment, Jim Stickley demonstrates how easy it is from criminals to perform these attacks. Most people receive legitimate text alerts from their financial institution so a malicious text can be very believable. DON'T CLICK EVER. Simply open your mobile app or open a browser and sign into your account. If there is a real fraud alert, you will be notified once you are logged in. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...