us

216.73.217.135

Back
News

FBI Warns of Mas​​sive ATO Fraud Surge as Cybercriminals Impersonate Banks and Drain Accounts

FBI Warns of Mas​​sive ATO Fraud Surge as Cybercriminals Impersonate Banks and Drain Accounts
R Richard M. DECEMBER 3, 2025 1 minute read

The FBI has issued a serious warning that cybercriminals are increasingly impersonating financial institutions to steal sensitive customer information and money. Impersonation is causing a significant increase in account takeover (ATO) fraud across the U.S. The report shares that people have lost over $262 million, with more than 5,100 complaints. This increase in numbers shows how quickly ATO fraud is growing and becoming more advanced. 

Scammers now use a mix of cultivated techniques that use social engineering. This includes phone calls and text messages, as well as emails and convincing phishing websites that lure individuals into disclosing their passwords, MFA codes, and one-time passcodes. Once the attacker gets even a single piece of login information, they can log into the account and swiftly reset the password. This allows the scammers to lock out the legitimate user and drain the account in just a matter of minutes.

In several cases, these scammers even pretend to be police officers or someone from law enforcement. They do this to create a misleading impression of urgency and create tension to get victims to share account login details and other credentials.

The FBI has raised concerns about the rise in the occurrence of SEO poisoning. It is a strategy where criminals embed harmful advertisements and deceptive search results. It directs users to harmful websites that digitally mimic the look and feel of banking websites. Once victims unknowingly enter these replicated sites, the attackers quickly transfer funds to mule accounts. They convert the stolen money into cryptocurrency, all while effectively masking their trail.

Experts indicate that most of these incidents arise from compromised credentials, coupled with attackers who have a keen understanding of internal financial processes. As a result, the absence of an authentication method that does not require passwords continues to be a serious drawback that puts users at risk of attack.

Cybersecurity companies have expressed concern about an increase in threats as the holiday season draws near, such as phishing waves tied to Black Friday, QR code scams, and AI-generated counterfeit websites. In just three months, Fortinet identified over 750 malicious domains themed for holidays.

At the same time, “purchase scams” are becoming a major way to commit fraud. Malicious actors set up convincing fake e-commerce websites to dupe victims into approving payments. Fraudsters run advertising campaigns that entice individuals to purchase from their site through credit cards that they can steal. Then they use these stolen cards elsewhere and make online purchases without the user’s consent.  

The Federal Bureau of Investigation recommends that individuals take caution. Also, to avoid the oversharing of personal information online. Furthermore, it’s important for users to keep a close eye on their accounts and to verify any communications that appear dubious. 

For financial institutions like banks and online businesses, this trend shows the need for better identity checks during account setup. They should use risk-based methods for logins and payments, and continuously monitor accounts. This can help identify mule accounts and detect unusual activity before money leaves the victim’s account.

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Share you link

Bring your voice

Bring Your Voice.

The community for every hand that writes and every voice that speaks against fraud.

Join Community

Pitch a piece and get a verified byline in the Media room.

“Industry Partnerships That Create Real Value”

Join Shufti’s partnership network to expand your connections, collaborate with industry leaders, and unlock new opportunities.

Pitch a piece and get a verified byline in the Media room.

Partnership Inquiries?
Email us at [email protected]

iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
Copyright © 2026 Shufti. All rights reserved.