^

Opinion

The new anatomy of bank fraud

POINT OF VIEW - Rafael R. Castillo - The Philippine Star

Today’s cybercriminals do not always hack the bank. Increasingly, they hack our trust.

A physician friend recently received what appeared to be an urgent call from his bank’s fraud and security unit.

The caller knew his name. More disturbing, she appeared to know details about his finances. She told him that someone using copies of several of his government-issued IDs had attempted to withdraw P500,000 from his bank account. Then those IDs appeared on his Viber screen.

The caller sounded professional. The story was plausible. And the message was frightening: the suspicious withdrawal had supposedly been stopped temporarily, but unless he acted immediately, his money could disappear.

There was, fortunately, a “solution.”

Transfer P500,000 to designated e-wallet accounts where the money would supposedly be kept safe until the bank resolved the problem.

The physician followed the instructions through his legitimate banking app. An hour later, the money was gone.

Only afterward, when he independently contacted his bank, did he learn the painful truth: the purported fraud officer did not belong to the bank. The person warning him that he was being hacked was apparently the scammer.

This case illustrates the changing anatomy of financial fraud. Instead of breaking through a bank’s computer defenses, criminals manipulate the account holder into performing an otherwise legitimate transaction.

The Anti-Financial Account Scamming Act, or Republic Act 12010, specifically recognizes social engineering schemes involving deception, impersonation of financial institutions and electronic communications used to obtain sensitive financial information.

The psychological formula is remarkably effective: authority + fear + urgency + confidential information = compliance.

The caller first establishes authority: I am from your bank’s fraud department.

Then comes fear: someone is stealing your money.

Then urgency: you must act immediately.

Finally comes credibility: personal information that seemingly only a legitimate institution should know.

What makes my friend’s experience particularly concerning is the amount of information the perpetrators allegedly possessed.

According to his incident report, they displayed copies of several government IDs and appeared familiar with details of transactions involving another financial institution.

That deserves serious investigation. But we must distinguish suspicion from proof.

It would be premature to call this an “inside job.” Personal information can leak through many routes: compromised email or cloud accounts, malware, phishing, stolen databases, breached third-party service providers, improperly handled documents or potentially unauthorized access by insiders.

The National Privacy Commission itself recognizes copies of identification documents and financial information as data capable of facilitating identity fraud.

The appropriate question therefore is not, “Who inside the bank did this?” It is: where did the criminals obtain information sufficiently detailed to impersonate a trusted financial institution?

Victims are sometimes embarrassed to admit what happened. They should not be ridiculed.

These operations succeed precisely because sophisticated fraudsters understand psychology. Doctors, lawyers, engineers, professors, executives and even technology professionals can become victims.

Intelligence is not immunity to manipulation. Indeed, professionals accustomed to making rapid decisions may sometimes respond particularly quickly when presented with what appears to be an urgent, solvable problem.

The lesson is not to become permanently suspicious of technology. It is to develop a new reflex: urgency should trigger verification, not compliance.

Stop the conversation

If someone contacts you claiming that your bank account has been compromised, do not follow that person’s instructions – even if the caller knows your name, account details, address, transactions or identification numbers.

End the conversation.

Then independently contact the institution using the telephone number printed on your card, inside the official banking application or on the institution’s verified website. Never use a telephone number, QR code, link or contact information supplied by the person who contacted you.

Most importantly: no legitimate bank needs you to transfer your money to a stranger’s account to “protect” it. Money does not become safer by leaving an account you control and entering one controlled by somebody else.

Banks must do better

Consumer education alone is insufficient.

RA 12010 imposes responsibilities on financial institutions to maintain adequate systems protecting customer accounts. BSP rules now require stronger fraud-management and authentication controls for institutions offering complex electronic services and high-value online transactions.

The direction is encouraging.

BSP has pushed tools including a “kill switch,” allowing customers to rapidly suspend account access when fraud is suspected, and a “money lock,” which can protect funds from digital transfer even if credentials are compromised.

But technology must go further.

A P500,000 transfer to newly encountered e-wallet recipients – particularly when inconsistent with a customer’s normal behavior – should trigger proportionate friction: enhanced authentication, behavioral analytics, warning screens, temporary cooling-off periods where appropriate or rapid human verification. Digital banking has spent years making money move faster. Fraud prevention sometimes requires making suspicious money move slower.

The first minutes matter

When fraud occurs, victims should immediately contact both the sending bank and receiving institution and ask that the disputed transaction and recipient accounts be flagged and, where legally permissible, held or restricted pending investigation.

BSP consumer-protection rules require supervised institutions to maintain active 24/7 reporting channels for unauthorized or fraudulent transactions and to communicate what action is being taken.

Preserve everything: screenshots, Viber conversations, telephone numbers, transaction receipts, timestamps, names used by callers and reference numbers.

Report the incident promptly to the financial institutions involved and the BSP. Suspected cybercrime can also be reported to the Philippine National Police Anti-Cybercrime Group and the Cybercrime Investigation and Coordinating Center.

We once taught people never to disclose their PIN or OTP. That advice remains essential, but it is no longer enough. The next generation of scams may require neither.

The victim may log into the genuine banking app, authenticate the genuine transaction and personally press “Send.” The criminal’s achievement is psychological rather than technological: convincing the victim that surrendering control is actually self-protection.

This is why financial literacy must evolve into fraud literacy.

Banks must improve detection. Regulators must pursue suspicious recipient accounts rapidly. E-wallet providers must strengthen anti-mule controls. Government must investigate how stolen identities circulate. Law enforcement must follow the money across institutions rather than leaving victims to navigate separate bureaucracies.

And consumers must acquire one lifesaving habit. When someone contacts you unexpectedly and says your money is in danger, do nothing with the money until you have independently verified the warning.

Investigate the failure. Correct the system. And prevent the next victim.

BANK

FRAUD

  • Latest
  • Trending
Latest
Are you sure you want to log out?
X
Login

Philstar.com is one of the most vibrant, opinionated, discerning communities of readers on cyberspace. With your meaningful insights, help shape the stories that can shape the country. Sign up now!

Get Updated:

Signup for the News Round now

FORGOT PASSWORD?
SIGN IN
or sign in with