Social engineering reshapes financial fraud as attacks scale

Social engineering is becoming the dominant attack vector against financial institutions and consumers alike. New data from BioCatch shows impersonation scams more than doubled in the United States over the past year, while Wall Street firms are battling phone-based attacks and cybercriminals are increasingly buying ready-made scam kits instead of building operations from scratch.
US firms face sharp bump in scam attempts
Impersonation scams targeting U.S. consumers more than doubled between 2025 and 2026, according to BioCatch, reflecting a broader shift toward fraud schemes that manipulate victims into authorizing transactions themselves. BioCatch’s findings are based on activity observed across 292 institutions serving more than 280 million users.
Impersonation scams where criminals pose as celebrities, relatives or representatives of trusted organizations were the most frequently reported scam type to the Federal Trade Commission last year. But they were not the most financially damaging despite their prevalence.
“Investment scams continue to account for the majority of scam losses in the U.S., with scammers promising high returns on a range of different investment classes, often employing spoofed websites and fake broker platforms to create a false sense of urgency,” says BioCatch analyst Gary Patterson. The FBI estimates investment fraud losses exceeded $8.6 billion in 2025.
BioCatch’s U.S. customers, which includes three of the country’s four largest banks, reported $46 million in attempted investment fraud losses over the same period. Purchase scams accounted for $28 million, while law enforcement and legal scams caused $22 million.
The firm also recorded a 50 percent rise in phishing attempts, a 45 percent increase in digital banking sessions involving remote access tools, and a pattern of account takeover activity concentrated after 5pm.
More than 83 percent of fraud attempts originated from devices located within the U.S., which BioCatch links to the growth of social engineering scams that manipulate victims into authorizing transactions themselves.
“With mule networks becoming more organized, proactive detection will depend on connecting behavioral, device, and network intelligence in real time,” says Sharell Barshishat, Biocatch’s advisory director for North America.
“When receiving banks can see sending-bank signals suggesting a manipulated customer, and sending banks can see receiving-bank signals flagging a beneficiary as a likely mule, as an industry, we can stop more scams, more often.”
The full 2026 Digital Banking Fraud Trends in the U.S. report can be found here.
Wall Street besieged by social engineering tactics
The trend extends beyond retail banking. Major Wall Street firms are also facing increasingly sophisticated social engineering attacks targeting employees rather than technical vulnerabilities. According to Reuters, hackers recently targeted several large hedge funds and private equity firms, attempting to breach internal systems through phone‑based social engineering tactics.
Point72 Asset Management told investors it had faced an attack but said no customer information was stolen. Hackers also attempted to access systems at Two Sigma Investments and Citadel, the two people familiar with the matter reportedly said.
Attempts to infiltrate major financial institutions are common, cybersecurity experts note, and phone‑based attacks remain effective. Groups such as so-called Scattered Spider, a loose collective of young hackers responsible for numerous corporate breaches, have used similar tactics.
Internationally, companies are contending with a rise in AI‑powered cyberattacks and ransomware. Earlier this year, the White House announced a working group bringing together AI developers and critical infrastructure operators to share threat intelligence and coordinate defences.
Scams become buyable kits
Criminals are also industrializing social engineering. Rather than building phishing infrastructure themselves, would-be scammers can now purchase turnkey fraud kits that combine fake investment websites, cryptocurrency theft tools and personalized victim targeting.
In 2026, get‑rich‑quick schemes have spread across social media, messaging apps and online communities. Many rely on professional‑looking websites and fabricated investment opportunities designed to collect deposits or steal access to cryptocurrency wallets.
One such operation was uncovered by Malwarebytes researchers on a cybercrime forum. The project was linked to a threat actor known as xrep, active since March 2026 and known for selling turnkey scam kits tailored to X (formerly Twitter).
The $500 package discovered in May offered a complete infrastructure for a fake cryptocurrency presale impersonating Tesla’s brand. The site generated personalized token allocations using victims’ X profile pictures, displayed fake fundraising progress bars and countdown timers, and encouraged users to act quickly.
Victims were then steered into two forms of financial loss: entering their cryptocurrency wallet’s 12‑word recovery phrase — effectively handing over full control — or manually sending cryptocurrency to an address controlled by the scammer.
A fabricated dashboard displayed fake token balances to reinforce the illusion of a legitimate investment. Behind the scenes, an administrative panel allowed the operator to monitor victims, collect recovery phrases, assess wallet value, manipulate displayed balances and send personalized messages to extract additional payments.
Researchers say the kit illustrates how modern scams combine social engineering, phishing and financial fraud into a single operation. By offering ready‑made infrastructure, xrep lowers the technical barrier for would‑be scammers, enabling individuals with limited skills to launch convincing schemes with minimal effort.
Professional‑looking websites, personalized offers and countdown timers have become more common, with such tactics often appearing highly believable. Security analysts advise that no legitimate investment should ever require a cryptocurrency recovery phrase, and that transactions made to fraudulent wallets are often irreversible.
Together, the incidents suggest financial fraud is becoming less about defeating technical security controls and more about manipulating human behavior. Whether targeting consumers, hedge fund employees or cryptocurrency investors, attackers are increasingly relying on persuasion backed by professional-grade infrastructure rather than sophisticated malware.
Article Topics
AI fraud | BioCatch | deepfakes | financial crime | financial services | fraud prevention







Comments