Cybercriminals attacks , aiming to trick American users of digital payment apps into making instant money transfers.
See also: Social engineering attacks will dominate web3 and metaverse

As the FBI Thursday, attackers are calling victims who respond to phishing emails from phone numbers that spoof the banks' legitimate 1-800 support number.
"Under the guise of reversing the fraudulent money transfer, victims are tricked into sending payments to bank accounts under the control of cybercriminals," the FBI said.
The fake fraud alerts list the payment amount and names of financial institutions and ask targets to confirm whether they attempted to make direct payments of thousands of dollars.
If recipients reply to the SMS and deny making such a payment, they will receive a second message saying they will be contacted “soon.”
The scammers call as promised, usually speaking English without an accent and claiming to represent the target's bank fraud department.
The ultimate goal is to trick victims into "reversing" the fake instant payment transaction by asking them to remove email from the payment app and attach it to one under the attackers' control.
See also: What is Social Engineering, what are its techniques and how to protect yourself?
Believing they are sending the transaction to themselves, victims are actually sending direct payment transactions from their bank account to the bank account controlled by the criminals.

The exchanges between the scammers and their victims can last for several days, showing the scammers' determination to carry out their social engineering attack.
The FBI also shared a list of steps Americans using digital payment apps should take to avoid falling victim to one of these scams:
- Be wary of unsolicited requests for account verification information. Cybercriminals may use email addresses and phone numbers that may then appear to come from a legitimate financial institution. If you receive a call or text message about possible fraud or unauthorized transfers, do not respond directly.
- If an unsolicited request for account verification is received, contact the financial institution's fraud department via verified phone numbers and email addresses on the bank's official websites, not those provided in text messages or emails.
- Enable multi-factor authentication (MFA) for all financial accounts and do not provide MFA codes or passwords to anyone over the phone.
- Understand that financial institutions will not ask customers to transfer funds between accounts in order to prevent fraud.
See also: Datasploit the first tool for social engineering
Finally, users are urged to be skeptical of callers who provide personally identifiable information, such as social security numbers and previous addresses, as proof of their legitimacy. The proliferation of large-scale data breaches over the past decade has provided criminals with vast amounts of personal data, which can be used repeatedly in a variety of scams.
