The new bank scam going viral on TikTok is jeopardizing financial security.

bank scam on TikTok

The growing popularity of TikTok isn't just spreading viral dances or trendy challenges: it has also become a platform for exposing new forms of bank fraud based on social engineering . A recent testimony posted on the platform has raised alarms by showing just how easy it can be for criminals to impersonate others and bypass the security systems of financial institutions.

In this case, a well-known TikTok user, popularly called "The Lady in Her Forties," recounted in detail how she became involved in a cyber fraud that resulted in the unauthorized reissuance of her credit cards . Her video went viral within hours, sparking a heated debate among users about the fragility of banking security and the use of personal data over the phone and online.

A call that sounds like it's from the bank... and opens the door to scams.

The TikTok 'likes' scam
Related article:
The TikTok 'likes' scam: official warning and guide to avoid falling for it

fraud in social media and banking

The victim's story begins on Monday, May 11, when she received a call on her mobile phone that bypassed the filter she had set up to block unknown numbers . On the other end of the line, a woman introduced herself as an advisor from her bank and offered her a new credit card, apparently as part of a routine marketing campaign.

When the customer refused to sign up for another product, the supposed employee changed tactics and suggested improving the terms of the cards she already had, something the victim recognized as a common practice in her previous communications with the bank . This air of normalcy was key to preventing the conversation from arousing suspicion.

During the call, the representative asked her to validate her information through the automated phone system, a procedure the bank typically uses when a customer calls in on their own initiative. Convinced she was following a legitimate protocol, the woman entered her PIN on the phone keypad , believing the bank's automated system was verifying her identity.

Minutes later, the victim receives an email seemingly from the bank's official alerts address. The sender's name and email format match the usual sender information, reinforcing the perception that it's all part of an internal bank procedure , thus dispelling any remaining doubts.

Identity theft and mass alteration of bank details

The scam becomes even more convincing when the person on the phone is able to recite the user's full address and other personal information—data that the criminals would have obtained beforehand through various means. This precision in the information makes the conversation, to the victim, indistinguishable from a genuine interaction with the bank.

At the end of the call, the supposed advisor provided a reference number that matched the format used by the bank in its communications. According to the victim, this detail finally convinced her that she was speaking with authorized personnel, since even her own bank managers acknowledged that the code resembled the official ones.

However, in the following days, warning signs began to appear. The virtual card linked to her mobile phone was deactivated without explanation, something the user initially interpreted as a logical step in the card renewal process . What was really happening was that the scammers had gained access to the banking system and modified key information.

The magnitude of the problem becomes apparent when, after a few days, the affected person logs into their online banking and discovers that their personal and contact information has been altered. Their profile now displays email addresses, phone numbers, and a physical address that do not belong to them . In other words, someone has managed to access their account and change the information necessary to receive new cards and communications at a different address.

Meanwhile, the woman begins receiving messages from a courier company claiming to be arranging the delivery of a supposed new credit card. Through WhatsApp , they confirm a shipment to an address that doesn't match her residence. At that point, the user realizes something is amiss and immediately contacts her account manager to find out what's going on.

Card reissue and delivery thwarted by security intervention

Upon speaking with her bank manager, the victim discovered that the system showed the cancellation of one of her cards due to loss or theft, a action she insists she never requested. Furthermore, the system indicated that not one, but two new credit cards had been issued in her name , each assigned to a different courier service for delivery.

The situation is particularly delicate because one of the shipments was already in progress. When contacted by the user, one of the courier services confirmed a scheduled delivery appointment for the card at an address that did not belong to the cardholder. It was then that the woman alerted the operator that the person who had arranged the shipment had impersonated her.

After the call, the delivery company reacted quickly and escalated the case to its security department, blocking the scheduled delivery. Instead of going to the address tampered with by the criminals, the card was redirected to a physical branch of the bank , thus neutralizing a key part of the criminal plan.

Meanwhile, the victim went to a bank branch to report the incident and check the status of all her cards and accounts. There, with the help of branch staff, she confirmed that the criminals had indeed orchestrated a kind of "three-way" scheme between the bank, the customer, and the fraudster , taking advantage of the customer's legitimate interaction to expedite the reissuance of payment methods.

The mechanism is deceptively simple: the victim, convinced they are interacting with the bank, enters their credentials into the system; the fraudsters, who have managed to infiltrate this process, use this authentication to process changes to the cards and contact information . Once the new cards are generated and redirected to an address under their control, the path is clear to drain the funds or make fraudulent purchases.

The scam goes viral on TikTok and sparks fears about social engineering.

The TikTok video in which the victim recounts the entire process has garnered thousands of views and comments. Many users are outraged and point out that for a transaction of this nature to go this far, there is likely some degree of failure or breach in the security chain , whether at the level of internal bank verification or controls at intermediary companies.

Among the reactions, some suggest that there could be people with inside access leaking information, while others point out that, according to standard security policies, banks should not request passwords or sensitive data when they are the ones making the call . Several users take the opportunity to recount similar experiences in which they received suspicious calls that mimicked the tone and protocols of financial institutions.

The content creator herself is leveraging the video's virality to forcefully question the level of protection offered by current banking systems. She claims to feel "violated, her privacy and information violated ," and demands explanations from her bank, calling for stricter controls and a thorough review of its authentication protocols.

The case highlights a type of fraud that has become increasingly sophisticated over time: social engineering applied to financial services . Instead of trying to break into secure technical systems, criminals target the most vulnerable part of the system, which is usually the end user. Through convincing phone calls, emails that mimic official templates, and the coordinated use of multiple companies, they create an appearance of legitimacy that is very difficult to detect at first glance.

This story, spread through TikTok, is serving as a warning to thousands of people in Spain and other European countries, where banks face a similar scenario: increasingly connected customers, remote transactions as the norm , and criminals exploiting any human or technical vulnerability to try to break into accounts.

How scammers operate: scattered data, complete profiles

The victim's account fits a pattern that authorities and financial institutions have been warning about for some time: criminals rarely obtain all their information from a single source. They typically gather fragments of personal and banking data from leaks, fake forms, or isolated scams, until they construct a profile complete enough to impersonate the real owner.

In this context, a seemingly innocuous phone call can be the final link in a chain of data collection that has been developing for weeks or months. The fact that they already have the address, full name, or even part of the account numbers makes the conversation much more believable to the victim, who tends to trust when they hear information they assume only the bank should know.

Financial institutions in both Latin America and Europe insist that they will never request online banking access codes, security codes, card PINs, or expiration dates by phone or email when the bank initiates contact. They also urge users to be wary of links sent through unofficial channels and to always verify the website address before entering any sensitive information.

On their security websites, banks remind customers that they should not share usernames or passwords on websites other than the official online banking platform or mobile app. Similarly, they advise against filling out forms received through social media, instant messaging, or suspicious emails, as many of these are used as bait to capture data that will later be combined with other stolen information.

This entire fraud ecosystem is amplified by the speed at which content travels on platforms like TikTok. A video with a shocking testimonial can reach hundreds of thousands of people in just a few hours, generating a mix of awareness, alarm, and misinformation if it isn't accompanied by clear explanations about how to act and who to contact if you suspect something is amiss.

Lessons for banking users in Spain and Europe

Although the case described is linked to a specific entity and a Latin American country, the methods used by the fraudsters are applicable to Spain and the rest of Europe. The widespread use of online banking, mobile transaction confirmations, and convenient remote card management are advantages that also create new risks when malicious actors become involved.

In Europe, regulators have promoted measures such as strong customer authentication (SCA) and the use of two-factor authentication for sensitive transactions. However, these technical barriers can be rendered ineffective if the user is tricked into entering their credentials through a channel controlled by third parties or under circumstances they perceive as legitimate.

That's why cybersecurity experts emphasize a key principle that may sound repetitive, but remains essential: never give out passwords, one-time codes, or card details to anyone who identifies themselves over the phone , even if they claim to be calling on behalf of the bank. If in doubt, the wisest course of action is to hang up and contact the bank directly using the official channels you already have saved.

It is also recommended to frequently review account activity and online banking notifications, as well as keep contact information up to date and activate all possible transaction alerts: card charges, transfers, online purchases, etc. Early notification can allow the bank to block cards or stop transfers before the damage becomes more significant.

In Spain, police forces and consumer protection agencies encourage reporting any attempted fraud, even if it is not completed. These reports provide valuable information for detecting patterns, identifying phone numbers, IP addresses, or intermediary companies frequently used by criminal groups, and thus strengthening joint investigations at the European level; for example, cases in which the Civil Guard dismantled a cyber fraud network.

The TikTok scam case illustrates how the combination of banking technology, social media, and the persuasive skills of criminals can lead to very complex situations for users. The victim has already filed a complaint with the authorities, and their testimony serves as a reminder that anyone, no matter how well-informed they believe themselves to be, can fall into the trap if the right circumstances arise.

This whole episode highlights the need for banks, digital platforms , and users to raise the bar for caution and verification: always check who is calling, be wary of anyone asking for sensitive data, carefully review emails and links received on mobile phones, and at the slightest suspicion, stop the transaction and contact the bank directly . Only by combining secure technology with more cautious usage habits can we reduce the impact of these bank scams, which, thanks to TikTok and other social media platforms, have gone from being isolated incidents to a shared concern.


Add as preferred source in Google