Personal Security

Fake Unauthorized-Transaction Alerts: Phone Phishing and Card Collection

Two official warnings show how a false unauthorized-transaction alert can move victims into an attacker-controlled phone call or a courier card-collection scheme. This briefing explains how to verify the transaction in the official app, reject card pickup, and respond to exposed credentials or cards.

Cover showing phone and card-pickup risks after a false transaction alert
Cover showing phone and card-pickup risks after a false transaction alert

Reference time: August 29, 2026, 4:00 p.m. KST · Review window: August 22, 2026, 4:00 p.m. to August 29, 2026, 3:59 p.m. KST

A warning about an unauthorized transaction is designed to make verification feel urgent. Two official alerts published on August 28 show how that urgency can be redirected into an attacker-controlled channel. In one, an SMS about an unauthorized PayNow transaction tells the recipient to call the number in the message. In the other, a caller claiming to represent a bank or credit bureau arranges for a courier to collect physical cards. A message does not become safe merely because it contains no link, and a matching name or verification code does not independently authenticate a visitor.

Check the transaction first and make the call second. Find the contact number in the official app or on the physical card, not in the alert.

The PayNow SMS phone route

DBS warned on August 28 about phishing SMS messages that urge recipients to resolve unauthorized PayNow transactions. The message directs the recipient to call a phone number embedded in the SMS. During that call, scammers may seek digital-banking credentials, card details, one-time passwords, or Digital Token approvals. Those details or approvals can be used for account takeover and unauthorized account or card transactions.

The important shift is that the SMS does not need a malicious link. People who associate phishing only with clickable URLs may call the number and enter a conversation that the scammer fully controls. A supposed cancellation or identity check can then be broken into several plausible-sounding requests. Ending the message flow before making that call is the first defensive boundary.

DBS advises customers to use its official hotline, website, and DBS or POSB apps. Bank staff will not ask customers through an unverified channel for card information, digital-banking credentials, one-time passwords, or Digital Token approvals. An approval prompt should be treated as an authorization action, not as a harmless way to confirm identity. If the customer did not initiate the request, it should not be approved.

The suspicious-activity card pickup call

Guelph Police Service separately warned about banking-fraud calls targeting seniors. The caller says that a bank or credit bureau has detected suspicious card activity, asks the victim to gather debit and credit cards, and requests the card name, card number, and PIN. The caller then provides a name and a verification code for a person who will collect the cards for replacement.

A courier arrives while the victim remains on the phone and repeats the same name and code. That match can look convincing, but both pieces of information originated inside the same scam operation. Police said the suspects then used the cards to make charges worth thousands of dollars. Repeating a code from the call is not independent verification.

An unsolicited caller should never be allowed to turn a fraud alert into a request to collect cards or disclose a PIN. Card blocking and replacement should be initiated by the customer through an official bank or card-company channel. Handing a card and its PIN to a courier exposes both the payment instrument and an authentication secret at the same time.

Two attack paths from a false transaction alert to credential requests or physical card collection
Two paths after a false alert

How the two warnings connect

The delivery methods differ, but the control pattern is the same. First, the attacker presents a time-sensitive transaction problem. Second, the victim is moved into a phone channel controlled by the attacker. The flow then branches: one path seeks credentials and approval prompts, while the other gathers cards and a PIN before sending a courier. Both paths end in unauthorized transactions before the victim independently checks the original claim.

Caller ID, an agent name, a case number, and a verification code may look like several pieces of evidence, yet they can all be created by the same caller. To separate the verification channel, end the call and open the already-installed official app. If help is still needed, use the support option in the app or dial the number printed on the physical card. Do not return to the number in the message.

A five-step transaction check

  1. End the SMS or call. Do not reply or redial a number supplied by the sender.
  2. Open the bank or card issuer's already-installed official app, without using a search ad or forwarded link.
  3. Compare the time, amount, payee or merchant, payment card, and approval device. Use the app's report or block option if the transaction appears in the account.
  4. If support is needed, use the number in the official app or on the back of the physical card. Do not accept a transferred call arranged by the original caller.
  5. If credentials, card details, an OTP, a token approval, or a physical card were exposed, contact the bank immediately and block the affected access or cards.

Compare more than the amount. A legitimate transaction with a similar value can create confusion, so match the time, counterparty, payment method, and approval device as a set. If a push alert appeared, open the app again from its normal icon and check recent activity rather than following the alert into an external page.

Five steps to verify a transaction through the official app and the number on the card
Five-step transaction check

Responding to exposed information or cards

Match the response to what was exposed. If no information was shared, end the contact, block the number, and review official account activity. If credentials or card numbers were disclosed, change the password through the official channel, block the card, and review recent sign-ins and transactions. If an OTP or Digital Token approval was provided, tell the bank about the approval and review registered devices and transfer permissions as well as the password.

If a courier took physical cards, report each card as lost or stolen to its issuer immediately. A separate report may be needed for cards from different issuers. If a PIN was also disclosed, review other financial services that use the same number and widen the reset. Where money has already moved, contact the financial institution and local police without delay and preserve the message, call, and transaction records.

  • Credentials exposed: change the password in the official app and review registered devices and recent sign-ins.
  • Card details or a physical card exposed: block and replace the card and review recent authorizations.
  • OTP or token approved: tell the bank what was approved and review transfer and device-registration status.
  • Financial loss: contact the bank and police immediately and preserve message, call, and transaction records.

A card-pickup rule for families

Guelph Police specifically asked people to warn elderly relatives and friends. The family rule can be simple: an unsolicited bank or credit-bureau call must not lead to gathering cards, disclosing a PIN, or giving cards to a visitor. A courier's ability to repeat an agent name or code does not authenticate the visit. Keep the door closed and verify through the official number.

Families can also agree in advance whom to call after a suspicious transaction alert. That family call should begin only after the original call has ended. Do not trust a third party who is added to the same line, and do not let a waiting visitor create a deadline. The verification process belongs to the customer, not to the person who initiated the alert.

One security habit for this week

When an unauthorized-transaction alert arrives, ask what the official app shows before asking which number to call. The number in the message, caller ID, and verification code may all belong to one scripted fraud channel. Ending the contact, opening the app directly, comparing the transaction, and then using the number on the card is a short routine that blocks both digital credential theft and physical card collection.

Sources reviewed

  1. Latest scams & frauds — SMS Phishing AlertDBS Bank · Official source
  2. Suspicious Activity ScamGuelph Police Service · Official source
  3. 설 명절 전후 불법사금융·보이스피싱 등 민생금융범죄 주의금융위원회 · Official source

SECUFOCUS NOW reorganized and analyzed the material above. This article does not replace the original sources.

READER COMMENTS

Comments

0

No comments yet.

Do not include personal information, advertising, or contact details.