Automatic (machine) translation. This text was translated automatically from the Polish original and may contain inaccuracies. In case of any doubt, the Polish version is the authoritative one.
← Back to Knowledge
Knowledge

The 'bank employee' scam — how criminals bypass safeguards while victims are left alone

The 'bank employee' scam — how criminals bypass safeguards while victims are left alone

Modern fraud no longer requires hacking systems. A phone, an app and the customer's trust are enough.

In recent months, court experts in digital forensics have increasingly been analysing fraud cases whose course is almost identical: a person contacting the victim by phone poses as a bank employee and reports an alleged attack on the account. In the name of "securing the funds", the victim performs a series of actions that result in their account being completely emptied. Importantly – everything happens in full accordance with banking procedures and using legitimate tools.

In such cases criminal proceedings are routinely discontinued because the perpetrator has not been identified, and the victims are left with no means of living. The victim's basic tool is a complaint to the bank — under the Payment Services Act (implementing PSD2) the bank is, as a rule, obliged to refund the amount of an unauthorised transaction by the end of the next business day (Article 46), and the Financial Ombudsman assists in disputes. When the bank refuses, the civil route remains, in which the key piece of evidence is often… an expert opinion.

How do the fraudsters operate?

The scenario is almost always the same:

  1. A call from the bank's hotline – the hotline number (e.g. 800 302 302) is faked using spoofing. A trusted number appears on the victim's screen, so it does not arouse suspicion.
  2. A security-department employee – a person with an accent or well-trained language informs the customer that their account has been attacked and requires immediate protection.
  3. Installing the TeamViewer or AnyDesk app – the victim is asked to download a legitimate remote-access application "to secure the account". In reality it gives the fraudster a live view of the victim's screen and guides them step by step; on a computer this can be full remote control, on a smartphone usually a live view — in both cases enough to capture login credentials and authorisation codes.
  4. Remote control over the banking app – the criminal sees everything happening on the screen, can enter transfer details, copy authorisation SMS messages, and even change transaction limits.
  5. "Securing the funds" in a new account – the victim is given the number of a "secure technical account" to which their funds are transferred. In reality they go to the criminals.

Why don't the banking systems react?

From the banking system's point of view, everything looks like standard customer activity:

  • logging in from a trusted device,
  • entering the correct SMS codes,
  • consciously approving transfers.

The bank detects no anomaly — and, moreover, usually rejects the complaint, claiming that "the customer confirmed the transactions themselves". In reality the customer acted under the influence of fraud and a mistake as to identity and purpose.

What can the victim do?

In practice the victim is left with no money, no support and a terse decision by the prosecutor to discontinue the investigation. The available avenues for pursuing claims include:

  • a complaint to the bank and a demand for a refund of the unauthorised transaction (the Payment Services Act / PSD2 — a refund, as a rule, by the end of the next business day, Article 46), and, in the event of refusal, the support of the Financial Ombudsman,
  • a civil lawsuit against the bank,
  • appointing a digital-forensics expert who will assess whether genuine authorisation took place,
  • demonstrating that the customer's actions were manipulated by the perpetrators, rather than conscious and free.

The expert's role in cases of this type

The court expert analyses:

  • event logs from the banking system,
  • internet transmission data (IP addresses, devices, times),
  • the nature of the remote-access application,
  • the mechanisms used to manipulate the victim.

The expert's opinion often has decisive significance for establishing whether the transfers were actually authorised, or merely formally clicked by the victim under the influence of the fraudster. Courts increasingly accept the conclusion that "approving" an operation does not mean the customer's genuine consent.

Systemic conclusions

The scale of this type of crime in Poland is enormous, and the consumer-protection system is ineffective. Law-enforcement efforts often end in discontinuation. Banks shield themselves with procedures. The customer is left alone.

Change is needed:

  • in banks' procedures (greater transaction-risk analysis),
  • in the legal system (a presumption of a lack of consent in cases of spoofing),
  • and in public awareness – that clicking under the influence of a fraudster is not the same as a conscious decision.

Do you have a similar case?

As a court expert dealing with digital forensics and the analysis of digital fraud, I offer the preparation of detailed technical opinions in civil cases concerning unauthorised transfers, spoofing and social-engineering manipulation. Every case requires an individual assessment — but there are recurring patterns that I can recognise and document.

Do you have questions? Get in touch – I will help you understand what really happened.

Prepared by: Waldemar Chodasiewicz Date prepared: 20 May 2024