Ingenious Fraud Through Email and Mobile Devices
Remote Access Disguised as “Help”
In many cases, attackers convince the victim to install remote control applications such as:
- AnyDesk
- TeamViewer
- RustDesk
The usual excuses include:
- “I’ll help you configure something.”
- “I’ll share internet with you.”
- “It’s to check your connection.”
- “It’s to verify your account.”
Once the victim shares the access information (session ID or connection code), the attacker gains visual and operational control of the device.
At that point, the attacker can:
- Open your banking app
- Register a new device
- Add a destination CLABE account
- Make real-time transfers
Many victims believe the money “disappeared on its own,” but in reality the criminal operated the banking app directly from the victim’s phone or computer.
Network Interception (If You Connected to Their Internet)
If the attacker provided access to their Wi-Fi network—or to a network they controlled—another possible scenario is a Man-in-the-Middle attack.
Although banking apps use strong encryption, if the device was already compromised or if a malicious certificate had been installed beforehand, attackers could potentially:
- Intercept credentials
- Capture session tokens
- Register the device as authorized
This type of attack is more technical, but it has occurred in real cases.
Device Registration Within the Banking App
What you mentioned is very important:
“They entered my account and within the app added a way to make transfers.”
Some banks allow users to:
- Enable SPEI transfers
- Register frequent recipient accounts
- Authorize new devices
- Change transfer limits
If an attacker manages to enter the account even once, they can:
- Register their own account as a frequent recipient
- Wait a few hours
- Empty the account in several transfers (to avoid automatic alerts)
This pattern is typical in mobile banking fraud.
Theft of SMS Codes or Authentication Tokens
Another possibility is that during the remote access session, the attacker could see SMS verification codes or push authorization notifications.
Many banks use authentication methods such as:
- SMS codes
- Digital tokens within the app
- Push notifications for approval
If the attacker could see the victim’s screen, they could approve the operations in real time.
Malware Already Installed on the Device
There is also specialized malware designed for mobile banking attacks (banking trojans). These can:
- Clone banking app screens
- Steal credentials
- Intercept SMS codes
- Overlay fake login screens
This type of malware has been particularly common on Android devices.

Typical Fraud Pattern in Cases Like This
The sequence usually follows this pattern:
- Gain the victim’s trust
- Obtain remote access or control of the network
- Access the banking app
- Register a destination account
- Make transfers in blocks (three transfers is very common)
- Quickly move the funds to “mule accounts”
Is This a Known Type of Fraud?
Yes. It is commonly classified as:
- Remote access fraud
- Social engineering fraud
- Mobile banking compromise
- In corporate environments, it resembles Account Takeover
It is not a sophisticated “movie-style hacking attack.” Instead, it is social engineering combined with control of the victim’s device.
Key Indicators in a Case Like This
The most relevant details you mentioned are:
- It happened within the same bank
- It occurred first on one account
- Then it happened on yours
- All the money was transferred in three transactions
This strongly suggests that the attacker:
- Already knew how to operate that specific banking app
- Knew where transfer settings were located
- Acted quickly to avoid account blocking
What to Do Immediately (If You Haven’t Already)
- Request a formal report from the bank.
- Ask for the access logs, including:
- Registered device
- Access IP address
- Exact timestamps
- File a complaint with CONDUSEF.
- Completely format the affected device.
- Change all passwords from a clean and secure device.
- Enable biometric authentication and two-factor authentication.
Important Point
In many of these cases, banks argue that:
“The operation was correctly authorized from the client’s device.”
Technically, that may be true—however, it occurred under manipulation.
But if there was:
- A newly registered device that had not been used before
- An unusual IP address
- Atypical transfer patterns
There may still be grounds for a formal claim.
If you want, I can also help you turn all the cybersecurity articles you wrote into a professional English blog section, which can help position your website internationally and improve SEO.
