STRAITMERE FUND RECOVERY SUPPORT

Bank phishing fraud

A password field being filled in

$7,900

Amount lost

Cloned login page

Method used

Hours, not days

Window to act

How a phishing transfer was challenged after the bank first refused responsibility

A client came to Straitmere after losing $7,900 to a bank phishing attack. The people behind it had built a login page that was an exact copy of his bank's, down to the wording and the security notices. He entered his credentials on what he had every reason to believe was his own bank's website.

What happened

It started with an email that appeared to come from his bank, asking him to complete a "security verification" of his account details. The message reproduced the bank's official format precisely — logo, tone, footer, the lot. The link led to the cloned page, and within minutes of him entering his details the account was accessed.

The $7,900 was moved quickly through several intermediary accounts. By the time he realised what had happened, the money had been split across accounts in different countries — which is exactly what the layering is designed to achieve, because every hop makes the trail harder to follow and the money harder to freeze.

How the case was worked

In cases like this, time is the deciding factor. As soon as the case reached us we sent a formal notice to the bank requesting that the transfers be blocked, and worked to identify where the money had been routed through international banking channels.

We also documented, in detail, the gaps in the bank's security procedures and the duties it owed its customer. This is the part clients cannot realistically do alone: the bank had initially declined any responsibility, and changing that position required the failures to be set out precisely rather than argued over the phone.

Where it landed

After urgent intervention, a substantial part of the client's money was recovered — most of it was frozen while still sitting in the intermediary accounts and subsequently returned. The decisions rested with the bank and the institutions involved; our role was to reach them fast enough and with a documented case.

The lesson is a hard one: in phishing cases the window is measured in hours, not weeks. Many people spend those hours feeling embarrassed and hoping the bank will fix it on its own. That delay costs more than the mistake did.

FREE CASE REVIEW

Start with a free review of your case

We work with clients across Malaysia on matters from $1,500. Romance and relationship-based scams, messenger-only schemes, e-commerce disputes and purely offline transactions are outside our scope.