Barclays Hit in Phishing Scam Using Monzo Account, PISP

Millions of pounds were swiped from Barclays accounts in a phishing scam by a fraudster using a Monzo account and a payments initiation service provider (PISP), The Telegraph reported.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    yesSubscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    PISPs are a newer concept, introduced by the revised European Payment Services Directive (PSD2), and give retail customers the ability to pay companies directly from their bank account instead of using a debit or credit card.

    “There is nothing new or different about a fraudster’s approach to these cases that are specific to using a PISP,” a Barclays spokesperson said, per the report. “It is the same type of social engineering to convince victims to share passcodes/Pinsentry codes as is done to defraud customers through traditional channels. We regularly warn customers to never give out their Pinsentry codes, passcodes or any passwords to prevent this type of fraud from happening.”

    The incident comes on the heels of an antitrust probe into Monzo by the Financial Conduct Authority (FCA). Monzo, a London challenger bank, is accused of being in violation of financial crime controls and anti-money laundering (AML) mandates.

    Read more: Monzo Faces FCA Investigation Into Alleged AML Contraventions

    A similar incident involving a PISP happened in May, according to meeting minutes from the Open Banking Implementation Entity (Obie), The Telegraph reported. Monzo did not appear to be involved.

    Advertisement: Scroll to Continue

    In that case, the victim clicked on a text message link to verify a payment and was taken to a phishing website that mirrored the victim’s bank. The cyberthief then swiped the victim’s login credentials, set up an account, and used the PISP to initiate payment requests, according to the report.

    That incident prompted the Obie steering group to discuss the possibility that open banking payments were more exploitable because of the varying methods used for fraud prevention and detection along the payment journey.

    Read also: PSPs Embrace Open Banking APIs for Speed, Compliance, Insights