The fake call center: the scam that bypasses biometrics and passwords
How banking vishing convinces the victim to authorize their own fraud — doubling Pix losses according to Febraban.
Audience: Companies and Operations · Risk level: CRITICAL
Blindfy Intelligence Unit · Technical review by Blindfy
Scenario
The finance team gets a call or WhatsApp from someone claiming to be the "bank manager" warning of a suspicious transaction. Under pressure, the employee authorizes with biometrics and password what they believe is a cancellation — and is actually transferring the company's balance.
How the scam works
Criminals use leaked data (CPF, branch, last account digits) to build credibility. They ask the victim to open the app, read the "cancellation code" and use biometrics — which in practice authorizes an outgoing Pix. The attack couples social engineering with the app's own legitimate flow.
Common mistake
Thinking biometrics and passwords are impenetrable. The criminal doesn't need to break them — he convinces the victim to use them.
Impact
According to Febraban, losses from fraudulent Pix have doubled, exceeding R$ 2.7 billion. For companies, the scam drains working capital, causes supplier defaults and exposes financial governance failures.
What works
Blindfy implements reverse verification protocols (the company calls back through an official channel), monitors financial data exposure in leaks and trains treasury teams with periodic vishing simulations.
Protection checklist
- Forbid authorizing transactions initiated by an incoming call
- Adopt a single callback channel via a saved official number
- Set daily Pix limits per user and per time window
- Require dual approval for out-of-pattern transfers
- Monitor leaks of the company's financial data
- Train treasury with quarterly vishing simulations
- Document every financial call received
Editorial sources
- Banco Central do Brasil — Orientações oficiais sobre golpes e Pix
- CERT.br / NIC.br — Cartilha de Segurança para Internet
- ENCCLA / Ministério da Justiça — Enfrentamento a golpes digitais
Passwords and biometrics don't fail — the protocol that allows using them under pressure does. Shielding the process is what separates a secure company from a silent victim.