Blindfy — Digital Protection

The fake call center: the scam that bypasses biometrics and passwords

How banking vishing convinces the victim to authorize their own fraud — doubling Pix losses according to Febraban.

Audience: Companies and Operations · Risk level: CRITICAL

Blindfy Intelligence Unit · Technical review by Blindfy

Scenario

The finance team gets a call or WhatsApp from someone claiming to be the "bank manager" warning of a suspicious transaction. Under pressure, the employee authorizes with biometrics and password what they believe is a cancellation — and is actually transferring the company's balance.

How the scam works

Criminals use leaked data (CPF, branch, last account digits) to build credibility. They ask the victim to open the app, read the "cancellation code" and use biometrics — which in practice authorizes an outgoing Pix. The attack couples social engineering with the app's own legitimate flow.

Common mistake

Thinking biometrics and passwords are impenetrable. The criminal doesn't need to break them — he convinces the victim to use them.

Impact

According to Febraban, losses from fraudulent Pix have doubled, exceeding R$ 2.7 billion. For companies, the scam drains working capital, causes supplier defaults and exposes financial governance failures.

What works

Blindfy implements reverse verification protocols (the company calls back through an official channel), monitors financial data exposure in leaks and trains treasury teams with periodic vishing simulations.

Protection checklist

  • Forbid authorizing transactions initiated by an incoming call
  • Adopt a single callback channel via a saved official number
  • Set daily Pix limits per user and per time window
  • Require dual approval for out-of-pattern transfers
  • Monitor leaks of the company's financial data
  • Train treasury with quarterly vishing simulations
  • Document every financial call received

Editorial sources

Passwords and biometrics don't fail — the protocol that allows using them under pressure does. Shielding the process is what separates a secure company from a silent victim.

← All risk analyses · Blindfy initial assessment