Scammers Impersonate Zelle via the Lure of “Getting Paid” to Get Paid Themselves

Stu Sjouwerman | Apr 27, 2023

Zelle impersonation scamA new impersonation scam targets users of the popular pay platform under the guise of the victim having money coming to them and with the goal to obtain Zelle credentials.

The goal of impersonating is as much to establish credibility as it is to leverage a brand with a large customer base to target. With over 67 million users, Zelle is a perfect brand to use if you’re a scammer looking to take victims for credentials that give you access to money and contacts (who you can further scam).

According to security researchers at security vendor Avanan, a new Zelle-themed scam includes an email with great presentation and a short URL that takes victims to a lookalike site:

Zelle-themed impersonation scam

The goal of these attacks, according to Avanan, is to establish credibility and rush the victim to forgo security checks, falling victim to the many possible scams this initial phishing email can lead to.

This serves as a reminder that all it takes is the right brand used in a phishing attack against a user utilizing that brand to make that person a victim. Whether it’s consumer-focused attacks – like the Zelle attacks – or ones impersonating business brands (e.g., Microsoft, UPS, banks, etc.), everyone needs to be aware of the possibility of such attacks and how to spot them quickly. Corporate users can undergo continual security awareness training to teach them how to spot an impersonation attack and keep from becoming its’ next victim.

Topics: Phishing

Discover dangerous look-alike domains that could be used against you! 

Since look-alike domains are a dangerous vector for phishing attacks, it's top priority that you monitor for potentially harmful domains that can spoof your domain.

Our Domain Doppelgänger tool makes it easy for you to identify your potential "evil domain twins" and combines the search, discovery, reporting, risk indicators, and end-user assessment with training so you can take action now.

DomainDoppelgangerResults-1Here's how it's done:

  • Get detailed results of look-alike domains found similar to your primary email domain
  • You can now quiz your users with your look-alike results
  • Get a summary PDF that contains an overview of the look-alike domains and associated risk levels discovered during the analysis
  • It only takes a few minutes to discover your “evil domain twins”!

Find Your Look-Alike Domains!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/domain-doppelganger

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.