Scammers Impersonate Zelle via the Lure of “Getting Paid” to Get Paid Themselves

Stu Sjouwerman | Apr 27, 2023

Zelle impersonation scamA new impersonation scam targets users of the popular pay platform under the guise of the victim having money coming to them and with the goal to obtain Zelle credentials.

The goal of impersonating is as much to establish credibility as it is to leverage a brand with a large customer base to target. With over 67 million users, Zelle is a perfect brand to use if you’re a scammer looking to take victims for credentials that give you access to money and contacts (who you can further scam).

According to security researchers at security vendor Avanan, a new Zelle-themed scam includes an email with great presentation and a short URL that takes victims to a lookalike site:

Zelle-themed impersonation scam

The goal of these attacks, according to Avanan, is to establish credibility and rush the victim to forgo security checks, falling victim to the many possible scams this initial phishing email can lead to.

This serves as a reminder that all it takes is the right brand used in a phishing attack against a user utilizing that brand to make that person a victim. Whether it’s consumer-focused attacks – like the Zelle attacks – or ones impersonating business brands (e.g., Microsoft, UPS, banks, etc.), everyone needs to be aware of the possibility of such attacks and how to spot them quickly. Corporate users can undergo continual security awareness training to teach them how to spot an impersonation attack and keep from becoming its’ next victim.

Topics: Phishing

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.