A significant surge in mobile phishing attacks targeting brokerage accounts has emerged in 2024 and continued into 2025, with cybercriminal groups deploying sophisticated phishing kits and adapting their tactics to circumvent enhanced security measures. The primary methodology in these attacks is the “ramp and dump” scheme, which involves manipulating stock prices through coordinated use of compromised brokerage accounts. The pattern follows broader trends in financial fraud techniques, including the massive compromise of 115 million US payment cards through digital wallet exploits in 2023-2024.
Between 2022 and 2024, early phishing attacks primarily used text message phishing (smishing) to impersonate entities such as the U.S. Postal Service or toll operators. Attackers tricked victims into entering payment information on fraudulent websites, then used SMS one-time codes to enroll stolen card details into mobile wallets on controlled devices, enabling fraudulent transactions. The method proved particularly effective before major platforms began phasing out SMS-based verification in favor of more secure authentication methods.
While financial institutions have strengthened authentication for mobile wallet enrollment by requiring bank mobile apps instead of SMS one-time codes, fraudsters have pivoted to targeting brokerage accounts, which present distinct security challenges. Since brokerage platforms typically block direct wire transfers, attackers now use multiple compromised accounts to manipulate foreign stock prices artificially. The shift comes as regulatory bodies worldwide implement stricter security frameworks for trading accounts.
The “ramp and dump” scheme involves coordinated buying activity to inflate targeted foreign stock prices, followed by selling holdings at a profit before the price collapses. The methodology exploits fragmented security controls across brokerage platforms and the challenges in detecting coordinated account manipulation. The sophistication of these attacks has increased alongside the proliferation of mobile infostealer malware targeting multi-factor authentication systems.
Looking ahead to 2025, experts anticipate these attacks will continue as criminals refine their techniques and exploit weaknesses in multi-factor authentication systems. Financial institutions are implementing enhanced security protocols, including improved anomaly detection for suspicious trading patterns and transitioning to app-based verification methods.
“The reliance on a single, phishable one-time token for provisioning mobile wallets,” said a leading cybersecurity expert, “was previously exploited, but many financial institutions that were caught flat-footed on this scam two years ago have since strengthened authentication requirements.”
The threat landscape is further complicated by the rise of low-cost initial access brokers selling compromised credentials, facilitating network infiltration and attack escalation. Investment scams, particularly those using social media channels, have resulted in a 50 percent increase in reported losses in early 2025. The increase matches broader trends in virtual banking fraud, which has seen significant growth across multiple regions, including a 73 percent rise in virtual banking fraud in South Africa.
Sources: KrebsOnSecurity, Cloud Security Alliance, Western Illinois University Cybersecurity Center, Infosecurity Magazine, Australian Tax Practitioners Board