Dhaka, Oct 10 (V7N) – A message warning that a bank account will be suspended, a notification promising an expensive prize or a link asking users to verify their social media accounts may appear harmless. But behind such messages can lie a sophisticated cybercrime operation designed to steal passwords, financial information and personal data.
Phishing, a form of online fraud that exploits trust, fear and curiosity, has become one of the most persistent threats in the digital world. Cybercriminals increasingly impersonate banks, mobile financial service providers, government agencies and well-known technology companies to persuade victims to disclose sensitive information or transfer money.
As part of Cybersecurity Awareness Month in October, the Cyber Crime Awareness Foundation has highlighted the importance of recognising phishing attempts and developing safer online habits. Cybersecurity experts and law enforcement agencies worldwide are also warning that criminals are combining traditional deception with artificial intelligence, making fraudulent messages, voices and online identities increasingly convincing.
A global problem measured in billions
The scale of cybercrime is reflected in the latest figures from the United States Federal Bureau of Investigation (FBI). According to its 2025 Internet Crime Report, released in April 2026, the FBI's Internet Crime Complaint Center received more than 1 million complaints involving suspected internet crime, with reported losses approaching $21 billion.
Phishing and spoofing, extortion and investment schemes were among the most frequently reported categories. The report also highlighted the growing financial impact of cryptocurrency-related fraud and scams involving artificial intelligence. <Link url="https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions" title="FBI report on internet crime and AI-related scams"/>.
These figures cover reported complaints in the United States, rather than the entire world. They nevertheless illustrate the scale of the threat facing internet users, businesses and financial institutions. Actual losses may be higher because not every victim reports an incident.
How phishing traps its victims
Phishing typically begins with a message that appears to come from a trusted source. The sender may claim that an account has been compromised, a payment has failed or immediate action is required to prevent a service from being suspended.
The message often contains a link to a fraudulent website designed to resemble the genuine website of a bank, mobile financial service provider or social media platform.
Once a victim enters a username, password, card number or other sensitive information, the details may be transmitted directly to the criminals. Stolen credentials can then be used to access accounts, impersonate victims or facilitate further fraud.
Fear is one of the most effective tools used in these schemes. A message claiming that a bKash or bank account will be blocked unless the recipient immediately clicks a link can trigger panic and discourage careful verification.
Greed and curiosity can be equally effective. Fraudsters may promise lottery winnings, expensive smartphones, cash rewards or exclusive offers in exchange for personal information.
Cybersecurity guidance from the US Cybersecurity and Infrastructure Security Agency (CISA) warns users to be cautious of messages that demand immediate action, offer rewards that appear too good to be true or request sensitive personal information. It also advises users to examine suspicious links and report questionable messages through appropriate channels. <Link url="https://www.cisa.gov/sites/default/files/2024-02/Update%20to%20Phishing%20General%20Security%20Postcard_01.01.2024.pdf" title="CISA phishing safety guidance"/>.
Fake social media logins and stolen identities
Social media platforms have become another major target for phishing operations. Criminals may send messages claiming that an account must be verified, warning that a page violates platform rules or alleging that someone has attempted to access the account.
The link may lead to a fake login page that closely resembles the legitimate service. When users enter their credentials, criminals can capture them and potentially take control of their accounts.
A compromised account can then be used to deceive friends, relatives or business contacts. Criminals may request emergency loans, circulate fraudulent investment offers or distribute malicious links while posing as the account's legitimate owner.
The consequences can extend beyond the original victim. A stolen account may become a new tool for targeting dozens or even hundreds of other people.
Artificial intelligence makes deception more convincing
The threat has grown more complex as criminals adopt artificial intelligence to create convincing messages, impersonate trusted individuals and automate fraudulent communications.
One widely reported example occurred in Hong Kong in 2024, when an employee was deceived during a video conference involving deepfake representations of company executives. The employee authorised transfers totalling about $25 million, believing the instructions were legitimate. The incident demonstrated how criminals can exploit trust in familiar faces and voices, not just email addresses or website designs. <Link url="https://www.reuters.com/legal/legalindustry/real-insurance-coverage-increasing-ai-deepfake-risks-2024-04-11/" title="Reuters report on AI-enabled impersonation fraud"/>.
The FBI's 2025 Internet Crime Report recorded more than 22,000 complaints involving AI-related information, with reported losses exceeding $893 million. The report warned that AI-generated content can make fraudulent profiles, personalised conversations and impersonation attempts harder to recognise. <Link url="https://www.fbi.gov/file-repository/2025_ic3report.pdf" title="FBI 2025 Internet Crime Report"/>.
Experts caution that a familiar voice, a convincing video call or a professionally written message should no longer be treated as proof of authenticity. Financial instructions and unusual requests should be independently verified through a trusted communication channel.
Bangladesh's warning from the 2016 cyber heist
Bangladesh has already experienced the potentially devastating consequences of a major cyberattack.
In February 2016, hackers used compromised systems and fraudulent payment instructions involving the SWIFT financial messaging system to target Bangladesh Bank's account at the Federal Reserve Bank of New York. Transfers worth $81 million were successfully made to accounts in the Philippines, while other attempted transfers were blocked.
The incident was not simply a conventional phishing scam; it involved a broader intrusion into the bank's systems and manipulation of financial transactions. However, it remains a significant reminder that compromised credentials, inadequate security controls and failures to detect suspicious activity can expose even major financial institutions to enormous losses. <Link url="https://www.business-standard.com/article/reuters/swift-network-wasn-t-hacked-in-81-million-bangladesh-heist-116051201128_1.html" title="Reuters report on the Bangladesh Bank cyber heist"/>.
The lesson extends beyond banks. Individuals, businesses and public institutions all need safeguards that prevent a single stolen password or deceptive message from becoming the starting point of a larger security breach.
Why passwords alone may not be enough
Cybersecurity specialists recommend multiple layers of protection rather than relying exclusively on users to identify every fraudulent message.
CISA advises organisations to use multifactor authentication (MFA), which requires an additional form of identity verification beyond a password. It particularly recommends phishing-resistant authentication because some conventional verification methods can still be circumvented through sophisticated attacks. <Link url="https://www.cisa.gov/audiences/small-and-medium-businesses/secure-your-business/require-multifactor-authentication" title="CISA guidance on multifactor authentication"/>.
For individuals, the basic precautions remain essential: use unique passwords, enable multifactor authentication, keep devices and applications updated, and avoid entering credentials after following unexpected links.
Users should also remember that a legitimate bank or mobile financial service provider may contact customers about account activity, but they should never disclose passwords, PINs or one-time verification codes to someone who requests them. Any unexpected request involving money or sensitive information should be verified through the provider's official app, website or independently obtained customer service number.
What to do after clicking a suspicious link
If a user has entered a password or financial information on a suspicious website, immediate action can reduce the potential damage.
The affected password should be changed through the official website or application, and the same password should be changed on any other account where it was reused. Users should contact their bank or mobile financial service provider immediately if payment details, PINs or verification codes may have been exposed.
Suspicious transactions should be reported promptly. Victims should preserve messages, transaction records, phone numbers and website addresses that may assist an investigation. They should also report the incident to the relevant platform and law enforcement authorities.
If a device appears to have been compromised, users should avoid entering further sensitive information on it until it has been checked and secured.
Awareness must accompany technology
Phishing succeeds not only because of technical weaknesses but also because criminals understand human behaviour. Urgency, fear, financial pressure and the promise of easy rewards can cause people to act before verifying a message.
Cybersecurity awareness campaigns therefore have an important role in helping people recognise warning signs. Schools, universities, businesses, banks and public institutions can strengthen protection through regular training, clear reporting procedures and practical demonstrations of common scams.
Technology companies and financial institutions also have a responsibility to improve account security, detect suspicious activity and make it easier for customers to report fraud.
As digital services become increasingly integrated into daily life, protecting personal information is no longer solely a technical concern. It is a shared responsibility involving users, service providers, businesses and law enforcement agencies.
The most effective first line of defence remains a simple habit: pause before clicking, verify before sharing information, and never allow fear or the promise of a reward to replace careful judgement.
END/ATN/SMA/