From deepfakes to foreign mules: How scammers are adapting to steal local funds
While BOV customers lost €6.8m to fraud last year, the bank says it stopped another €3m from being lost
No proceeds derived from major frauds have ended up in Maltese banks in the past three years, the head of Bank of Valletta’s fraud prevention unit said.
“In the last three years, I have never seen a victim of fraud where the money ended locally... not even once in the local banks or in the local sphere,” BOV group chief anti-financial crime officer Ryan Caruana said.
Noting that BOV had prevented some €3 million from being lost to fraud last year, he said all the funds in question had been destined for “foreign IBAN numbers, foreign banks, foreign jurisdictions, either in the EU or in third countries”.
European countries, including Lithuania, the UK, France and Spain, were among those favoured by fraudsters, he said, noting that prevention efforts were complicated by scammers opening accounts in different jurisdictions.
Stressing the importance of due diligence controls at receiving banks, Caruana insisted that “the other bank should know why someone is constantly receiving certain amounts”.
Fraudsters were increasingly turning to cryptocurrencies and money “mules” – paid intermediaries – to help them shield funds from the gaze of authorities, he said.
Times of Malta reported in January that a couple alleged to have defrauded third-country national (TCN) workers out of hundreds of euros each used TCN intermediaries in Malta, who would receive the funds in their home country bank accounts before withdrawing the money in cash in Malta and handing it over to the couple.
With BOV losing some €6.8 million to fraud last year, the €3 million saved represents just under one third of the total funds targeted by scammers. “That shows that our controls are working and they’re working well,” said Caruana, adding that, though fraud attempts had been ongoing for some time, they had “really kicked off” in the past three years.
While most attempted frauds were targeting “very low” sums of money, BOV had also seen “very good” cases of fraud prevention where it prevented amounts of between €500 and €2,000 from being taken, he noted.
Never click on links sent by SMS, even if they claim to be from the bank, Ryan Caruana warned. Photo: Shutterstock.Spoofing
Caruana stressed that fraud was an issue facing all banks, with a report by the NASDAQ stock exchange finding that more than €85 billion had been lost to fraud across the EU and UK in 2024.
He noted that a Financial Action Task Force (FATF) report published in February found that fraud now accounted for some 40% of all UK crimes.
BOV faced criticism in February when former journalist and ex-Nationalist Party candidate Norman Vella accused the bank of failing to address “known security weaknesses” that allowed fraudsters to move money out of accounts without detection.
He claimed the bank relied on text messages (SMS), accusing it of having substandard controls in place for logins on new devices and insufficient transaction monitoring.
The criticism followed the well-publicised case of alleged fraudster Tammy Caruana, who is accused of duping some 200 victims out of more than €1 million.
Addressing concerns about the bank’s use of SMS messages, Caruana stressed the bank never sent links by text message, noting that, with the use of new technologies, it was “much easier” to spoof, or falsify, a phone number, something banks had “no control over”.
He added that several local entities were working on the problem “to keep this threat as low as possible”, acknowledging that new technologies presented a challenge to banks.
However, there was “nothing wrong” with someone calling a BOV customer claiming to represent the bank: “We do call people for appointments, support and documentation to understand transactions – [there’s] nothing wrong in that”.
How can someone tell if the call is fraudulent?
The caller asking a customer for the last four digits of their bank card “is one of the red flags”, said Caruana. Neither should a customer be asked for any login information.
Requests for the last digits of an ID card or account number, made to increase trust in the caller, were also red flags to watch out for, he said. “Irrespective of what you will say, the other person on the line will say, yes, thank you – even if you make mistakes.”
BOV faced criticism earlier this year following the well-publicised case of alleged scammer Tammy Caruana. Photo: FacebookDeep fake
Similarly, SMS messages advising a customer that their account has been blocked or there is an issue with their card, usually including a malicious website link, were also warnings to watch out for.
While Maltese speakers may have in the past found comfort in being called by someone speaking in Maltese, due to the language’s low user base worldwide, that was no longer the case, Caruana pointed out. He said the possibility of someone employing artificial intelligence to produce a “deep fake” (synthetic media) voice speaking Maltese existed, in addition to locals becoming involved in carrying out scams.
Aside from not giving out login-capable information or clicking links in SMS messages, Caruana also advised customers to carefully consider the destination of any transfer and why they are sending it.
“I find it very hard to believe that people start sending money to people they never met,” he said, noting such transfers could be involved in romance or investment scams: “Why should someone invest in certain programmes with expectations that are too good to be true?”
Although the bank was “materially” stepping up its fraud prevention systems, “the best control is education in fraud”, he said.