Phishing scam pretends to show HSBC transfer alert to steal email credentials

A recent phishing campaign mimics HSBC payment alerts with urgent claims of large transfers to lure victims into a fake Gmail login page, risking credential theft and broader account compromise.

A phishing campaign posing as an HSBC payment alert is using a startling claim , that a $102,000 transfer has already been completed , to push recipients towards a fake Gmail sign-in page. The message is designed to create panic and urgency, but its real aim is to steal email credentials rather than let the victim review a bank receipt.

The lure mimics a bank confirmation with a reference number, masked account details, a fee and a payment note, yet it also contains obvious warning signs, including inconsistent currencies and misspelled words. MalwareTips says the button labelled “Review Payment Recipt” leads away from HSBC to a page that imitates Google’s login screen, showing how the scam uses the appearance of a banking document to hide a credential theft attempt.

That distinction matters because access to an inbox can be more valuable to criminals than access to a single bank account. As PCrisk notes, attackers can use a compromised email account to search for banking alerts, password resets, invoices and identity documents, then build more convincing follow-up scams or reset other accounts tied to the same address. HSBC’s own fraud pages warn that customers should never share personal or security information by email and should contact the bank directly if anything looks suspicious.

The safest response is to check any alleged transfer only through the official HSBC app or a bank website entered independently, not through a link in the message. HSBC Bank USA advises customers to be wary of impersonation scams and to verify suspicious contact through trusted channels, while HSBC Private Bank says phishing emails often rely on urgency, fear and the appearance of legitimacy to trick people into giving away sensitive information.

Anyone who clicked the link and entered a password should change it immediately, review recovery settings and signed-in sessions, and check the mailbox for forwarding rules or other unauthorised changes. Security researchers also recommend scanning the device for malware, since some phishing campaigns pair credential theft with broader account compromise.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.