Weaponized ‘transaction alert’ message

TechnologyDigital
29 Jul 2026 • 12:08 AM MYT
The Manila Times
The Manila Times

One of the longest-running English broadsheets in the Philippines

Weaponized ‘transaction alert’ message

“TRANSACTION ALERT! An unusual transaction of PHP 21,100.00 was detected on your account. If you did not authorize this, cancel here: [link]. Do not share your OTP or password with anyone.”

Nearly every Filipino who owns a bank account or an e-wallet has received a message like this, or something almost identical to it. Read it again, slowly. Notice how reasonable it sounds. Notice how it even warns the reader never to share an OTP with anyone. That line is not there to protect anyone. It is there to earn trust just long enough to destroy it.

A trained eye would already smell danger just by looking at the link. The real bank’s website ends in “.com.ph”. This one ends in “.co,” designed to look familiar but belonging to no bank at all. The word “pay” was added to sound official, and “.co” was chosen because it resembles “.com” just enough to slip past a hurried reader. After that comes a string of random letters and numbers, a tag most people would never notice, but one that lets the criminal track who clicked and from where. None of this takes special training to catch. It only takes the habit of pausing before tapping.

This needs to be said plainly, because most people have not grasped how serious this shift has become. For years, Filipinos were told to watch out for suspicious links and urgent threats. That advice worked, so criminals abandoned it and began impersonating the defenses instead of sneaking past them. The very message above, the very “Verify You’re Human” checkbox found on countless websites, the very approval request from a banking app, can now all be faked with frightening precision. Once a scam looks like security, a person’s guard drops completely, because years of training have taught them to trust exactly that look.

Consider how bad this has gotten. Criminal networks now build fake versions of the human-verification puzzle found on countless websites, the one asking a user to click a box or solve a picture. Instead of letting the person through, it instructs them to open a command window and paste in a string of code to “complete the verification.” That code is not verification. It is a loaded weapon, and the victim pulls the trigger themselves, believing they are following a routine safety step. There have already been documented cases where this exact trick delivered password-stealing malware through cloned pages mimicking trusted names.

It gets worse. Criminals now flood victims’ phones at night with real login approval requests, the same “Approve this login?” notification banks trained customers to trust. One request. Then another, at two in the morning, until an exhausted thumb finally taps “approve” just to make it stop. The bank’s own security feature becomes the button that lets the thief in. Security agencies worldwide flag this as one of the fastest-growing attack methods today, precisely because it needs no hacking skill at all, only patience and exhaustion.

Even the instinct to call for help is turned against victims. Some fraud rings leave a phone number instead of a link, knowing a link can be blocked by spam filters but a call cannot. A calm, professional-sounding voice answers, speaks the vocabulary of a real bank agent, and walks the victim into surrendering access to their own device. No malware, no suspicious file, just a voice trained to be trusted, doing exactly what a text was feared to do.

Now consider a busy day, distracted, in a jeepney, or cooking dinner. Would there be time to notice a strange domain, or would a thumb move faster than caution allowed? Most people would need a second look, and a second look is exactly what these messages are designed to prevent.

This should alarm anyone who lives their financial life inside a phone. People trust apps because they look official, carrying the right logos and the same security language their banks taught them to recognize. That trust is no longer a shield. In the wrong moment, it is an open door.

So, what should ordinary users do, faced with a threat that has learned to disguise itself as protection? First: no legitimate bank, app, or website will ever ask a user to open a command line, terminal, or code-pasting window. If anything on the screen asks for this, it should be shut down immediately, no matter how official it looks.

Second, familiarity should not be trusted blindly. A message that looks exactly like the ones safely dismissed before is not proof this one is safe too. Criminals copy people’s habits precisely, right down to the polite reminder not to share an OTP.

Third, if a login approval request appears and the user did not just try to log in, it should never be approved, not out of irritation, not to make notifications stop. Change the password and call the bank using the number printed on the card, never one given by the message itself.

Fourth, any unexpected call or text claiming to be from a bank or an IT provider deserves the same suspicion given to a stranger at the door, however polished the voice.

Filipinos have survived worse threats, but by staying alert to what looked wrong. This new danger demands something harder: staying alert even to what looks exactly right. The scammers have learned the language of safety fluently, right down to the message sitting in someone’s inbox today. It is time to ask, even of the most trusted signals, whether they are truly what they claim to be. Money, identities and peace of mind depend on it.

Newswav Malaysia Best News App

Newswav is an online content aggregator and obtains its content from different online sources. The content in the app do not belong to Newswav nor do they reflect the opinions of Newswav and its staff. Your use of this app indicates your understanding and acceptance of this information.

Newswav Sdn. Bhd. (201701008480 (1222645-M)) 2026 All Rights Reserved