Case Library / Vishing (Voice Phishing) / Wells Fargo 'Alice Fries' Bank-Impersonation Vishing / 2FA-Bypass Wire Fraud (2022 fraud; 2023 lawsuit)

Wells Fargo 'Alice Fries' Bank-Impersonation Vishing / 2FA-Bypass Wire Fraud (2022 fraud; 2023 lawsuit)

A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from customer Alice Fries, and a Wells Fargo representative then knowingly overrode the bank's own $50,000 wire-review threshold to release a $100,000 fraudulent wire, per a Los Angeles lawsuit built partly on the bank's own recorded verification call.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

On October 24, 2022, Wells Fargo customer Alice Fries had a legitimate call with a Wells Fargo premier banker at 1:10 p.m. Nine minutes later, at 1:23 p.m., she received a call whose caller ID spoofed Wells Fargo's genuine 800 number. The caller, impersonating the bank, claimed her account was compromised, sent her a two-factor authentication code, and asked her to read it back, which she did. Using that code, the fraudster changed her online banking password, enrolled her account in a wire-transfer feature ("Wires Basic"), and initiated a $100,000 wire to a payee named "Savage Car Wash" in Miami, Florida, double the bank's alleged standard $50,000 online-wire limit. While still on the phone with the scammer over an hour later, Fries went to a Wells Fargo branch, where an employee said it sounded like a scam and that the wire was in process; a call-center rep told her the wire had been recalled and gave her a confirmation number, but the wire was never actually stopped and the money was sent. Wells Fargo refunded only $50 as a courtesy. Fries sued in Los Angeles (LA Superior Court case 23STCV18422, filed Aug. 3, 2023; related federal complaint C.D. Cal. 2:23-cv-07321-SPG-PD, dated Nov. 22, 2023), and discovery reportedly produced a recorded call in which a Wells Fargo wire-verification representative ("Mark") told the fraudster the amount was "unusual," had been "flagged," and required a "second review," then approved and released the wire anyway. Wells Fargo's online banking agreement contains a standard arbitration clause, and Wells Fargo has compelled arbitration in numerous other consumer disputes, but no public record was located confirming whether a motion to compel arbitration was actually filed in this specific case, and no final publicly confirmed merits outcome or settlement was located as of the last available report (April 2024 coverage).

How the Attack Worked

Per the complaint: at 1:10 p.m. on Oct 24, 2022, Fries had a legitimate call with her Wells Fargo premier banker/advisor and declined proposed investments. At 1:23 p.m., nine minutes later, she received an inbound call whose caller ID displayed the same Wells Fargo 800 number she normally saw, a spoofed call from a fraudster impersonating the bank. The caller claimed her account was compromised and, using Wells Fargo's own customer-facing verification convention, sent her a two-factor authentication code and asked her to read it back to "verify her identity." Fries complied, believing it consistent with the bank's normal process (and primed by having just spoken to a real Wells Fargo employee minutes earlier). Using the harvested 2FA code, the fraudster allegedly changed her online banking password, enrolled her account in a "Wires Basic" wire-transfer feature, and initiated a $100,000 wire to a payee called "Savage Car Wash" in Miami, Florida, an amount double Wells Fargo's alleged standard $50,000 online wire limit. While still on the phone with the fraudster (over an hour into the call), Fries grew suspicious and walked into a Wells Fargo branch, where employee "Walter" told her it sounded like a scam and that a fraudulent $100,000 wire was already in process. She then called the Wells Fargo call center; a rep ("Chavi") told her the wire had been recalled and gave her a confirmation number. The next day she learned the wire had NOT been recalled: the $100,000 had gone to Savage Car Wash. Discovery later produced a recorded call between a Wells Fargo employee ("Mark," on a wire-verification line) and the fraudster, in which Mark stated the $100,000 request was "an unusual amount of money," that it had "been flagged," that transfers over $50,000 require a "second review," and that a 24-48 hour delay could apply, then said "no worries, I'm going to release this wire transfer transaction and transfer it today," and approved it anyway.

The Lure & the Tell

The lure: an inbound call arriving just 9 minutes after a real Wells Fargo advisor call, displaying the bank's genuine, familiar 800 number on caller ID, from someone who already knew enough context to sound legitimate and who used the bank's own "read back your verification code" convention, the same convention Fries said Wells Fargo itself normally used with her. The tell (in hindsight, and flagged instantly by a human once involved): the request to read back a 2FA/OTP code over an inbound call is never legitimate no matter what the caller ID shows, since real banks generate the code for outbound-initiated verification, not to be "confirmed" to an inbound caller; additionally, a wire request that exceeds a bank's own stated review threshold, arriving on the heels of a suspicious 2FA event, is a textbook fraud pattern that the bank's own employee ("Mark") explicitly recognized and verbalized ("unusual amount," "flagged," "second review" required) before overriding it anyway, meaning the institutional tell existed and was verbally acknowledged, but not acted upon.

Outcome

Fries was refunded only $50 by Wells Fargo as a "courtesy," leaving an alleged $99,950 net loss; she filed suit (LA Superior Court case 23STCV18422, filed Aug 3, 2023; also captioned in removed/related federal filing C.D. Cal. 2:23-cv-07321-SPG-PD, complaint dated Nov 22, 2023) alleging state-law claims including UCC/Commercial Code security-procedure violations and intentional infliction of emotional distress. No public record was located confirming how the case proceeded procedurally after the November 2023 federal complaint, whether it was compelled to arbitration under Wells Fargo's standard online-banking arbitration clause, settled, or otherwise resolved, and no final merits judgment or settlement amount was found. Status should be treated as case history through the late-2023/early-2024 complaint and reporting stage, not a final verdict.

Why It Matters

This case is unusually well-documented because litigation discovery produced the bank's own internal recorded verification call, giving rare, verbatim evidence of a real-time human control (the $50,000 wire threshold / second-review requirement) being correctly identified and then knowingly overridden by bank staff, not merely a technology or process gap, but a documented human decision to bypass a known safeguard. It also illustrates a structural weakness common across bank-impersonation vishing: banks that ask customers to "read back a code we just sent you" as routine identity verification are using the identical script a scammer needs, so customers cannot distinguish a legitimate verification call from a spoofed one by process alone. The suspicious 9-minute gap between a real advisor call and the fraudulent call also raises (unproven) concerns about possible information leakage enabling more convincing, better-timed social engineering.

Defenses

Documented failure modes exposed by this case: (1) banks that use "read back the code we texted you" as an identity-verification ritual train customers to comply with exactly the request a vishing scammer will make; (2) caller ID is not authentication: spoofing a bank's real published 800 number is trivial and customers have no way to distinguish it from a real call; (3) dollar-threshold controls (Wells Fargo's alleged $50,000 online-wire limit requiring "second review" and a 24-48 hour delay) are only as strong as the human enforcing them: the complaint alleges the rep verbally acknowledged the threshold, the flag, and the review requirement, then overrode all three; (4) a recorded-line policy for high-value wire verification is a good control ONLY if supervisors audit the recordings in real time or near-real time, not just after a customer complaint triggers discovery; (5) post-incident whistleblowing to a branch employee ("Walter") who could see the wire in process shows some fraud-detection worked, but the recall/reversal process failed or was misrepresented to the customer, and the "refund only if you admit you authorized it" posture is a recurring complaint-pattern in bank-impersonation vishing suits. Recommended practices for consumers/institutions: banks should never ask customers to read back a one-time code over the phone as a verification step; customers should independently call back a number from a statement/card rather than trust an inbound caller-ID match, especially within minutes of another bank call; institutions should treat wire-limit overrides as requiring documented supervisory sign-off, not a single rep's discretion; recorded verification calls should be sampled/audited proactively, not just pulled in discovery.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and timing setup: The complaint alleges the fraudster called just nine minutes after a real Wells Fargo advisor call, which is only plausible if the fraudster already knew Fries was a Wells Fargo customer, had her phone number, and had some way to learn of or coincide with the timing of a genuine bank interaction, whether through commercially available personal data, a prior phishing/smishing contact, or (unconfirmed, per the complaint's own speculation) leaked information from inside or around the bank.
Countering Stage 1: The specific data trail that let a fraudster time a call within nine minutes of a real one is unconfirmed and largely outside a bank's direct control; the nearest practical control is for banks to treat any inbound call referencing a customer's account arriving shortly after an outbound bank-initiated contact as an elevated-risk pattern worth flagging, rather than assuming coincidence.
2
Caller-ID spoofing setup: Consistent with widely available commercial caller-ID spoofing services, the fraudster configured an outbound call to display Wells Fargo's genuine, publicly published 800 number, a technique that requires no access to Wells Fargo's systems and is trivial to obtain.
Countering Stage 2: Carrier-level STIR/SHAKEN caller-ID authentication, plus explicit customer education that a bank's real number appearing on caller ID is not proof of a legitimate call, reduces reliance on caller ID as an implicit trust signal.
3
Pretext and authority framing: The fraudster called Fries claiming her account was compromised, opening with an urgent, authoritative pretext delivered moments after a real bank interaction so it would read as a natural continuation of legitimate bank contact rather than a new, suspicious one.
Countering Stage 3: Training customers and staff that a bank will never call and then ask the customer to 'confirm' a security event over that same inbound call removes the pretext's credibility, especially when reinforced immediately after any real bank contact.
4
Real-time 2FA/OTP phishing: Using Wells Fargo's own customer-facing convention of texting a one-time code and asking the customer to read it back to 'verify identity,' the fraudster had Fries relay the code Wells Fargo's system had just generated, defeating two-factor authentication without any technical bypass.
Countering Stage 4: Eliminating 'read the code back to us' as a verification convention entirely, in favor of in-app push approval or a callback to a number independently sourced from a statement or card, closes the exact gap this case exploited, since the bank's own script was indistinguishable from the fraudster's.
5
Account takeover: With the harvested code, the fraudster changed Fries's online banking password and enrolled her account in a wire-transfer feature ('Wires Basic') that had not previously been active, actions typically possible once an attacker holds both a valid password reset path and a live 2FA code.
Countering Stage 5: Step-up verification or an automatic hold when a password change and a new high-risk feature enrollment (like wire transfer access) occur in the same short session, particularly following a customer-reported suspicious call, would catch account takeover before a transaction can be attempted.
6
Fraudulent transaction initiation: The fraudster initiated a $100,000 wire to a payee ('Savage Car Wash') in Miami, an amount double Wells Fargo's alleged standard $50,000 online wire limit, which under the bank's own stated procedure should have triggered a mandatory secondary review and a 24-48 hour hold.
Countering Stage 6: A hard, system-enforced transaction hold for any wire exceeding the bank's own stated threshold, one that cannot be overridden without a second, independent reviewer's sign-off, prevents a single representative's judgment call from bypassing the control.
7
Internal control bypass: Per the recorded call produced in discovery, a Wells Fargo wire-verification representative ('Mark') verbally identified the request as an unusual, flagged amount requiring second review, then approved and released it anyway during that same call, converting a documented human safeguard into the point of failure.
Countering Stage 7: Proactive, real-time or near-real-time supervisory audit of recorded high-value wire-verification calls, rather than only reviewing them after a customer complaint triggers litigation discovery, would have caught the override at the moment it happened instead of a year or more later.
8
Payout and detection evasion: The wire was sent to the Miami payee, and a separate Wells Fargo call-center representative reportedly told Fries the wire had been recalled and gave her a confirmation number, a false assurance that delayed her from pursuing other recovery options before Wells Fargo confirmed the next day that the funds were gone, completing the fraudster's objective.
Countering Stage 8: Wire-recall confirmations given to customers should be tied to a verified system status, not a representative's assurance alone, and institutions should maintain rapid-response fraud holds with correspondent and receiving banks so a recall attempt has a realistic chance of intercepting funds before they clear to the destination account.
Quick Facts
Victim
Alice Fries, Wells Fargo retail/premier banking customer
Location
Los Angeles, California, USA (victim/filing); fraudulent wire destination: Miami, Florida, USA (payee "Savage Car Wash")
Date
2022-10-24 (fraud occurred); lawsuit filed 2023-08-03 (LA Superior Court, case 23STCV18422) / removed to federal court C.D. Cal. as 2:23-cv-07321-SPG-PD (complaint dated 2023-11-22); reporting on the case surfaced in 2024
Impact
$100,000 fraudulent wire transfer alleged; Wells Fargo refunded only $50 as a "courtesy," leaving Alice Fries with an alleged net loss of $99,950 (all figures per the civil complaint; not independently adjudicated as of the last public record found)
Status
Confirmed
Case Type
Real-World Incident
Sector
Financial Services & Insurance
Related

Related Cases

SABRIC-Documented Vishing and SIM-Swap Fraud Surge Against South African Bank Customers (2023-2025)

SABRIC's own Annual Crime Statistics reports document a sustained, industry-wide surge in vishing- and SIM-swap-driven digital banking fraud across South…

Incident 2023Read →

Retool smishing + deepfake vishing breach (2023)

A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…

Incident 2023Read →

Optus/TPG Telecom OTP-Interception Mobile-Upgrade Vishing Fraud (Sydney, 2023-2024)

A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support, tricking 100+ Australians into…

Incident 2023Read →