A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from customer Alice Fries, and a Wells Fargo representative then knowingly overrode the bank's own $50,000 wire-review threshold to release a $100,000 fraudulent wire, per a Los Angeles lawsuit built partly on the bank's own recorded verification call.
Reviewed by the Social Engineering Examples team.
On October 24, 2022, Wells Fargo customer Alice Fries had a legitimate call with a Wells Fargo premier banker at 1:10 p.m. Nine minutes later, at 1:23 p.m., she received a call whose caller ID spoofed Wells Fargo's genuine 800 number. The caller, impersonating the bank, claimed her account was compromised, sent her a two-factor authentication code, and asked her to read it back, which she did. Using that code, the fraudster changed her online banking password, enrolled her account in a wire-transfer feature ("Wires Basic"), and initiated a $100,000 wire to a payee named "Savage Car Wash" in Miami, Florida, double the bank's alleged standard $50,000 online-wire limit. While still on the phone with the scammer over an hour later, Fries went to a Wells Fargo branch, where an employee said it sounded like a scam and that the wire was in process; a call-center rep told her the wire had been recalled and gave her a confirmation number, but the wire was never actually stopped and the money was sent. Wells Fargo refunded only $50 as a courtesy. Fries sued in Los Angeles (LA Superior Court case 23STCV18422, filed Aug. 3, 2023; related federal complaint C.D. Cal. 2:23-cv-07321-SPG-PD, dated Nov. 22, 2023), and discovery reportedly produced a recorded call in which a Wells Fargo wire-verification representative ("Mark") told the fraudster the amount was "unusual," had been "flagged," and required a "second review," then approved and released the wire anyway. Wells Fargo's online banking agreement contains a standard arbitration clause, and Wells Fargo has compelled arbitration in numerous other consumer disputes, but no public record was located confirming whether a motion to compel arbitration was actually filed in this specific case, and no final publicly confirmed merits outcome or settlement was located as of the last available report (April 2024 coverage).
Per the complaint: at 1:10 p.m. on Oct 24, 2022, Fries had a legitimate call with her Wells Fargo premier banker/advisor and declined proposed investments. At 1:23 p.m., nine minutes later, she received an inbound call whose caller ID displayed the same Wells Fargo 800 number she normally saw, a spoofed call from a fraudster impersonating the bank. The caller claimed her account was compromised and, using Wells Fargo's own customer-facing verification convention, sent her a two-factor authentication code and asked her to read it back to "verify her identity." Fries complied, believing it consistent with the bank's normal process (and primed by having just spoken to a real Wells Fargo employee minutes earlier). Using the harvested 2FA code, the fraudster allegedly changed her online banking password, enrolled her account in a "Wires Basic" wire-transfer feature, and initiated a $100,000 wire to a payee called "Savage Car Wash" in Miami, Florida, an amount double Wells Fargo's alleged standard $50,000 online wire limit. While still on the phone with the fraudster (over an hour into the call), Fries grew suspicious and walked into a Wells Fargo branch, where employee "Walter" told her it sounded like a scam and that a fraudulent $100,000 wire was already in process. She then called the Wells Fargo call center; a rep ("Chavi") told her the wire had been recalled and gave her a confirmation number. The next day she learned the wire had NOT been recalled: the $100,000 had gone to Savage Car Wash. Discovery later produced a recorded call between a Wells Fargo employee ("Mark," on a wire-verification line) and the fraudster, in which Mark stated the $100,000 request was "an unusual amount of money," that it had "been flagged," that transfers over $50,000 require a "second review," and that a 24-48 hour delay could apply, then said "no worries, I'm going to release this wire transfer transaction and transfer it today," and approved it anyway.
The lure: an inbound call arriving just 9 minutes after a real Wells Fargo advisor call, displaying the bank's genuine, familiar 800 number on caller ID, from someone who already knew enough context to sound legitimate and who used the bank's own "read back your verification code" convention, the same convention Fries said Wells Fargo itself normally used with her. The tell (in hindsight, and flagged instantly by a human once involved): the request to read back a 2FA/OTP code over an inbound call is never legitimate no matter what the caller ID shows, since real banks generate the code for outbound-initiated verification, not to be "confirmed" to an inbound caller; additionally, a wire request that exceeds a bank's own stated review threshold, arriving on the heels of a suspicious 2FA event, is a textbook fraud pattern that the bank's own employee ("Mark") explicitly recognized and verbalized ("unusual amount," "flagged," "second review" required) before overriding it anyway, meaning the institutional tell existed and was verbally acknowledged, but not acted upon.
Fries was refunded only $50 by Wells Fargo as a "courtesy," leaving an alleged $99,950 net loss; she filed suit (LA Superior Court case 23STCV18422, filed Aug 3, 2023; also captioned in removed/related federal filing C.D. Cal. 2:23-cv-07321-SPG-PD, complaint dated Nov 22, 2023) alleging state-law claims including UCC/Commercial Code security-procedure violations and intentional infliction of emotional distress. No public record was located confirming how the case proceeded procedurally after the November 2023 federal complaint, whether it was compelled to arbitration under Wells Fargo's standard online-banking arbitration clause, settled, or otherwise resolved, and no final merits judgment or settlement amount was found. Status should be treated as case history through the late-2023/early-2024 complaint and reporting stage, not a final verdict.
This case is unusually well-documented because litigation discovery produced the bank's own internal recorded verification call, giving rare, verbatim evidence of a real-time human control (the $50,000 wire threshold / second-review requirement) being correctly identified and then knowingly overridden by bank staff, not merely a technology or process gap, but a documented human decision to bypass a known safeguard. It also illustrates a structural weakness common across bank-impersonation vishing: banks that ask customers to "read back a code we just sent you" as routine identity verification are using the identical script a scammer needs, so customers cannot distinguish a legitimate verification call from a spoofed one by process alone. The suspicious 9-minute gap between a real advisor call and the fraudulent call also raises (unproven) concerns about possible information leakage enabling more convincing, better-timed social engineering.
Documented failure modes exposed by this case: (1) banks that use "read back the code we texted you" as an identity-verification ritual train customers to comply with exactly the request a vishing scammer will make; (2) caller ID is not authentication: spoofing a bank's real published 800 number is trivial and customers have no way to distinguish it from a real call; (3) dollar-threshold controls (Wells Fargo's alleged $50,000 online-wire limit requiring "second review" and a 24-48 hour delay) are only as strong as the human enforcing them: the complaint alleges the rep verbally acknowledged the threshold, the flag, and the review requirement, then overrode all three; (4) a recorded-line policy for high-value wire verification is a good control ONLY if supervisors audit the recordings in real time or near-real time, not just after a customer complaint triggers discovery; (5) post-incident whistleblowing to a branch employee ("Walter") who could see the wire in process shows some fraud-detection worked, but the recall/reversal process failed or was misrepresented to the customer, and the "refund only if you admit you authorized it" posture is a recurring complaint-pattern in bank-impersonation vishing suits. Recommended practices for consumers/institutions: banks should never ask customers to read back a one-time code over the phone as a verification step; customers should independently call back a number from a statement/card rather than trust an inbound caller-ID match, especially within minutes of another bank call; institutions should treat wire-limit overrides as requiring documented supervisory sign-off, not a single rep's discretion; recorded verification calls should be sampled/audited proactively, not just pulled in discovery.
SABRIC's own Annual Crime Statistics reports document a sustained, industry-wide surge in vishing- and SIM-swap-driven digital banking fraud across South…
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…
A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support, tricking 100+ Australians into…