Introduction

A recent article published by CBC news highlighted a concerning scam that involved the Bank of Montreal (BMO). The scam managed to exploit vulnerabilities associated with the two-factor authentication (2FA) system of the bank. This advisory aims to provide an overview of the issue, its implications, and recommendations.

Summary of the incident

The scam primarily targeted customers with lines of credit. Perpetrators pose as bank employees and use a combination of phishing techniques and flaws in the 2FA process to gain unauthorized access to customers’ accounts, subsequently making unauthorized transactions.

Implications

  1. The trustworthiness of 2FA is at stake. Customers generally perceive 2FA as a robust security measure, but this incident underscores potential vulnerabilities.
  2. The scam demonstrates that even with the second layer of authentication, user accounts can be compromised if the process isn’t foolproof.
  3. Potential loss of customer trust in banking institutions due to such vulnerabilities.

Recommendations

  1. Stay Informed: Regularly update oneself about the latest scams and phishing techniques. Always be skeptical of unsolicited calls or emails asking for personal or banking information.
  2. Use Advanced Security Features: Wherever possible, use advanced security features like biometric authentication or hardware-based security keys.
  3. Monitor Accounts: Regularly check bank accounts for unauthorized transactions and report any discrepancies immediately.
  4. Stay Educated: Participate in security awareness sessions provided by your Richter Guardian team, the bank or other trusted organizations.

While 2FA is an essential security feature, it is not infallible. Richter Guardian clients should be proactive in understanding its limitations and continuously seek ways to enhance their security posture.

Contact us at anytime you are unsure. If you receive a call from someone purporting to be your bank and you are unsure, call us to help you determine the legitimacy of their communication.

Table 1 – Levels of two-factor authentication that may be available to protect your bank account.  

Type of 2FA Method Description Level of Strength of Security
SMS-Based 2FA Sends a one-time code to the user’s registered mobile number, which they then input to authenticate. Moderate – Vulnerable to SIM swapping attacks and interception.
Push Notification
(e.g., through an app)
Sends a notification to the user’s registered device, prompting them to approve or deny the login request. High – More secure than SMS-based, but can still be vulnerable if the device is compromised.
Token-based Authenticator
(e.g., Google Authenticator, Authy)
Uses a time-based one-time password (TOTP) generated by an app. The user enters the code displayed on the app. High – Not vulnerable to SIM swapping; however, a device compromise could pose risks.
Hardware Tokens
(e.g., YubiKey, RSA SecurID)
Physical device that generates or holds digital authentication data. Some require a button press to display a code, while others transmit the code when plugged into a device. Very High – Not susceptible to most common cyber-attacks. Loss or theft of the device is the primary concern.
Biometric 2FA Uses the user’s unique physical or behavioral characteristics, such as fingerprint, face recognition, or voice pattern. High – Difficult to replicate but isn’t immune to all attacks (e.g., high-quality replicas or recordings). Also, concerns about data privacy persist.
Email-Based 2FA Sends a one-time code or link to the user’s registered email address, which they then use to authenticate. Moderate – Security depends on the strength and security of the user’s email account. Vulnerable to email hacking.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Security advisories
Subscribe to newsletter

Subscribe to receive our latest news and insights in your inbox each week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

FAQs

What is a two-factor authentication scam?

A two-factor authentication scam happens when a criminal tries to trick someone into sharing a one-time code, approving a login request, or giving access to an account.

What is two-factor vs. multi-factor authentication?

Both add an extra layer of security beyond your password, so that even if someone learns your password, they still can't get into your account.

Two-factor authentication (2FA) asks for exactly two proofs of identity: usually your password plus one more step, like a code sent to your phone.

Multi-factor authentication (MFA) asks for two or more. So 2FA is really just one type of MFA.

In practice, the difference matters less than the habit itself: turning on this extra step wherever it's offered is one of the simplest, most effective ways to protect your accounts. If you're not sure how to set it up, the Cyber Defence Desk can walk you through it.

How do bank impersonation scams work?

In a bank impersonation scam, the attacker pretends to be from a trusted financial institution. They may use urgency, fear, or partial personal information to convince someone to share codes, credentials, or account details.

Why are authenticator apps safer than SMS codes?

Authenticator apps are generally safer than SMS because they do not rely on text messages, which can be exposed through SIM swapping, phone compromise, or social engineering.

What should I do if I receive a suspicious message from my bank?

Do not click links, share codes, or reply with personal information. Contact the bank through its official website, app, or phone number, and ask for guidance before taking action.

Can scammers bypass two-factor authentication?

Scammers may bypass two-factor authentication by tricking someone into approving a request or sharing a code. That is why it is important to verify messages and avoid acting under pressure.

How can high-net-worth individuals reduce scam risk?

High-net-worth individuals can reduce scam risk by using unique passwords, enabling multi-factor authentication, limiting public information, reviewing social media exposure, and getting guidance before responding to suspicious messages.

Protect your digital life by detecting risks before they escalate

Richter Guardian gives you enterprise-level cybersecurity tailored for individuals, families, and executives.

24/7 monitoring & threat intelligence
Identity theft & impersonation detection
Fast incident recovery & expert guidance
Have questions after reading?
Blog

Related posts

Article illustration: Authenticator Apps vs SMS for Login Security

Why Authenticator Apps Are Safer Than SMS for Login Security

Authenticator apps are more secure than SMS for two-factor authentication. We compare both methods, explain SIM swapping and interception risks, and recommend using an authenticator app for important accounts.

Introduction

One of the best ways to add extra security to your accounts is through Multi-Factor Authentication (MFA) – this means you need more than just a user ID and password to log in. We strongly recommend using MFA for your important accounts.

However, not all MFA methods are equally secure. Authenticator apps are a safer option than SMS authentication methods because they generate security codes directly on your device. SMS authentication codes, on the other hand, can be intercepted by hackers.

What is Multi-Factor Authentication and what is the benefit?

MFA adds an extra step to logging in. Instead of just entering a user ID and password, you must also provide another piece of information, like a code from an app or a text message. This extra step makes it much harder for hackers to break into your account, even if they steal your password.

MFA method #1: What is an authenticator application?

An authenticator app is a mobile app that generates security codes for logging in. These codes are called Time-Based One-Time Passwords (TOTP) and change every 30 to 60 seconds.

When you set up an authenticator app for an account, you scan a QR code or enter a secret key. This links the authenticator app to your account and allows it to generate matching codes.

To log in, you enter your username, password, and the current code displayed on your authenticator app. If the code matches the one your account server expects, you get access.

Some popular authenticator applications include:  

  • Google Authenticator
  • Microsoft Authenticator
  • Authy
  • Duo Mobile

MFA method #2: What is SMS authentication?

SMS authentication is when a security code is sent to your phone via text message. You enter this code along with your user ID and password to log in. These codes are One-Time Passwords (OTP) which are generated for one-time use. OTPs can last for a specified amount of time – users will need to generate a new OTP if they exceed the time limit.  

Sometimes, websites may also send security codes via email instead of SMS, but the process is the same.

Why authenticator applications are preferred over SMS authentication

Authenticator apps provide better security than SMS codes for several reasons:

  • Less chance of being hacked: Authenticator apps generate codes directly on your device, while SMS codes are sent over the internet and can be stolen.
  • No risk of SIM swapping: Hackers can trick your phone provider into transferring your number to a new SIM card, allowing them to receive your SMS codes.
  • No risk of interception: SMS codes can be stolen using man-in-the-middle attacks, where hackers eavesdrop on internet traffic.
  • Codes change frequently: Authenticator apps refresh their codes every 30 to 60 seconds, making them harder to steal and use.

How hackers can steal SMS codes

Here are two common ways cybercriminals can steal SMS codes:

  • Man-in-the-Middle Attacks – Hackers intercept your internet traffic when you connect to an unprotected Wi-Fi network (like public Wi-Fi at a coffee shop). This can let them steal SMS codes.
  • SIM Swapping – A hacker contacts your mobile provider pretending to be you and tricks them into activating a new SIM card with your phone number. Now, they receive all your text messages, including your security codes.

How to keep your accounts safe

  • Use an authenticator app instead of SMS authentication whenever possible.
  • Protect your phone with a strong PIN or password.
  • Avoid using public Wi-Fi when entering security codes.
  • Never share your security codes with anyone.
  • Be cautious of phishing scams that try to trick you into revealing your codes.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Article illustration: PetSmart Credential Stuffing Attack

PetSmart Warns Customers of Credential Stuffing Attack

PetSmart warned of a credential stuffing attack and reset some passwords. We explain what credential stuffing is and how to protect yourself with unique passwords, MFA, and dark web monitoring.

Introduction​

​PetSmart, a pet retail giant in the United States, is alerting certain customers about password resets resulting from an ongoing credential stuffing attack attempting to breach existing accounts. The company released a statement on March 6 to let customers know about the credential stuffing attack. ​

As a precaution, PetSmart reset the passwords for any accounts logged in during the credential stuffing attack. Additionally, they reassured customers that there was no evidence of compromise to petsmart.com or any of their systems during the incident.​

What is credential stuffing?

​A credential stuffing attack is a type of cyber-attack in which threat actors use previously acquired usernames and passwords, typically obtained from data breaches, to gain unauthorized access to user accounts on various online platforms. ​

Threat actors usually automate the process of trying these login credentials across multiple websites and services. Threat actors are cognizant of the fact that people commonly reuse passwords across various accounts, making them even more inclined to exploit this widespread behavior.

How to protect yourself against credential stuffing attacks

Although cyber breaches may be unavoidable, you can still prevent breached details from being used on other websites or services by taking the following precautions:

  1. Use Unique Passwords For Each Account – Minimize the impact if one account is compromised.​
  2. Enable Multi-Factor Authentication (MFA) – Implement MFA wherever possible to add an additional layer of security.​
  3. Update Outdated Passwords – Change your passwords periodically, especially for critical accounts like email, banking, and social media.​
  4. Limit Access – Only use trusted devices and networks to access sensitive accounts. Avoid logging in from public computers or unsecured Wi-Fi networks to access sensitive accounts. Ensure that you are not saving your credentials on a public computer.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Sailing on vacation with father and son

A $4.5-Million Account Raid: What Every Investor Should Learn About Protecting Their Wealth While on Vacation

A Calgary investor is suing TD Waterhouse Canada Inc. after fraudsters allegedly broke into his TD Direct Investing accounts while he vacationed in Hawaii. Nothing has been proven in court, but the case shows how fast wealth can vanish once login credentials fall into the wrong hands.

What happened

A Calgary investor is suing TD Waterhouse Canada Inc. after fraudsters allegedly broke into his TD Direct Investing accounts while he vacationed in Hawaii.

According to The Globe and Mail, the intruders sold his holdings and poured more than $5 million into a thinly traded Hong Kong stock.

When it collapsed, he lost roughly $4.5 million in retirement savings.

TD says he either made the trades himself or failed to secure his account. Nothing has been proven in court, but the case shows how fast wealth can vanish once login credentials fall into the wrong hands.

Why this keeps happening

This isn't an isolated incident.

TD Bank has faced other serious regulatory scrutiny in recent years, and securities fraud attorneys continue to field claims from investors who say controls failed them.

Banks guard their own core systems closely, but the real weak points are often somewhere else: the client's personal devices, account passwords, and email accounts, all sitting outside the bank's  oversight and controls.

Why travel makes you a target

It's worth pausing on the timing here: the alleged fraud happened while the investor was away in Hawaii. That's not a coincidence worth overlooking.

Vacations pull people out of their normal routines on purpose, and that's exactly what makes them good for rest, and terrible for security.

At home, most people have habits without even thinking about them: checking accounts over morning coffee, noticing a strange email between meetings, recognizing when something on a statement looks off.

Travel disrupts every one of those habits at once:

- You're on hotel or airport Wi-Fi, which is rarely as secure as your home network.
- You're checking email and banking apps quickly, often on borrowed time between activities, so a suspicious login alert can get skimmed past instead of read carefully.
- Time zone changes mean notifications may arrive at 3 am and get dismissed unread.

Many people intentionally "unplug" from their finances while traveling, treating vacation as a break from monitoring entirely.

Fraudsters understand this pattern well. Account takeovers cluster around known absences: holidays, long trips and/or business travel.

A window of even a few days without anyone watching an account closely is often all it takes to sell off holdings and move funds into a single volatile position, which is exactly what allegedly happened in this case.

None of this means people shouldn't travel or unplug — they should. It means the monitoring can't rely on the account owner remembering to check in from a beach in Hawaii.

Steps you can take right now

Basic habits, especially before and during travel, meaningfully reduce your own risk:

- Turn on multi-factor authentication for every brokerage, banking, and email account.
- Use a unique, strong password for each financial account — never reuse them.
- Avoid logging into financial accounts on public or hotel Wi-Fi while traveling.
- Set up account alerts for trades, withdrawals, and login attempts before you leave.
- Designate someone you trust to glance at statements while you're away.
- Review account activity closely in the days right after returning.
- Ask your brokerage about limiting or freezing margin trading if you rarely use it.

Where personal habits aren't enough

Even careful people get targeted, especially the moment they step away from their routine.

This is a gap Richter Guardian is built to close.

Corporate and bank-side security stops at the workplace door — it doesn't watch the personal phone, laptop, or email account a fraudster actually needs.

Richter Guardian's monitoring and prevention service watches continuously, including while clients travel, for compromised credentials and suspicious activity. If something looks wrong, clients aren't left to figure it out alone.

Our incident response team, the Cyber Defence Desk, is reachable via phone, email, video or a mobile app to explain what's happening and guide next steps.

The bottom line

Vacations should mean rest, not vigilance. For high-net-worth individuals and families with complex accounts and multiple devices, someone still needs to be watching while you're not. Protection shouldn't stop where your routine does.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.