A new Android malware attack used a fake bank call to steal card data and take out a loan. Here’s how to spot the warning signs and protect yourself today.
Table of Contents
What Happened in the Android Malware Attack?
The attack began with a fraudster posing as a bank employee during a phone call. The caller claimed there was a problem with the victim’s payment card.
The victim was persuaded to install SpyNote, a harmful app that gave the attacker remote control of the Android phone.
The attacker then installed WindRelay and used the victim’s banking app to take out a loan in their name.
The caller also persuaded the victim to tap a payment card against the phone and provide the PIN. WindRelay then helped relay the card data for fraudulent purchases.
According to Group-IB, the entire attack happened during a 13-minute call. BleepingComputer reported the findings on August 12, 2026.
This case involved malware rather than a data breach. However, criminals can also use details from earlier breaches to make fake bank calls more believable.
Many people do not know their information has appeared in a breach until suspicious activity starts.
If you are unsure whether your information was leaked somewhere online, automatic monitoring can help you spot problems earlier. Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.
Who Was Targeted and What Information Was Stolen?
Group-IB did not say how many people were affected.
Researchers found almost two dozen WindRelay samples submitted to VirusTotal between November 2025 and July 2026.
Based on the languages and organizations impersonated, the attacks appear focused on Czechia, Slovakia, and Slovenia.
In the investigated attack, criminals gained remote access to the victim’s Android phone and banking app. They also relayed payment card information through NFC.
NFC, or near-field communication, is the technology that lets a card communicate with a phone or contactless payment terminal.
The victim also provided the card PIN during the call. The attacker then used the card information for purchases at a real payment terminal.
SpyNote can steal other information, including login details, authentication codes, text messages, and keystrokes. However, Group-IB did not confirm all these were stolen here.
How the Fake Bank Call Turned an Android Phone Into a Card Reader
The attack relied heavily on social engineering, meaning the criminal persuaded the victim to take actions that gave them access.
First, the fraudster called while pretending to work for the victim’s bank.
The victim was told to sideload SpyNote. Sideloading means installing an Android app from outside the official Google Play store.
The app was even personalized with the victim’s name, which helped make it look legitimate.
Next, the victim granted the app Accessibility Service permissions. These Android permissions can give an app powerful control over what happens on the phone.
Once SpyNote had remote access, the attacker installed WindRelay without needing more help from the victim.
The caller then asked the victim to place a payment card against the phone.
WindRelay captured the live NFC communication and sent it to the attacker’s device over the internet.
That allowed the attacker to use the card information at a genuine contactless payment terminal.
Futureproof keeps your data safer with simple guidance to set a strong password, turn on 2-step verification, and lock down your account.
Check my safetyWhy a Bank Call Can Be More Dangerous Than It Looks
The biggest lesson is that criminals do not always need to break through your phone’s security themselves.
They may simply persuade you to install an app, approve powerful permissions, or share information during a convincing phone call.
A caller may also know your name or other personal details. That alone does not prove they work for your bank.
Urgency is another warning sign. If someone says you must act immediately, ending the call gives you time to verify the situation yourself.
You can then contact your bank using the number printed on your card or listed on its official website.

At Futureproof, Kevin explains digital safety in simple words, with clear tips and zero fluff. He holds a degree in information technology and studies fraud trends to keep his tips up-to-date.
In his free time, Kevin plays with his cat, enjoys board-game nights, and hunts for New York’s best cinnamon rolls.
