Barclays has issued a fresh warning about a sophisticated mobile malware scam that could compromise users' banking details. The bank says criminals are increasingly using malicious software to spy on devices, control them remotely, and steal sensitive information, including login credentials for banking apps.
How the scam works
Mobile malware is harmful software designed to infiltrate smartphones and tablets. Once installed, it can monitor user activity, alter device settings, and access other applications, including banking apps. Barclays explains that fraudsters often sneak malware onto devices by creating seemingly legitimate apps, such as PDF readers or file managers, and placing them on genuine app stores.
After installation, these apps operate normally for weeks or even months. However, when a fake update is offered, it contains malware that installs itself silently without the user's knowledge. These harmful apps frequently request access to the device's accessibility services, which, if granted, gives fraudsters full control over the phone.
Fake login screens steal credentials
With accessibility permissions enabled, criminals can program the device to open a fake login screen whenever the user selects their banking app. This fraudulent page captures the user's login information, which is then sent directly to the scammers. Barclays warns that this level of access can also allow malware to intercept two-factor authentication codes, making it even harder for victims to detect the breach.
According to Barclays, the scam is particularly dangerous because it exploits users' trust in official app stores and routine update prompts. The bank notes that scammers are constantly adapting their methods, making it essential for customers to stay vigilant.
Protection advice from Barclays
To safeguard against this threat, Barclays advises customers to be suspicious if an app requests accessibility permissions without a clear need. The bank also recommends installing the latest security updates for devices and using two-factor authentication for important apps to add an extra layer of security.
"Be suspicious if an app asks for accessibility permissions. Always install the latest security updates for your device," a Barclays spokesperson said. "If a text or email has a link to an app you don't recognise, don't download it. Use two-factor authentication to keep important apps safe."
The bank further advises installing anti-virus software on all devices and researching options before choosing one. If a device begins acting strangely—such as freezing or restarting unexpectedly—Barclays urges customers to check their bank accounts immediately and follow guidance on gov.uk for recovering an infected device.
Additional safety measures
Barclays also highlights the importance of verifying unexpected calls. "If you receive an unexpected call and you're not sure it's from us, end the call. Then call us back from a different phone, or call a friend to make sure the scammers aren't still on the line," the bank added.
Customers are encouraged to remain cautious about unsolicited messages containing app links and to avoid downloading apps from unverified sources. The bank emphasises that scammers are quick to adapt, so ongoing awareness is critical.
This warning comes as part of broader efforts to combat financial fraud in the UK, where mobile malware attacks have become increasingly prevalent. By following these precautions, users can significantly reduce their risk of falling victim to such scams.



