A massive and unprecedented breach of payment card data has come to light, with sophisticated Chinese cybercriminal syndicates reportedly compromising up to 115 million payment cards in the United States between July 2023 and October 2024.
This historic attack, leveraging cutting-edge smishing tactics and digital wallet abuses, has inflicted financial damages estimated in the billions.
A New Era of Smishing: Beyond Basic Scams
Where the world once worried about amateurish “package delivery” text scams, the threat landscape has radically evolved. Since August 2023, investigators have monitored a meteoric rise in highly coordinated smishing campaigns, orchestrated by Chinese-speaking criminal groups.
Unlike prior waves of SMS phishing, these attackers employ a multi-layered approach: targeting victims through SMS, RCS, and even iMessage to lure them into revealing sensitive payment details.
What differentiates these attacks is the seamless integration of advanced phishing infrastructure with real-time multi-factor authentication (MFA) bypasses. Victims tricked into submitting security codes and card details inadvertently enable criminals to sidestep standard banking safeguards.
The most troubling technical leap centers on the exploitation of digital wallet systems, primarily Apple Pay and Google Wallet.
Traditionally, fraud detection relies on monitoring suspicious card transactions. The new tactic? Hackers use stolen credentials to “provision” cards onto new digital wallets, rapidly converting compromised details into legitimate-looking Apple or Google Pay accounts.
This tokenization effectively cloaks fraudulent activity, rendering many conventional detection techniques ineffective. Law enforcement officials and industry analysts now warn of a “new category” of financial crime—one that current frameworks are woefully ill-equipped to combat.
From Phishing Kits to Industrial-Scale Fraud
The criminal infrastructure uncovered during the nearly two-year investigation is vast and disturbingly organized.
Researchers identified modular phishing-as-a-service platforms, fake e-commerce portals, and even brokerage account takeover schemes, all orchestrated with the professionalism and efficiency of legal software firms.
The syndicates trade templates, infrastructure, and stolen data on dark web markets, operating with business-like scalability. With an estimated 12.7 million to 115 million accounts compromised, the breach impacts consumers of every central US bank and card issuer.
Security experts urge the public to be more vigilant than ever, closely monitoring SMS communications and digital wallet activity, as this “industrialization” of smishing marks a watershed moment in global payment fraud.
Regulatory bodies, meanwhile, are urgently reassessing their reliance on traditional fraud models, as tech-enabled criminals continue to exploit cracks in the rapidly digitizing financial ecosystem.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates