Staying Ahead of the Cybersecurity Curve

May 13, 2025

Fraudsters running online financial scams keep evolving their tactics. Staying safe online presents a high difficulty, especially for those who did not grow up using computers as children.


In times of market volatility, many bad actors capitalize on consumers' high emotions and steal their data.


Let's review some general cybersecurity best practices for individuals and discuss a scam targeting Charles Schwab users.


A Current "Smishing" Campaign to Watch Out For

The newer Schwab "Smishing" scam begins when the client receives a text message prompting them to "verify a transaction."


Clicking the link leads the unwary investor to a fraudulent website that mimics Schwab's login page. There, they are prompted to enter their credentials, which the fraudsters use to access schwaballiance.com.


The fraudulent website may also prompt the client to enter a two-factor verification code that they would automatically receive from Schwab. Once submitted, this code allows the fraudster to complete the login process.


Once they have access, the fraudster will change the security token on the account to point to a device in the criminals' hands instead of the client's device. At this point, the client is effectively locked out of the account, and the fraudster can begin initiating wire transfers that rapidly drain assets from the account. 

Why This is Timely

This string of online scams and cyberattacks is not an isolated event. 


Fraudsters are growing, and the global cost of cybercrime has increased exponentially over the last few years. When many of us think of a digital scammer, we still may think of a lonely, 40-something-year-old man tucked away in his mother's basement.


The reality is that cybercriminals are running large-scale, highly efficient operations with hundreds of members/employees. In fact, cybercrime intersects with international law, global politics, technological advancements, and even human trafficking.


Actions To Take If You Think You Are The Victim Of A Scam

If you suspect a bad actor targeted you, here are some steps you can take.


The most crucial step is to remain calm and vigilant. While being a potential victim can be scary, remember there is no need to be embarrassed.


Fraudsters want victims to stay quiet and be embarrassed rather than speak out and get help.


  • For the Schwab "smishing" scam, take a screenshot of the text and forward it to phishing@schwab.com. (Make sure the phone number is visible.)
  • Delete the text message.
  • If you clicked on the link, you should stop logging into your online accounts, immediately run an anti-virus/malware scan, and remove anything identified in that scan. Next, verify that the operating system on your device is updated, and then change all relevant passwords. 
  • To help protect against these attacks, add security measures to your financial accounts, such as two-factor authentication and verbal passwords. 
  • Be sure you report any suspicious or fraudulent activity in your accounts as soon as possible.


General Cybersecurity Reminders

Check out these reminders from Charles Schwab. These points are also good benchmarks for assessing other personal information online.


  • Do not click on links or attachments received via text message. 
  • Instead, manually enter the official Schwab site by typing the URL into your web browser. 
  • Or utilize Schwab's mobile application.
  • Do not enter Schwab credentials or other information into a page reached by clicking a link. The same applies to phone numbers received via text message. Use a verified number you've used in the past.
  • Double-check that the URL provided is not a subtle variation of the real one.
  • Stay calm and verify using official verified channels.


We recommend that our clients familiarize themselves with the Fraud Prevention section of Schwab's Cybersecurity Resource Center. Staying informed and educated is the best defense against phishing schemes and other scams. 

Connect With Clayton Financial Group

At Clayton Financial Group, we help clients achieve their life plans and take their growth and security seriously. We are an independent boutique advisory firm with national coverage and decades of industry experience.


Contact us today if you need help with investment, tax, risk management, estate, or other planning. 

April 17, 2025
Let's discuss eight life changes and events that should prompt adults to schedule a financial check-in.
April 4, 2025
At the beginning of April, the Trump administration announced their strategy to impose tariffs on US trading partners worldwide.
March 12, 2025
Retirement isn't just about leaving work—it's about entering a new phase of life that should be both financially secure and personally fulfilling.
More Posts