https://www.bbc.co.uk/programmes/articles/10GRvfdYcfzZWVV9g6x1qk/couple-s-life-savings-stolen-in-trojan-horse-mobile-app-scam * Homepage Accessibility links * Skip to content * Accessibility Help BBC Account Live Notifications * Home * News * Sport * Weather * iPlayer * Sounds * Bitesize * CBeebies * CBBC * Food * Home * News * Sport * Earth * Reel * Worklife * Travel * Culture * Future * TV * Weather * Sounds More menu Search BBC Search BBC * Home * News * Sport * Weather * iPlayer * Sounds * Bitesize * CBeebies * CBBC * Food * Home * News * Sport * Earth * Reel * Worklife * Travel * Culture * Future * TV * Weather * Sounds Close menu BBC One Rip Off Britain * Home * Episodes * Clips * Top Tips * Holiday Advice * The Cost Of Living * Send your story * Privacy Notice * Contact us Main content Couple's Life Savings Stolen In 'Trojan Horse' Mobile App Scam A retired nurse had her life savings stolen from her bank account while she slept, after inadvertently downloading a malicious mobile app. The malicious app was discovered by cyber experts for BBC's Rip Off Britain Liz Nolan, from Lancashire, only spotted the unfamiliar transactions totalling more than PS12,000 after being unable to withdraw cash, and noting her online bank accounts with Barclays and Revolut had been emptied. Barclays informed Liz her money had been moved to her Revolut account using her mobile phone, and her banking login details, at around 5am that morning. Her Revolut account showed numerous cryptocurrency transactions and a PS4,000 payment to an overseas account. 'It was like my whole world just dropped out of my legs,' Liz told Rip Off Britain. 'I was shaking and I was a mess.' Despite Liz's insistence that she'd been asleep when the payments were made, both banks concluded that Liz had authorised the transactions herself, from her own device, meaning she wouldn't be refunded. 'I just said to them, you know, why would I do this?' said Liz. 'That's my pension. I've worked 44 years as a nurse. Why would I do that?' Liz contacted Rip Off Britain for help, reporting that she hadn't received any suspicious emails or phone calls, though her mobile phone had started behaving strangely the week before the scam took place. Liz Nolan was told by her banks they wouldn't refund her because the transactions came from her phone She said it wouldn't switch off or let her view her notifications, or even do a factory reset. Then she later spotted a PDF reader app that she couldn't remember downloading and which couldn't be opened or uninstalled. 'tapjacking' With Liz's permission, Rip Off Britain sent her device to a cybersecurity firm for investigation. The report from Pen Test Partners revealed that the app in question would have appeared innocuous while in fact capturing everything Liz typed, including banking passwords and login details, which would have enabled scammers to log on to Liz's bank and move her money. It may have achieved this by 'tapjacking' - a technique of obscuring on-screen objects like security control pop-ups with an overlay designed to trick the user into tapping an unseen 'accept' button, thereby accepting options unintentionally. This enabled the app to view a list of Liz's other apps, override any attempts to deactivate it or turn off the phone and prevent notifications or security messages. The firm concluded that the app had not been installed via any app store, but had most likely been downloaded by Liz clicking on a pop-up link or something in a text message. Russia connection 'malicious in nature' Ken Munro, a cybersecurity expert from Pen Test Partners, said that as soon as Liz had unwittingly given the app additional permissions, it had 'got its hooks into the phone'. Cyber expert Ken Munro from Pen Test Partners revealed the malicious app had taken over Liz's phone without her knowledge and secretly drained her bank accounts 'At that point, it could start to grab her banking passwords as she typed them in,' he told Rip Off Britain. 'And then the hackers, with that amount of access, could start moving money - slowly but surely, while she was asleep.' Data extracted from the phone also revealed an IP address of a location in Russia, noted to be known as 'malicious in nature'. Pen Test Partners concluded 'with high confidence' that the malicious app was linked to or responsible for the fraudulent activity on the device. 'It just blew my mind that all that was happening,' said Liz after being presented with the findings. 'I knew that something was going on with my phone, but wasn't sure what. And then obviously when [the scam] happened, I couldn't speak to anybody without crying. It was the emotional aspect of it all.' After Rip Off Britain shared Pen Test Partners' report with Liz's banks, Revolut refunded her in full. Cybersecurity expert Adenike Cosgrove told Rip Off Britain: 'What we're starting to see is that these cyber criminals and fraudsters - they're not hacking in, they're actually logging in, often with the access that we inadvertently give them. 'It gives the criminal initial access to the device, then they're monitoring the device, all of the other applications, all of the banking services that you're leveraging, they're watching for all the passwords that you type in.' She advises that customers alert their bank if they notice any suspicious activity on their phone, so the bank can pay special attention to account activity. Cybersecurity expert Adenike Cosgrove says scammers aren't hacking in, they're logging in to our accounts because they already have our security details Adenike also highlighted the importance of only downloading applications from an official app store, and keeping mobile devices updated with latest software updates. A spokesperson for Revolut said: 'We are very sorry to hear about Ms Nolan's case, or any instance where our customers are targeted by ruthless and highly sophisticated criminals. 'On further investigation of the customer's case and with new insights provided by cybersecurity experts, it is apparent that a malicious banking trojan application was used by criminals to compromise Ms Nolan's device to facilitate account takeover fraud. 'In recognition of this new information, Revolut has reimbursed Ms Nolan for the total funds lost. We have also issued a goodwill payment of PS500 in recognition of the distress she has experienced in this case. 'Revolut works hard and invests heavily to protect and support customers. We are continuously developing new and innovative ways to detect malware and compromised devices, using sophisticated internal tools, 3rd party tools and machine learning. A spokesperson for Barclays said: 'Our highest priority is the protection of our customers' funds and data. We have every sympathy with our customer, who has reported being a victim of a sophisticated fraud. 'Our investigation shows that funds were transferred from our customer's Barclays account to their Revolut account. 'We cannot comment on the status of the funds after they were transferred into our customer's Revolut account as this is not information we have access to. We advised the customer to reach out to Revolut to understand the status of the funds.' Rip Off Britain wants to hear from others who may have had similar experiences. You can email the programme at ripoffbritain@bbc.co.uk Watch Rip Off Britain's report on Tuesday 2 January 2024 at 10:45am, BBC One, or on BBC iPlayer. Related Content Similar programmes By genre: * Factual > Consumer BBC One homepage * Home * Schedule * TV Guide Explore the BBC * Home * News * Sport * Weather * iPlayer * Sounds * Bitesize * CBeebies * CBBC * Food * Home * News * Sport * Earth * Reel * Worklife * Travel * Culture * Future * TV * Weather * Sounds * Terms of Use * About the BBC * Privacy Policy * Privacy Policy * Cookies * Cookies * Accessibility Help * Parental Guidance * Contact the BBC * Make an editorial complaint * BBC emails for you * Advertise with us Copyright (c) 2024 BBC. The BBC is not responsible for the content of external sites. Read about our approach to external linking. [p]