Skip to content
DnsLister Forum

Where domain hunters compare notes

M&T Bank fraud “phantom hacker” scam victim locked out of online banking for 2-3 months. Branch and fraud dept won’t give timeline or any answer on restoring access

My client (I'm his IT support) has been through a bad time with phishing scams. I don't know quite how to describe him because what he's done, over and over, makes him sound stupid, but he isn't. He may just be extra meek, gullible and ignorant. He has had several incidents over the years where he gets his scammed into using his debit cards for the fake $600 "Microsoft" virus fix type of thing. The bank has reissued cards many times over the years.

During the incident a few months ago his debit cards were compromised, canceled, and reissued and he was denied access to his online account access. Then a second scam hit where he was manipulated into sending thousands of dollars in gift cards in what I'd call a "phantom hacker" scam- convincing him he needs to move money out of his accounts because a scammer has access to them. They conned him into sending in the range of $6000 – $10000 with gift cards so the scammer can put it somewhere "safe" for him.

After that second incident, M&T Bank canceled his 2 debit cards and a M&T credit card again, and sent replacement cards. I went into the bank with him and we spoke to the Banker who was subbing for a Manager on vacation. My client stated that he never gave anyone access to his bank account numbers and she said they probably didn't need to close the accounts, but the next day they reversed course and did just that. That day they opened two new accounts and transferred his balances.

He has since received his new debit cards and his replacement credit card is working. But he has had zero online banking access for roughly 2-3 months (on the old and now new accounts) and counting.

The day we visited the branch, I completely wiped and reloaded his PC. I installed a full Enterprise-grade security suite with Atera RMM, and ThreatDown EDR, Application Blocking, DNS Filtering, Firewall Control and Managed Threat Detection and Response (ThreatDown personnel actually shut down real-time attacks). I sent an email attesting to this to the Banker we spoke with. She forwarded it to the Fraud Dept. This was 9/9/26, almost 2 weeks ago.

The branch manager told him it's up to the fraud department to restore access, but the fraud department won't give him a date, won't give him a timeline, and won't even tell him if online access will ever be restored. They're just leaving him in limbo.

Questions:

  • Has anyone dealt with M&T Bank's fraud department in a situation like this? How long did it take?
  • Does the bank actually have the right to deny online access indefinitely without explanation?
  • Is a CFPB complaint the right move here, or is there a better escalation path?

He is too nice a guy to get angry with them, but I'm getting angry with them on his behalf!

Source: r/personalfinance · by /u/rickncn

Leave a Reply

Your email address will not be published. Required fields are marked *