Barclays has issued a warning to UK customers about a new scam involving malware that infiltrates personal devices to steal sensitive information and money. The alert, published on the bank's website, highlights the growing threat of mobile malware—harmful software designed by criminals to spy on, control, and attack smartphones, tablets, and smartwatches.
Once installed, the malware can steal personal data, alter device settings, and access apps, including banking applications. Barclays explained that criminals often disguise the malware as legitimate-looking apps, such as PDF readers or file managers, which are available on official app stores. These apps function normally for weeks or months before prompting an update that contains the malware, which installs itself without the user's knowledge.
The bank warned that harmful apps frequently request access to a device's accessibility services, granting them full control. With this access, scammers can set devices to open a fake login screen when the user selects their banking app, thereby stealing login credentials.
To help customers protect themselves, Barclays shared five tips: monitor devices for unusual behaviour like random freezing or restarting; check bank accounts if suspicious activity is detected; contact the bank immediately if details are compromised or money lost; change leaked passwords without delay; and report scams to Action Fraud (0300 123 2040) or, in Scotland, Advice Direct Scotland (0808 164 6000).
Customers are also advised to forward scam emails to report@phishing.gov.uk and scam texts to 7726 for free. If a scammer calls, hang up and search for the organisation's official contact details online, never calling back the number provided.