MetaTrader 5 Used for Phishing / Account takeover attempts

 

I got contacted via WhatsApp with a "misdialed number"... off by 1 number and got into chat with a woman from Hong Kong. We talked for almost a week, mostly about trades and how much money she was making in foreign exchange gold trades. She wanted to show me how to do it. So she asked me to download MetaTrader to my phone and show her screen shot of the settings page. As it was too quick, the demo account hadn't been registered yet and said so on the screen shot. She asked for me to click the menu and I noticed that the account number is on that page as well. I took a screen shot, but blacked out the number before sending it. She was not happy. She'd spent over a week with me setting up this phishing and I caught on.

Lesson learned:1) Attractive women who randomly contact you... in dreams only. 2) Offers to help configure and teach you this software expose your account number to them for subsequent takeover. 


Suggestion for product developer: Make account number a password protected field that only shows up when a specific button is pushed. 


Just spreading the word. Phishing is getting more sophisticated. And apparently I'm getting lonelier. :(