Experts flag Bank of America phishing scam that hands your device over to hackers
Why would Bank of America want to install ScreenConnect on your computer?
by https://www.techradar.com/uk/author/sead-fadilpai · TechRadarNews By Sead Fadilpašić Published 5 August 2026
Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter
- Huntress flags phishing emails spoofing Bank of America, pushing victims into different infection chains on Windows vs. macOS
- Windows users were tricked into installing ScreenConnect RMM via fake “Account Guard,” while macOS users faced credential‑harvesting forms for identity theft
- Emails mimicked Bank of America branding but came from unrelated domains; users advised to verify sender addresses to spot scams
Bank of America customers have been warned to take extra caution after experts warned of hackers spoofing the bank into trick you into downloading unwanted software and granting them access to your computer.
Security researchers Huntress revealed how it received a phishing email in their honeypot (an address set up primarily to catch scammers) claiming to have come from Bank of America.
Obviously, the message came from a domain completely unrelated to the company, but looked almost identical to the real thing, with the company logos, color schemes, and other details, meticulously imitated.
Latest Videos FromTechRadarWatch full video here:
Just another ScreenConnect scam
In the email, the researchers were warned that their account was about to be “restricted” unless they “confirmed” certain information.
Depending on the platform from which the victim views the email, both the infection chain and the end goal are different. For Windows users, victims are invited to install “Account Guard”, which is described as a “powerful tool designed to protect your financial data, prevent unauthorized transactions, and other cyber threats”.
This is no guard - this is a Visual Basic script that leads to an installation of the ScreenConnect Remote Monitoring and Management (RMM) tool. ScreenConnect is not malicious itself - it is a legitimate tool - but it is also one of the most abused software out there, leveraged to grant attackers unabated access to victim computers without triggering any alarms.
For macOS users, on the other hand, the goal is different. Instead of trying to deploy malware, the attackers try to steal sensitive data. First, the victims are asked to log in to their banking account (twice - the first attempt is scripted to fail, in case the victim purposely submits the wrong password the first time).
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsors