Criminals Are Impersonating Bank Staff. The FBI Logged 5,100 Cases.

On November 25, 2025, the FBI's Internet Crime Complaint Center warned that since January 2025 it had received more than 5,100 complaints about account takeover fraud involving criminals impersonating financial institution staff, customer support, or technical support, with reported losses exceeding 262 million dollars. The scam is not about finding a specific teller's home address. It is about using a public professional identity, a name, a title, a branch, a photo, to make a fake call or message convincing enough that a customer hands over their login credentials or a one time passcode.

Is this actually about privacy, or just fraud?

Both, and it is worth separating the two risks clearly, because they call for different responses.

Bank tellers and branch staff face a well documented, physical, workplace threat: robbery. In August 2025, a man walked into a Pioneer Bank branch in Las Cruces, New Mexico, handed a teller a threatening note, and left with 3,513 dollars in cash. He was later sentenced to 37 months in federal prison. That is a real and serious risk, but it is a workplace security issue tied to cash handling, not a privacy issue tied to a public online profile.

The privacy story is different, and it is most concrete for licensed roles. Financial professionals who are registered representatives, investment advisers, or mortgage loan originators have legally mandated public profiles through systems like FINRA BrokerCheck and NMLS Consumer Access. BrokerCheck can show up to 10 years of employment history, licenses, exams, and certain disciplinary matters. NMLS Consumer Access confirms whether a mortgage professional or company is authorized to do business in a given state. These are not people search sites. They are regulatory disclosures required by law, and they exist to protect consumers, but they also create a durable, searchable professional identity that can be combined with other public data.

How does a scammer actually use this information?

A scammer does not necessarily need your home address to run this scam. They need enough public detail to sound credible on a phone call: a name, a branch, a title. A message like "this is Jordan Lee from the fraud team at your bank's Downtown branch, we detected a fraudulent transfer and need your verification code" only works because that name, title, and branch are plausible and often publicly findable. LinkedIn's own help documentation confirms that public profiles can appear in Google, Bing, and other search engines, and that changes to visibility settings can take weeks or months to be reflected in search results.

To be clear about what the evidence does and does not show: the FBI's advisory confirms the impersonation and credential theft mechanics, but it does not say attackers commonly source names from LinkedIn or a specific data broker. Treat name and role harvesting as a plausible, common sense enabler of this scam, not as a quantified FBI finding.

We cannot touch your BrokerCheck record. We can shrink everything sitting on top of it.

Privoria removes your name from people search and data broker sites that pair your public professional identity with a home address, phone number, or relatives, the exact combination that turns a routine impersonation attempt into something more personal. Real people, ongoing monitoring, not a single cleanup pass.

Run my free scan Start free trial

What should a financial services employee actually do?

  • Use work email and work phone numbers in public biographies, never a personal mobile number for convenience.
  • Review your LinkedIn public profile settings and remove branch schedules, direct contact details, and unnecessary career and location details. Remember that search engines can take weeks or months to catch up with the change.
  • If you are a registered representative or mortgage professional, review exactly what BrokerCheck, NMLS Consumer Access, or your state licensing portal discloses, and use a business address rather than a residential one wherever that is an option.
  • Treat any request for a password, MFA code, one time passcode, or account change as a potential scam. The FBI is explicit that legitimate institutions generally do not call to request usernames, passwords, or one time codes.
  • Verify through a known internal contact path, never through a number or link the caller provides.
  • Preserve threatening messages, voicemails, and any suspicious contact attempt according to your employer's security procedures.

What does removal actually fix here?

Removal can reduce the number of people search profiles that pair your name with a home address, phone number, or family members, which lowers how much personal material is available to make a scam feel more targeted. It cannot remove your FINRA BrokerCheck record, NMLS listing, or other legally required professional disclosure. It cannot stop caller ID spoofing, phishing websites, or fraudulent search ads, and it will not prevent a branch robbery, which is a physical security issue for your employer, not a data issue. According to Consumer Reports, opt outs done by hand or basic automation clear roughly 27 percent of exposed listings, while ongoing removal by real people reaches closer to 70 percent, which is the gap between a one time cleanup and something that actually holds up over time.

Frequently asked questions

Can Privoria remove my FINRA BrokerCheck listing?

No. BrokerCheck and NMLS Consumer Access are regulatory disclosures required by law, not commercial people search listings, and they cannot be removed through an opt out request.

Is bank teller violence connected to online privacy exposure?

Generally no. Documented cases of bank teller threats are almost always tied to in person robbery for cash, a physical workplace security issue, not to a worker's personal information being found online.

How do I know if a call claiming to be from my bank's fraud team is real?

Hang up and call back using a number you already know is legitimate, such as the one on the back of your card. Legitimate institutions generally do not ask for your password or one time passcode over the phone.

Does removing my LinkedIn details help right away?

Not instantly. LinkedIn's own help pages note that search engines can take weeks or months to reflect a visibility change, so treat it as a step that helps over time, not an immediate fix.

Back to blog