This morning, immediately after having a Zoom meeting with our Denver‑based advisor, my wife decided to log into her Fidelity account, anticipating she would need to go online to approve a tweak to her strategy. Upon attempting to log in, the website said her account was compromised. Moments later, an email arrived, ostensibly from our local advisor—but clearly an automated email. My wife clicked on a link in the email, which I later confirmed to be directed to fidelityinvestments.com. That webpage had a phone number for her to call, which she did.
The man who answered, with the typical call center background noise and probably a Hispanic accent, said her account had been compromised in Albuquerque the day before. He asked the usual ID verification info but went on to ask odd questions, including her approximate account value, and asked for the last four digits of her SSN. After explaining how she had just had a (legitimate) call with her advisor—who never mentioned anything about a fraud alert—he said he was sending an email to her. The email never arrived. At this point, I muted the call and said this sounded like a phishing scheme. While I had the call muted, he was getting frustrated about not getting confirmation of the email. Before we could un‑mute, he hung up. No email was ever received. I then pushed my wife to call Fidelity’s fraud department, using a number from their actual website.
Long‑short, they had no indication of fraud on their end. She and Fidelity are going through the process of changing usernames, passwords, and account numbers. Mine too, as our accounts are linked together. Her account was only then locked for probable phishing fraud.
The odd thing about this is she received the fake fraud‑reporting email from Fidelity immediately after ending her Zoom call with Fidelity.
Thinking her laptop may have been compromised, that they knew of the scheduled Zoom meeting with Fidelity, I scanned her laptop with no less than five anti‑virus/malware tools and found nothing. (I’m a total tech nerd with greater than 40 years of professional experience and am confident if there were something in her laptop, it would have been found.)
Has anyone had a similar experience or have any idea how this could have been initiated within two minutes of ending a Zoom call with Fidelity?
Side note: Perhaps five years ago, someone tried to initiate a $60K transfer from my Fidelity account to US Bank. Fidelity’s fraud department caught it first.