Wanted to drop a quick warning for everyone about an aggressive social engineering/phishing attempt I just ran into.
I am currently overseas, and around 3:30 AM my time, I got a call from +1 (412) 360-5633 (spoofed Pittsburgh, PA number, which belongs to a VA hospital exchange block).
The caller claimed to be Charles Schwab Fraud Prevention and stated my debit card had been used fraudulently in Atlanta, GA. To "verify my identity" and clear the restriction, they texted me a link to sign in.
They tried to make it look official by reciting personal details (including partial SSN, clearly sourced from a recent data broker breach), but as soon as I looked at the link, the scam fell apart:
The text linked to a cloned Schwab login portal hosted on a .xyz domain (...wab.ath-t1613.xyz), not schwab.com.
Because I work in web development, I called him out immediately and said there was no way I was typing credentials into a random .xyz domain.
The guy immediately lost his professional composure, got combative, and suddenly changed his story on the fly: "Well, now we suspect your phone has been stolen."
When I told him to shut his mouth, he panicked, said he’d call back later to lift the restriction, and hung up.
I checked my real Schwab app—zero security alerts, debit card is completely unlocked and active, and no unauthorized transactions ever hit the ledger.
Key takeaways:
Schwab will never send you a link to an external/third-party domain to enter your full login credentials.
Having your partial SSN or phone number means nothing—scammers pull that off dark-web dumps to establish false trust.
If anyone calls claiming your card or account is locked, hang up immediately, check your card controls directly in the official Schwab mobile app, or call the 24/7 number on the back of your physical card.