{"id":412268,"date":"2026-09-08T19:08:57","date_gmt":"2026-09-08T19:08:57","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=412268"},"modified":"2026-09-08T19:08:57","modified_gmt":"2026-09-08T19:08:57","slug":"fake-pending-purchase-imessage-scam","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/fake-pending-purchase-imessage-scam\/","title":{"rendered":"Fake Pending Purchase iMessage Steals Your OTP"},"content":{"rendered":"<p>A fake pending purchase iMessage says an order is waiting for approval. If it was not yours, a support number promises to cancel it before the charge goes through.<\/p><div id=\"mwtad1108536264\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The transaction is invented. The code that arrives during the call is real.<\/p>\n<p><img decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Fictional iMessage about a pending purchase with a fake support hotline\" title=\"\" class=\"lazyload\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-pending-purchase-imessage-1.png\"><\/p>\n<div id=\"mwtad3630330358\" class=\"gas_fallback-ad_309746-ad_406044-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>The fake purchase is designed to trigger a callback<\/h3>\n<p>The fake pending purchase iMessage scam starts with an alert about an order, card transaction, or e-commerce payment the recipient does not recognize. The message does not always include a clickable link. It may simply tell the person to call a telephone number to stop the charge.<\/p><div id=\"mwtad3744137267\" class=\"gas_fallback-ad_381396-ad_406044-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>That callback is the real opening. A criminal answers as a bank fraud investigator, retailer, or marketplace support agent and treats the invented purchase as an active emergency.<\/p>\n<p>Singapore&#8217;s ScamShield warned in August 2026 about iMessages impersonating DBS and Shopee. Recipients were told that a pending transaction required verification and were directed to an unfamiliar hotline.<\/p>\n<h3>The agent asks for a one-time password<\/h3>\n<p>During the call, the scammer collects identity details and claims to begin a cancellation. The victim then receives a genuine one-time password from a bank or e-commerce service.<\/p><div id=\"mwtad1848715126\" class=\"gas_fallback-ad_309686-ad_406044-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The caller says the OTP cancels, verifies, or blocks the purchase. In reality, it may authorize a password reset, login, new payee, card transaction, wallet addition, or purchase initiated by the criminal.<\/p>\n<p>A real security code can complete a fake story. The text that delivers the code usually says what it is for and warns not to share it.<\/p>\n<h3>The brands are real, but neither sent the scam<\/h3>\n<p>DBS is a real bank and Shopee is a real e-commerce platform. Their names give the message immediate relevance to a large audience. The campaign works even when the recipient uses only one of them.<\/p><div id=\"mwtad3478340534\" class=\"gas_fallback-ad_381401-ad_406044-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Warning signs include:<\/p>\n<ul>\n<li>an unexpected iMessage claims a purchase is pending or needs approval;<\/li>\n<li>the message comes from a foreign number or random email address;<\/li>\n<li>the only cancellation route is a telephone number inside the message;<\/li>\n<li>the number differs from the one in the official app or on the bank card;<\/li>\n<li>a caller asks for an OTP, PIN, password, or full card details;<\/li>\n<li>the supposed agent keeps the victim on the line while a code arrives;<\/li>\n<li>the code describes a login or payment rather than a cancellation;<\/li>\n<li>the caller says hanging up will allow the transaction to proceed.<\/li>\n<\/ul>\n<div id=\"mwtad4116718495\" class=\"gas_fallback-ad_309747-ad_406044-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why Calling the Number Feels Safer Than Clicking<\/h2>\n<p>People have learned to be suspicious of links in text messages. A telephone number can seem like a safer alternative because it leads to a conversation instead of a web form.<\/p>\n<div id=\"mwtad1109824001\" class=\"gas_fallback-ad_381404-ad_406044-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>The scam uses that assumption. The number is not an independent support channel. It was placed in the message by the same people who invented the transaction.<\/p>\n<p>A live operator can answer questions, adjust the script, repeat account language, and sound calm while the recipient is worried. The caller may transfer the victim to a second person who claims to be a fraud supervisor or bank investigator.<\/p>\n<p>Caller ID does not repair the problem. A callback reaches the number that was dialed. An incoming call can also be spoofed to display a familiar company or bank.<\/p>\n<div id=\"mwtad3604909257\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>The independent check is simple: end the conversation, open the official bank or shopping app, and inspect recent activity. If help is needed, use the number printed on the card or published on the verified company website.<\/p>\n<p>Do not ask the caller whether the number is genuine. A scammer can confirm their own false identity all day. Verification must leave the channel they control.<\/p>\n<p>The operator may try to prevent that check by saying the transaction is still in a hidden authorization queue. Real providers can explain pending activity through an independently reached fraud team. A claim that only one unknown agent can see the charge is a reason to hang up.<\/p>\n<div id=\"mwtad151084019\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>Another pressure tactic is to read back information the victim just supplied and present it as account verification. Repeating a name, email address, or card digits does not prove access to the provider&#8217;s systems. It proves that the caller heard the answer.<\/p>\n<p>Some calls use several voices. A supposed marketplace representative transfers the customer to a bank investigator, who then transfers the call to a security specialist. The handoffs create theater and keep the victim from making an outside call. All of the roles can be people working together or one operator changing tone.<\/p>\n<p>A genuine fraud team will not object if a customer hangs up and calls the official number. It may place temporary protections on an account, but it does not need the customer to remain isolated on an unverified line.<\/p>\n<p><img decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Fictional one-time password alert showing a purchase authorization warning\" title=\"\" class=\"lazyload\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-pending-purchase-imessage-2.png\"><\/p>\n<div id=\"mwtad340420450\" class=\"gas_fallback-ad_309748-ad_406044-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Fake Pending Purchase iMessage Scam Works<\/h2>\n<h3>Step 1: A high-volume iMessage creates a believable charge<\/h3>\n<p>The campaign sends alerts from foreign telephone numbers or email-based iMessage accounts. A familiar bank or marketplace name is combined with a realistic amount and recent time.<\/p>\n<p>The criminal does not need access to the recipient&#8217;s account. Popular brands and ordinary purchase amounts ensure that some messages reach active customers.<\/p>\n<h3>Step 2: The recipient calls the supplied hotline<\/h3>\n<p>The message says immediate contact is required if the purchase was not authorized. Calling feels responsible because real fraud alerts also encourage quick action.<\/p>\n<p>The key difference is how the number was obtained. A hotline inside an unsolicited message has not been verified independently.<\/p>\n<h3>Step 3: A fake investigator builds an account profile<\/h3>\n<p>The operator asks for a name, telephone number, email, card digits, username, identity number, or recent transaction. Questions are framed as identity checks.<\/p>\n<p>Some details may already be known from breached data. Repeating accurate information can make the agent sound as if an account is open on their screen.<\/p>\n<h3>Step 4: The criminal starts a real account action<\/h3>\n<p>While speaking, the scammer attempts a login, password reset, purchase, wallet enrollment, or transfer using the data collected. The legitimate service sends an OTP to the real customer.<\/p>\n<p>This is why the code can arrive from a genuine sender. The service is responding to the criminal&#8217;s action, not confirming the caller&#8217;s identity.<\/p>\n<h3>Step 5: The OTP is relabeled as a cancellation code<\/h3>\n<p>The operator asks the victim to read the number aloud or type it into a form. The script may call it a reversal, fraud case, cancellation, or verification code.<\/p>\n<p>The instruction in the genuine OTP message matters more than the caller&#8217;s explanation. A code that says it approves a payment will not cancel that payment when shared.<\/p>\n<h3>Step 6: The account or payment is compromised<\/h3>\n<p>Once the code is entered, the attacker can complete the pending action. A successful login may provide saved cards, order history, addresses, loyalty balances, and a route into linked services.<\/p>\n<p>If one action is blocked, the caller may request another code and claim the first expired. Each new OTP can correspond to a different theft attempt.<\/p>\n<h3>Step 7: The victim receives a false resolution<\/h3>\n<p>The agent announces that the purchase is canceled and supplies a case number. That reassurance delays the moment when the customer checks the real account.<\/p>\n<p>Later calls may pretend to investigate the resulting fraud. The victim is then asked to move money to a safe account, install remote-access software, or provide another code.<\/p>\n<div id=\"mwtad2752307698\" class=\"gas_fallback-ad_318930-ad_406044-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>The Government Warning Confirms the Campaign<\/h2>\n<p>ScamShield&#8217;s <a href=\"https:\/\/www.scamshield.gov.sg\/resources\/scam-alert\/alert-28aug26\/\" target=\"_blank\" rel=\"noopener\">August 28, 2026 alert<\/a> describes iMessages impersonating DBS fraud investigators and Shopee support. The messages allege a pending transaction, direct recipients to a fake hotline, and lead to requests for an OTP.<\/p>\n<p>The agency advises recipients to verify transactions inside the genuine bank or e-commerce app and to use the official hotline published by the provider. That removes the scammer from both the information source and the contact route.<\/p>\n<p>This is confirmed brand impersonation, not a complaint about DBS, Shopee, Apple, or iMessage. The criminals use those familiar names and services without authorization.<\/p>\n<p>A similar script can substitute another bank, retailer, delivery platform, payment app, or streaming service. The durable warning is the sequence: unexpected purchase, message-supplied hotline, incoming OTP, and a caller who wants the code.<\/p>\n<p>The amount and merchant in the opening message should be treated as bait until they appear in a genuine account. A detailed receipt number or time stamp is easy to generate and does not prove that a payment network has recorded anything.<\/p>\n<div id=\"mwtad2098222818\" class=\"gas_fallback-ad_381388-ad_406044-placement_406705\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Company, Address, and Fulfillment Checks<\/h2>\n<h3>The company name must match the account you open yourself<\/h3>\n<p>Do not rely on the logo or sender label. Open the genuine app and look for the transaction. If the account shows nothing, the message did not create a charge simply by mentioning one.<\/p>\n<p>If activity is visible, contact the provider through the app or known website. Do not return to the number in the iMessage.<\/p>\n<h3>The hotline must come from an independent source<\/h3>\n<p>Use the number on the physical bank card, inside the authenticated app, or on the company&#8217;s verified website. Compare it with the number in the message without dialing the latter.<\/p>\n<p>Search results can contain fraudulent ads and support numbers. Prefer a saved app or typed official domain.<\/p>\n<h3>The OTP text reveals what is being authorized<\/h3>\n<p>Read the complete genuine code message. It may name a merchant, amount, device, login, payee, or password reset. That information is the strongest clue to what the criminal initiated.<\/p>\n<p>No legitimate agent needs the customer to defeat a security warning by reading the protected number aloud.<\/p>\n<h3>The case number does not fulfill a cancellation<\/h3>\n<p>A verbal promise and invented reference number are not evidence that a purchase was reversed. The account&#8217;s transaction history and provider confirmation are what matter.<\/p>\n<p>If the real account shows a completed charge, contact the provider and bank immediately. Do not wait for the fake agent&#8217;s promised refund.<\/p>\n<div id=\"mwtad23710046\" class=\"gas_fallback-ad_381392-ad_406044-placement_406664\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li><strong>End the call.<\/strong> Do not argue, wait for a supervisor, or share another code. The caller already controls the story and hotline.<\/li>\n<li><strong>Open the real apps independently.<\/strong> Check the bank, card, and e-commerce accounts for logins, purchases, new payees, address changes, and password resets.<\/li>\n<li><strong>Call the bank&#8217;s official fraud number.<\/strong> Use the card or verified website. Explain which OTP was shared and the exact wording of the code message.<\/li>\n<li><strong>Freeze cards and transfers where necessary.<\/strong> Ask whether a digital wallet, device, beneficiary, or recurring payment was added and remove anything unfamiliar.<\/li>\n<li><strong>Secure the shopping account.<\/strong> Change its password, sign out other sessions, remove unknown addresses and cards, and enable strong multifactor authentication.<\/li>\n<li><strong>Protect the email account.<\/strong> It may control password resets for both services. Change a reused password and review sessions, recovery methods, forwarding rules, and connected apps.<\/li>\n<li><strong>Preserve the evidence.<\/strong> Screenshot the iMessage, sender, hotline, OTP wording, call history, transaction details, and any case number before reporting and deleting.<\/li>\n<li><strong>Report the sender in iMessage.<\/strong> Use Report Junk where available and block the sender after the record is preserved.<\/li>\n<li><strong>Report the campaign.<\/strong> Singapore users can contact ScamShield and the police. Elsewhere, report to the impersonated company and national fraud service.<\/li>\n<li><strong>Watch for a second-stage call.<\/strong> Criminals may impersonate the bank again using details learned during the first conversation. Use only the case route you opened independently.<\/li>\n<li><strong>Check for remote access.<\/strong> If the caller made you install an app or share a screen, disconnect the device from sensitive accounts, remove the software, and run a Malwarebytes scan. AdGuard can help block known phishing pages and malicious ads, but it cannot cancel a transaction or invalidate a shared OTP.<\/li>\n<li><strong>Reject paid recovery offers.<\/strong> A stranger who promises to recover the transfer for a fee, cryptocurrency deposit, or another OTP is continuing the scam.<\/li>\n<\/ol>\n<div id=\"mwtad946750809\" class=\"gas_fallback-ad_381392-ad_406044-placement_406665\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Frequently Asked Questions<\/h2>\n<h3>Can an iMessage sender name or number be spoofed?<\/h3>\n<p>Messages can arrive from unfamiliar numbers or email-based Apple accounts, and caller ID on follow-up calls can be manipulated. The safe check is inside the genuine service, not in the sender label.<\/p>\n<h3>Why did the OTP come from the real bank or platform?<\/h3>\n<p>The scammer initiated a real action with that service. The genuine system then sent the code to its customer. The code authenticates the action, not the person on the phone.<\/p>\n<h3>Can an OTP cancel a purchase?<\/h3>\n<p>A legitimate provider may use security checks in specific workflows, but an unsolicited caller should never ask you to read a protected code. Follow the description in the code message and verify in the app.<\/p>\n<h3>What if no pending purchase appears?<\/h3>\n<p>That strongly suggests the alert was invented. Do not call the message number. Report and delete it after preserving any evidence you need.<\/p>\n<h3>What if I called but shared no information?<\/h3>\n<p>Block the number and remain alert for follow-up attempts. The operator now knows the telephone number is active and that the purchase story produced a response.<\/p>\n<h3>Does this mean DBS or Shopee was hacked?<\/h3>\n<p>The official warning describes impersonation. A criminal can copy a brand name and send messages without breaching the company. Check official notices for any separate incident.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The fake pending purchase iMessage scam turns a cautious reaction into the attack. The victim calls to prevent fraud, but the supplied hotline leads directly to the people attempting it.<\/p>\n<p>Never share an OTP with an unexpected caller. Open the real bank or shopping app, verify the transaction, and contact support through a number you found independently. If a code was shared, protect both accounts immediately and tell the bank exactly what the code authorized.<\/p>\n<div id=\"mwtad672478216\" class=\"gas_fallback-ad_176819-ad_406044-placement_406666\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A fake pending purchase iMessage says an order is waiting for approval. If it was not yours, a support number promises to cancel it before the charge goes through. The transaction is invented. The code &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Fake Pending Purchase iMessage Steals Your OTP\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/fake-pending-purchase-imessage-scam\/#more-412268\" aria-label=\"Read more about Fake Pending Purchase iMessage Steals Your OTP\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":412266,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-412268","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/412268","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=412268"}],"version-history":[{"count":0,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/412268\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/412266"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=412268"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=412268"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=412268"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}