{"id":420285,"date":"2026-09-28T16:14:33","date_gmt":"2026-09-28T16:14:33","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=420285"},"modified":"2026-09-28T16:14:33","modified_gmt":"2026-09-28T16:14:33","slug":"replacement-bank-card-scam-stolen-identities","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/replacement-bank-card-scam-stolen-identities\/","title":{"rendered":"Replacement Bank Card Scam: How Stolen Identities Fueled $650,000 Fraud"},"content":{"rendered":"<p>Your bank says a replacement card is on its way. There is just one problem: you never asked for one.<\/p><div id=\"mwtad1820598044\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>That single notification may be the first visible sign of a fraud that began long before the envelope was sent.<\/p>\n<figure><img loading=\"lazy\" decoding=\"async\" width=\"1100\" height=\"675\" class=\"wp-image-420277 size-full lazyload\" style=\"max-width:100%;height:auto\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Flat on-screen reconstruction of an unexpected bank card replacement notice\" title=\"\" sizes=\"auto, (max-width: 1100px) 100vw, 1100px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/imagesreplacement-request.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/imagesreplacement-request.png 1100w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/imagesreplacement-request-300x184.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/imagesreplacement-request-1024x628.png 1024w\"><\/figure>\n<div id=\"mwtad937511846\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>Criminals used stolen identities to request new cards<\/h3>\n<p>A North Carolina bank fraud case shows how dangerous a fraudulent replacement card request can be. At least 10 people had their identities misused.<\/p><div id=\"mwtad18702800\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>According to the <a href=\"https:\/\/www.justice.gov\/usao-wdnc\/pr\/reidsville-man-sentenced-650000-bank-fraud-scheme-involving-stolen-identities\" target=\"_blank\" rel=\"noopener\">Justice Department<\/a>, Cordara Mattox called financial institutions while pretending to be the account holders.<\/p>\n<p>He requested replacement debit and credit cards. Once the cards were obtained, the conspirators used them for retail transactions exceeding $650,000.<\/p>\n<p>Jacob Lawson and Mattox pleaded guilty to conspiracy to commit bank fraud. Lawson received 15 months in prison; Mattox had previously received 30 months.<\/p><div id=\"mwtad1681833959\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<h3>The warning sign can look like ordinary account service<\/h3>\n<p>A new card arriving unexpectedly, or an alert about a replacement request, may seem like a bank error. It may instead mean someone passed an identity check.<\/p>\n<p>Victims do not have to click a phishing link or speak to a scam caller for this particular fraud to begin. Existing stolen information may be enough.<\/p>\n<p>The public case summary does not identify how the conspirators first obtained each person&#8217;s data. It also does not describe every bank&#8217;s verification process.<\/p><div id=\"mwtad3967375612\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Our images are non-functional reconstructions of the warning and response path. They are not actual bank screens or evidence from the criminal case.<\/p>\n<ul>\n<li>An unrequested replacement-card notice deserves immediate verification.<\/li>\n<li>Unknown mailing-address or contact-detail changes increase urgency.<\/li>\n<li>Card activity can occur before a victim realizes a new card exists.<\/li>\n<li>The correct response is to call the bank through its independently verified channel.<\/li>\n<li>Ask the bank to review all active cards, delivery addresses, and recent requests.<\/li>\n<\/ul>\n<h3>This is identity theft, not proof the bank sent a phishing email<\/h3>\n<p>The deception in this case was directed at financial institutions. The criminals impersonated customers to obtain replacement cards and spend money.<\/p>\n<div id=\"mwtad4272987877\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>A genuine bank notification about a replacement could be the warning that exposes the scam. Do not automatically label every such email fraudulent.<\/p>\n<p>Instead, verify the account through the bank&#8217;s app, a prior statement, or the number on your existing card. Avoid the contact details inside a suspicious message.<\/p>\n<div id=\"mwtad3037645276\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What the Lawson and Mattox Case Reveals<\/h2>\n<p>From July 2021 through April 2025, Lawson conspired with Mattox and others, according to court records summarized by federal prosecutors.<\/p>\n<div id=\"mwtad1063364543\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>The group obtained personal identifying and banking information for victims in North Carolina and elsewhere. The precise source of that information was not disclosed.<\/p>\n<p>Mattox then contacted banks as if he were the account holders. He asked for replacement debit and credit cards, which gave the group a path to purchases.<\/p>\n<p>Retail transactions made with those cards exceeded $650,000. The restitution amount announced for the case was $656,781.46.<\/p>\n<div id=\"mwtad1288324890\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>The records establish a specific identity-theft operation, not merely a theoretical vulnerability. Both named defendants admitted their roles through guilty pleas.<\/p>\n<p>It is important not to fill the gaps with guesses. The DOJ did not say whether cards were mailed to altered addresses, intercepted, or collected another way.<\/p>\n<p>The public announcement also does not explain how each bank approved the request. Different institutions may have different identity checks and fraud controls.<\/p>\n<p>For a reader, the useful lesson is simple: an unexpected card event can be a security alert even if no unauthorized purchase has appeared yet.<\/p>\n<p>If the bank confirms that no request came from you, ask it to lock the replacement card and investigate how the request was authenticated.<\/p>\n<div id=\"mwtad3722385941\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Replacement Bank Card Scam Works<\/h2>\n<h3>Step 1: The criminal acquires enough account information<\/h3>\n<p>The fraud starts before the victim sees a replacement notice. Someone has information that may help them pose as the account holder to a bank.<\/p>\n<p>That may include personal identifiers and banking details. The Lawson-Mattox announcement confirms they possessed both categories, but not their exact source.<\/p>\n<p>Do not assume a single data breach caused the event. A bank&#8217;s investigation should examine the specific request and any changes made to the account.<\/p>\n<p>A victim can be careful online and still be targeted. Identity theft often exploits data beyond the victim&#8217;s immediate control.<\/p>\n<h3>Step 2: The criminal contacts the bank as the customer<\/h3>\n<p>Mattox posed as victims when contacting financial institutions, prosecutors said. That is the central impersonation in this case.<\/p>\n<p>The criminal&#8217;s objective is not to persuade the victim directly. It is to make a bank representative or system accept a fraudulent service request.<\/p>\n<p>Questions about address, account history, or verification codes may be part of a bank&#8217;s process. We do not know which checks were bypassed here.<\/p>\n<p>Never share a one-time code with a stranger who says it will cancel a card request. Contact the bank independently instead.<\/p>\n<h3>Step 3: A replacement card is issued without authorization<\/h3>\n<p>Once the request succeeds, a new debit or credit card enters the process. It may be shipped or otherwise delivered, depending on bank procedures.<\/p>\n<p>In this case, the conspirators obtained replacement cards. The DOJ did not disclose the exact route by which each card reached them.<\/p>\n<p>An alert that a card has been ordered is therefore meaningful. It can give the real customer time to stop a card before activation or use.<\/p>\n<p>Ask whether the old card remains active, what address was used, and whether phone numbers or email addresses were changed at the same time.<\/p>\n<figure><img loading=\"lazy\" decoding=\"async\" width=\"1100\" height=\"675\" class=\"wp-image-420278 size-full lazyload\" style=\"max-width:100%;height:auto\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Flat on-screen reconstruction of a bank security review for an unauthorized replacement card\" title=\"\" sizes=\"auto, (max-width: 1100px) 100vw, 1100px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/imagesreplacement-review.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/imagesreplacement-review.png 1100w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/imagesreplacement-review-300x184.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/imagesreplacement-review-1024x628.png 1024w\"><\/figure>\n<h3>Step 4: Retail spending converts identity theft into loss<\/h3>\n<p>Prosecutors say the conspirators used the replacement cards for retail transactions exceeding $650,000. That was the money-making stage.<\/p>\n<p>A new card can appear legitimate to a store because it was issued by the real bank. The fraud lies in who requested and controlled it.<\/p>\n<p>Do not wait for a monthly statement if you receive an unrequested-card alert. Some transactions can be completed before paper statements arrive.<\/p>\n<p>Activate account notifications for card creation, address changes, online access, and transactions where your bank offers them.<\/p>\n<h3>Step 5: The victim must unwind both the card and identity misuse<\/h3>\n<p>Blocking one card is essential, but it may not address the stolen information used to obtain it. Ask the bank what else changed.<\/p>\n<p>Review other accounts, credit reports, and any new financial products opened in your name. Keep a list of institutions contacted and actions taken.<\/p>\n<p>If the bank finds a fraudulent request, ask for a written summary. That record can help with disputes, police reports, and later identity-theft remediation.<\/p>\n<p>Recovery is not always instant. A calm, documented response gives the customer a stronger trail if the issue has to be escalated.<\/p>\n<div id=\"mwtad743891811\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How to Tell a Genuine Bank Notice From a Phishing Message<\/h2>\n<p>A notification about a card request might be real, fraudulent, or a phishing lure that only pretends a request exists. The appearance alone cannot settle it.<\/p>\n<p>Open your bank&#8217;s app directly or call the number on an existing card. Ask whether a replacement was actually requested and when.<\/p>\n<p>If the bank has no record, the message may be phishing. Do not click its \u201ccancel\u201d button or provide personal information through the linked page.<\/p>\n<p>If the bank confirms a request you did not make, treat it as account compromise. Ask for immediate blocking and an investigation of contact changes.<\/p>\n<p>Do not rely on an email sender name, a logo, or polished design. Those elements are easy to copy into a fraudulent message.<\/p>\n<p>Even an authentic notification can be missed if a criminal has altered the account&#8217;s email or mailing address. Periodic direct account review remains useful.<\/p>\n<p>Some banks allow travel or card controls in the app. These can reduce exposure, but they do not replace reporting an unauthorized issuance.<\/p>\n<p>When speaking with the bank, distinguish \u201cI lost my card\u201d from \u201csomeone impersonated me and ordered a replacement.\u201d The second statement identifies the full problem.<\/p>\n<div id=\"mwtad313614891\" class=\"gas_fallback-ad_381388-ad_309685-placement_406705\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Practical Safeguards for a Household<\/h2>\n<p>Make sure the bank has your current email, phone, and mailing address. Outdated details can delay alerts and make unusual changes less obvious.<\/p>\n<p>Use unique passwords for financial accounts and enable multifactor authentication. These steps do not guarantee protection against phone impersonation, but they close other routes.<\/p>\n<p>Consider a credit freeze if identity information was exposed or new accounts appear. A freeze is not the same as blocking an existing debit card.<\/p>\n<p>Review statements for small test purchases as well as large ones. An unfamiliar transaction can be the first clue that another card exists.<\/p>\n<p>If you assist an older relative, ask whether they want help setting up account alerts. Respect their control while making it easier to notice unusual requests.<\/p>\n<p>Never tell them a breach was their fault. In the documented case, the criminals used stolen data and impersonated customers without their consent.<\/p>\n<p>Keep a trusted bank number in a secure place. That reduces the chance of following a malicious number during a stressful alert.<\/p>\n<p>Finally, ask how your bank verifies replacement requests. It may offer additional account notes, alerts, or controls that suit your situation.<\/p>\n<div id=\"mwtad1926125402\" class=\"gas_fallback-ad_381392-ad_309685-placement_406664\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What This Case Cannot Tell Us About Every Account<\/h2>\n<p>The prosecution describes a particular criminal group and period. It is not a measurement of how often replacement-card fraud happens at every bank.<\/p>\n<p>It also does not identify the institutions involved in every transaction. Naming a bank without evidence would unfairly imply it had a documented role.<\/p>\n<p>The source of the stolen information remains an important unknown. Victims should resist claims that one company or data breach is responsible without proof.<\/p>\n<p>Likewise, the public summary does not say every victim received an email alert. Some may have discovered the problem only after transactions appeared.<\/p>\n<p>The restitution figure is not automatically the amount an individual customer will recover. Banks and courts handle different parts of the financial aftermath.<\/p>\n<p>A replacement card request can have innocent explanations, including a scheduled expiration or an earlier request by an authorized account holder.<\/p>\n<p>That is why verification matters. You do not need to accuse anyone before asking the bank to confirm a request and explain its origin.<\/p>\n<p>Keep notes from the first call. A precise timeline can reveal whether the replacement, address change, and spending occurred in a connected sequence.<\/p>\n<p>If several institutions report similar unauthorized changes, widen the response beyond one card. Identity theft may affect credit, loans, and other accounts.<\/p>\n<p>If only one message is suspicious and the bank finds no request, focus on the phishing attempt and any information you may have entered.<\/p>\n<p>Both paths begin with the same safe action: reach the real bank through a channel you control, then follow the evidence from its records.<\/p>\n<div id=\"mwtad2043909244\" class=\"gas_fallback-ad_381392-ad_309685-placement_406665\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li><strong>Call your bank immediately.<\/strong> Use an established number or the official app. Explain that a replacement card was requested without your permission and ask it to block every affected card.<\/li>\n<li><strong>Review account changes.<\/strong> Check shipping addresses, email addresses, phone numbers, authorized users, payees, and recent access. Ask the bank to preserve the request record.<\/li>\n<li><strong>Dispute unauthorized purchases.<\/strong> Identify both pending and posted transactions. Request a case number, confirmation in writing, and the applicable dispute deadlines.<\/li>\n<li><strong>Secure identity records.<\/strong> Change account credentials and review credit reports. Consider a credit freeze if the bank confirms personal information was misused.<\/li>\n<li><strong>Document the timeline.<\/strong> Save messages, envelopes, card mailers, account screenshots, and names of bank representatives. Record when each alert or transaction appeared.<\/li>\n<li><strong>File reports.<\/strong> Use <a href=\"https:\/\/www.identitytheft.gov\/\" target=\"_blank\" rel=\"noopener\">IdentityTheft.gov<\/a>, local police when appropriate, and <a href=\"https:\/\/www.ic3.gov\/\" target=\"_blank\" rel=\"noopener\">IC3<\/a> for an online or interstate element.<\/li>\n<li><strong>Watch for follow-up contact.<\/strong> An impostor may call pretending to resolve the case. Do not disclose codes or use a callback number from an unsolicited message.<\/li>\n<\/ol>\n<p>If a replacement card arrives at your home, do not activate it while the incident remains unexplained. Ask the bank whether it is part of a legitimate remediation plan.<\/p>\n<p>If no card arrives, do not dismiss the alert. The question is whether a request occurred and where the resulting card was sent.<\/p>\n<p>Scanning your device can help if you entered credentials on a suspicious page. It does not fix the identity records or block a card by itself.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Can someone order my replacement card without taking my old one?<\/h3>\n<p>Yes. The documented scheme involved impersonating customers to request new cards. A missing old card is not required for the request itself.<\/p>\n<h3>Does an unexpected replacement email always mean a card was ordered?<\/h3>\n<p>No. The message could be phishing. Check through your bank&#8217;s official app or phone number to confirm whether a request exists.<\/p>\n<h3>How did Lawson and Mattox get victims&#8217; information?<\/h3>\n<p>The DOJ says they obtained identifying and banking information, but its public summary does not specify the original source for each victim.<\/p>\n<h3>Were the defendants convicted?<\/h3>\n<p>Both pleaded guilty to conspiracy to commit bank fraud. Their prison sentences and restitution were announced by federal prosecutors.<\/p>\n<h3>Should I freeze my credit or just cancel the card?<\/h3>\n<p>Cancel the unauthorized card immediately. A credit freeze may also help if identity information was stolen or new accounts were opened.<\/p>\n<h3>What should I ask the bank to investigate?<\/h3>\n<p>Ask when the replacement was requested, how it was authenticated, where it was sent, what account details changed, and which transactions used it.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The replacement bank card scam turns stolen identity data into a legitimate-looking card under a criminal&#8217;s control. The Lawson-Mattox case shows the scale possible.<\/p>\n<p>If you receive a card alert you did not initiate, verify it directly with your bank. Stopping the card quickly is only the first step; investigate the identity misuse too.<\/p>\n<div id=\"mwtad267274884\" class=\"gas_fallback-ad_176819-ad_309685-placement_406666\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Your bank says a replacement card is on its way. There is just one problem: you never asked for one. That single notification may be the first visible sign of a fraud that began long &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Replacement Bank Card Scam: How Stolen Identities Fueled $650,000 Fraud\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/replacement-bank-card-scam-stolen-identities\/#more-420285\" aria-label=\"Read more about Replacement Bank Card Scam: How Stolen Identities Fueled $650,000 Fraud\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":420277,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-420285","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/420285","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=420285"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/420285\/revisions"}],"predecessor-version":[{"id":420464,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/420285\/revisions\/420464"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/420277"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=420285"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=420285"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=420285"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}