Skip to main content

Current scam tactics and how to protect your account

The warning signs people were taught to look for no longer apply. What changed, and what helps.

Scam tactics have gotten more sophisticated over time. Many newer techniques are not after your password at all. They need you to take an action: install an app, hold your card against your phone, or read a code aloud.

ARQ will never:

  • Call you to ask for personal details, codes, or to ask you to carry out a transaction

  • Ask for the six-digit verification code sent by SMS, WhatsApp or email.

  • Ask for your four-digit passcode, fingerprint or face unlock

  • Ask for your full card details — number, expiry, CVV or PIN

  • Ask you to install an app to check, verify or protect your account

  • Ask you to move your money to a different account for safekeeping

  • Contact you by direct message on social media to provide support

Genuine contact does not come with a deadline. Urgency (a countdown, an account closing today, a warning that hanging up will cost you money) is a pressure technique rather than a real constraint. Ending a call and coming back through the in-app chat will not cost you anything.


Four techniques that became more common recently

1. An app that offers to help, then operates your phone

Someone claiming to be support asks you to install an app to resolve a problem. Once installed, it requests accessibility permissions — which allow it to read your screen, record what you type and tap buttons on your behalf. It does not need your password; it waits until you log in normally.

What helps: not installing apps at the request of someone who contacted you, even if the number looks like ours; installing only from Google Play or the App Store, checking the developer name; and reviewing which apps hold accessibility permissions, usually under Settings › Accessibility on Android.

2. Card details captured through the phone

Sometimes called NFC relay. After persuading you to install an app, the fraudster asks you to hold your card against your phone to validate or activate it. The phone reads the card and relays the data to someone who uses it to pay elsewhere.

There is no legitimate reason for anyone to ask you to hold your card against your phone to verify it — not us, not a bank, not a merchant.

What helps: declining the request; freezing the card in the app and contacting us if it already happened; turning NFC off when not paying.

3. A familiar voice on the phone

Voice cloning needs only a very short audio sample. The cloned voice is used two ways: a family member in urgent need of money, or a support agent reporting unusual activity. A recognisable voice tends to lower suspicion, and cloned voices are hard to identify by ear.

What helps: ending the call and calling back on a number you already had saved; agreeing a shared word with close family for urgent money requests; treating urgent requests made by call or voice note with caution even when the voice sounds right.

4. QR codes that lead somewhere else

A QR code cannot be read by eye. Fraudulent codes are placed over legitimate ones in public places, or sent by email where they pass filters as images. They lead to a page resembling ours and ask for your details.

What helps: checking whether a physical code has been stuck over another; reading the full address before opening it, paying attention to the end of the domain (arqfinance.com.verify-account.net is not ours); not entering your passcode or card details on a page reached by QR.


And the techniques that have not gone away

  • Fake support by direct message after you comment on our social posts. We do not provide support by DM.

  • Fake prizes, asking for personal details or a small payment to release them.

  • Fake payment confirmation — a forged receipt or a site to "confirm" a payment. Checking the money in your own app is more reliable.

  • Someone claiming to work here, reporting suspicious activity and asking for a code to cancel it.


How to check that it is really us

The ARQ Website is www.arqfinance.com

Help Centre help.arqfinance.com

App ARQ on the App Store and Google Play

Email only from @arqfinance.com (automated messages from no-reply@arqfinance.com)

Support through the in-app chat

  • Rather than checking the person who contacted you, close the message and open the app yourself. If the notice is genuine, it will be there.

  • Read the full email address rather than the display name. Addresses like support@arq-finance.com are not ours.

  • Reach our social accounts through the link on our website rather than searching within the platform — fraudulent accounts copy names, images and follower counts.

  • We do not make phone calls asking for personal details or codes.

How we notify you: push notification, email to your registered address, and SMS in urgent cases. These inform you — they do not ask you to reply with details.


Three things worth a couple of minutes

  1. Biometric unlock for opening the app and confirming transactions.

  2. Verifying your email address, so you have an additional way to receive codes if you lose access to your phone number.

  3. Keeping your phone and the app updated, since updates often close security gaps.


If something has already happened

It is usually better to cut off access first and work out what happened afterwards.

  1. Freeze your card in the app.

  2. Change your passcode.

  3. Contact us through the in-app chat. If you cannot open the app, email help@arqfinance.com from your registered address.

  4. If your phone suddenly lost signal and has not regained it, it is worth contacting your mobile provider to check whether anything changed on your line.

If you do not recognise a transaction: tell us through the in-app chat with the date, amount, what you do not recognise, and any supporting material. We record the report, investigate and inform you of the outcome.

If you have found a security vulnerability, our responsible disclosure programme is the right route rather than support.


Most of the scam techniques do not break anything technical — they rely on someone acting quickly under pressure. Knowing about them in advance is a large part of the defence.

Did this answer your question?