Bank customers in several states received calls from people posing as representatives of their financial institution, according to Cape Coral police.
The callers asked for one-time passcodes and account-verification details. Investigators said that information was then used to contact the real bank, change customers’ mailing addresses, and request expedited replacement debit cards.
The new cards were sent to addresses in Cape Coral, putting them under the fraudsters’ control. Police later connected Santino Parreno Guerra, 31, to cash withdrawals and high-value money-order purchases tied to the compromised accounts.
Detectives arrested Guerra during a July 23 search of a Cape Coral residence. He now faces identity-theft and grand-theft charges while the investigation continues. The charges are accusations and have not been proven in court.
The Calls Targeted One-Time Passcodes
The investigation began in early July after corporate security specialists at an unnamed financial institution found coordinated account compromises, according to Gulf Coast News Now.
Police said the callers impersonated bank representatives and tried to get customers to share one-time passcodes. Those temporary codes are designed to confirm that the person logging in, changing account details, or requesting account services is the real customer.
The callers also sought other verification details that could help them pass the bank’s security checks. Once they had enough information, investigators said, the fraudsters contacted the bank’s call center while pretending to be the account holders.
The Address Change Put New Debit Cards in Cape Coral
The stolen verification details were then used against the real bank. Police said the fraudsters changed the mailing addresses on compromised accounts to locations in Cape Coral and requested expedited replacement debit cards.
That method gave them access to newly issued cards, not just stolen card numbers. Expedited shipping also shortened the time between the account takeover and the moment the cards could be used for withdrawals or purchases.
Detectives with the Cape Coral Police Department’s Economic Crimes Unit later connected Guerra to fraudulent cash withdrawals and high-value money-order purchases. Money orders can move stolen funds into another payment instrument, making the trail more complicated than a single card swipe or ATM withdrawal.
A Search Warrant Led to His Arrest
Economic-crimes detectives and the Cape Coral Police SWAT team searched a residence on Northeast 24th Avenue on the morning of July 23. Police said they found evidence connected to the investigation and took Guerra into custody.
He was transported to the Lee County Jail and booked on charges of fraudulent or illegal use of personal identification involving a victim age 60 or older, grand theft, and resisting an officer without violence.
Cape Coral police said the investigation remains ongoing.
Verification Codes Should Stay With the Customer
The Federal Trade Commission warns consumers not to share verification codes with someone who calls, texts, or emails unexpectedly. Banks use those codes to confirm the customer’s identity, which is exactly why scammers want them.
A real bank caller should not need a customer to read back a one-time passcode, approve a login, or provide a code that arrived by text or email. If the call is about fraud, a locked account, a suspicious transaction, or a new card request, the safer step is to hang up and contact the bank through the number on the card, the official app, or the bank’s verified website.
The Office of the Comptroller of the Currency’s HelpWithMyBank.gov guidance also warns consumers not to provide bank account details, one-time passcodes, credit card numbers, or other personal information over the phone unless they initiated the contact and know the entity is legitimate.
Account Changes Need a Fast Check
Customers should treat unexpected address-change notices, replacement-card notices, new-device alerts, one-time codes, and failed login messages as urgent. Those messages can mean someone is already trying to take over the account.
If a bank account may be compromised, the customer should call the bank immediately, ask whether the mailing address or phone number was changed, cancel any replacement cards that were ordered, remove unknown devices, reset online banking credentials from a clean device, and review recent withdrawals, debit-card activity, and money-order purchases.
Victims should save one-time-code messages, call logs, voicemails, emails, bank alerts, address-change notices, card-shipping notices, transaction records, ATM withdrawals, money-order receipts, screenshots, and any names or phone numbers used by the caller. Bank impersonation and identity-theft reports can also be filed with local police, the FTC at ReportFraud.ftc.gov, and IdentityTheft.gov.
