CISA Emergency Alert: Critical Banking Trojan "Goldfish" Targeting US Banks - March 19, 2026
New sophisticated malware bypasses two-factor authentication and drains accounts within minutes.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency alert about a new banking trojan dubbed "Goldfish" that has already stolen over $45 million from American bank accounts. The malware spreads through fake banking app updates sent via SMS and email, perfectly mimicking legitimate bank communications. Once installed, Goldfish intercepts 2FA codes in real-time and initiates unauthorized wire transfers within seconds. Major banks including Chase, Bank of America, and Wells Fargo have confirmed customer compromises. CISA recommends: never download banking apps from links in messages, only use official app stores, enable biometric authentication, and set up transaction alerts for any amount. The FBI Cyber Division is actively investigating with arrests expected soon.
What this article means for a user right now
New sophisticated malware bypasses two-factor authentication and drains accounts within minutes.
- Phishing Link Checker: For suspicious links, login pages, fake delivery texts, and scam emails.
- Scam Detector: For mixed scam inputs such as messages, files, screenshots, links, and fake shops.
Related Scam Types
Best next step
Official resources
Industry anti-phishing organization with reporting and education resources.
FTC Consumer AdviceUS consumer guidance for scams, fraud patterns, and reporting options.
FBI Internet Crime Complaint CenterOfficial reporting channel for internet-enabled crime in the United States.