Phishing teams are using bank branding to push panic clicks. One recent sample uses Maya styling to claim a GoTyme Bank beneficiary was enrolled — then offers a “Remove Beneficiary” button. That button is the trap.
A new phishing modus targets GoTyme users with emails that look like Maya “beneficiary enrolled” alerts. Red flags include a non-bank sender domain, mixed bank branding, and a Remove Beneficiary button that pushes panic clicks. Do not use email buttons. Open the official GoTyme app or website yourself, check beneficiaries there, and report the message as phishing.
- Device detail meant to scare you (for example, enrollment “from a device signed in as Xiaomi 15 Ultra”)
- A large Remove Beneficiary call-to-action designed to make you click before you think
Legitimate banks do not ask you to fix account security by clicking a button in an unsolicited email. For the basics of how phishing works, see our guide on what phishing is.
Why this works
The message mixes urgency, brand trust, and fear of unauthorized transfers. Cross-brand confusion (Maya look, GoTyme beneficiary) makes people hesitate and click “just to be safe.” Attackers count on that hesitation.
This is classic email phishing: impersonation plus a credential or session harvest behind a fake control panel. The same door shows up in ransomware and account-takeover cases — how ransomware gets into a PH business.
What to do if you receive one
- Do not click Remove, Cancel, Verify, or any link in the email. Close the message.
- Check the real From address, not only the display name. Bank mail should come from the bank’s own domain — not a lookalike or analytics domain.
- Open the official GoTyme app or type the official website address yourself. Never use a link from the email.
- Review beneficiaries and recent activity inside the official app or site. If something is wrong, use in-app support or the bank’s published hotline.
- Mark the message as phishing/spam in Gmail or your mail client so filters learn.
- If you already clicked or entered a password, change the GoTyme password from the official app, turn on MFA if available, review devices/sessions, and contact GoTyme support immediately.
- For work devices, treat this as an incident: report it to IT, and do not reuse the same password elsewhere.
These steps match the same hygiene we recommend for companies hardening everyday tools — how companies keep technology tools secure and endpoint security baseline.
What not to do
- Do not reply to the email or call numbers listed only in the message
- Do not upload ID photos or OTPs to any page reached from the email
- Do not forward the live phishing link to colleagues as a “test click”
- Do not assume antivirus alone blocks every fake login page — identity and behavior still matter
What the email looks like
Observed traits of this modus:
- Subject line in the pattern “Beneficiary enrolled: [Name]”
- Display name that looks like a bank brand, while the real From address is a third-party domain (in this sample: linksanalytics.com, not a Maya or GoTyme domain)
- Mixed branding: Maya header and logos, but the beneficiary is labeled as GoTyme Bank
- Device detail meant to scare you (for example, enrollment “from a device signed in as Xiaomi 15 Ultra”)
- A large Remove Beneficiary call-to-action designed to make you click before you think
For teams and SMEs
If staff bank or pay vendors from work laptops, this is an endpoint and awareness problem, not only a consumer issue. Cover the three doors: devices, network edge, and identity. ARA’s practical map is on Enterprise Cybersecurity Architecture. When you want a short, no-pitch review of exposure, book Usap Tayo.
Quick checklist
| Check | Safe action |
|---|---|
| Sender domain | Must match the real bank domain |
| Brand mix | Maya header + GoTyme beneficiary = treat as suspect |
| Remove / Verify button in email | Ignore — use the official app |
| Device scare line | Verify inside the app, not via email |
| Already clicked | Change password, enable MFA, contact the bank |
Stay calm, open the real app yourself, and report the message. Panic clicks are what this modus is built for.
