Posting this as a warning, not an accusation — but the pattern is concerning enough that others should be careful.
What happened:
1. Received a promotional-looking email from support@nexo.com (an “exclusive golf tournament invite”) with high-pressure urgency (“reply within hours or miss out”) — classic phishing shape.
2. The email included my correct anti-phishing code. I’ve since tested this multiple times and it keeps matching, which shouldn’t be possible unless the code is being pulled from something on Nexo’s side rather than being unique/secret to phishing attempts specifically.
3. I opened a support ticket to flag this. The ticket got closed — and the response came through the same email thread as the phishing email.
4. Today, someone attempted an in-store purchase on my Nexo card. That card has been deactivated since a similar incident last year. The transaction was rejected, but the attempt itself means someone is trying to use a card I already had frozen.
Why I’m posting:
If your anti-phishing code seems to show up in emails you’re not sure about, don’t take that as proof of legitimacy — verify through the app directly, not by replying to email. And if you’ve had a card compromised before, double-check it’s still actually locked, because clearly mine was targeted again.
I’m escalating through Action Fraud and Nexo’s formal complaints channel outside of the ticket system, since I don’t trust that thread anymore.
Anyone else seeing similar issues — matching codes, tickets closed via suspicious threads, card attempts on old/deactivated cards? Would be useful to know if this is isolated or wider.
submitted by /u/Londonskaterboi
[link] [comments]
