iPhone stolen in Marbella, accounts drained in 12 hours: inside the fraud

An iPhone stolen in Marbella leads to €20,000 drained from accounts in 12 hours. Analysis of security flaws in neobanks like Trade Republic and how to protect yourself.

English · Original discussion in Spanish · Published

Express theft in Marbella: how €20,000 was drained from an iPhone in 12 hours

An iPhone 15 stolen at Playa Padre, a luxury beach club in Marbella, was enough for professional incivil to drain accounts worth €20,000 in less than 12 hours. The case exposes critical security flaws in neobanks like Trade Republic and the reliance on a single device.

The theft began when the thieves observed the phone's unlock PIN, which the victim kept with their ID in the case. With access to the phone, they used Apple Pay with the Trade Republic card to withdraw cash and make purchases. They also made instant transfers from a savings account to a current account. The victim could not block the Trade Republic account from the app (it required access to the phone) and the emergency phone line only offered a bot that did not stop the movements.

The security hole in neobanks

Trade Republic took several days to contact the victim, despite multiple reports. Traditional banks, by contrast, can block accounts and cards within minutes. The absence of a quick blocking process and the reliance on the app on the device itself are criticized. Furthermore, SMS-based two-factor authentication (2FA) is vulnerable if the attacker has access to the number via SIM.

Apple Pay tokenization does not protect if the phone is unlocked: once inside, the attacker can use stored cards without further verification.

Lessons and protective measures

The discussion thread (precursor to this article) generated an extensive security analysis. The conclusions point to:
- Do not keep your ID with your phone.
- Use facial recognition or fingerprint as the only unlock method (no backup PIN).
- Do not have cards from accounts with large balances in Apple Pay or similar.
- Use a separate phone for banking apps and another for daily use.
- Enable stolen device protection in iOS that requires Face ID outside trusted locations.

Some participants noted that the sense of security is fictitious: the convenience of having everything on one phone comes at a high risk. Others argued that the problem is not the phone, but the concentration of access and the lack of quick protocols in certain banks.



The open question is whether neobanks and mobile payment systems will assume part of the responsibility or whether the user must shield themselves with measures that are not yet standard. Meanwhile, everyone assesses their own exposure.

Related debates on the forum

Summary of a discussion on Burbuja.info - Foro de economía, actualidad y política., translated from Spanish and reviewed before publication. Read the full discussion (491 replies).

More summaries

All summaries in English →

Back