Our service provider reports seeing increased activity with a malware screen takeover, which is targeting token users. This particular malware variant will prompt a user to input account and/or token data, which then results in another screen prompt indicating that the user will be unable to access the account for 24-hours while maintenance is performed. While the user is detained on the fake “maintenance” screen, it allows the fraudster enough time to take over the session and commit fraud.