
If a call, text, or email says it is your bank and something is wrong with your account, do one thing before anything else: stop, hang up or close the message, and call your bank yourself using the number printed on the back of your card. Do not use any number, link, or reply option the message gave you. A real bank is fine with you calling back. A scammer needs you to stay on the line right now. That single habit, calling back on a number you already trust, defeats almost every bank impersonation scam, no matter how convincing the first contact looked.
That is the whole answer. The rest of this guide explains why it works, how these scams are built, and exactly what to do for a call, a text, and an email, because the right move is slightly different for each.
This article explains how these scams operate. It is general information, not personal financial or legal advice. See our disclaimer for more.
Why “just call your bank” is the rule that beats everything
Bank impersonation is not a rare edge case. In its 2025 fraud data, the U.S. Federal Trade Commission reported that people lost about $3.5 billion to imposter scams, the most-reported fraud category of the year, and that among business impersonators the highest reported losses came from scammers posing as banks. So this is not a fringe worry. It is one of the most common and most costly scams there is.
The reason a callback works is simple. Every part of a scam message can be faked except one thing: which number you choose to dial. Scammers can copy a bank’s logo, its wording, even its phone number on your screen. What they cannot do is control the number on your own card. When you hang up and dial that number yourself, you route around every fake detail they built. If the “problem” was real, your bank will still see it when you call. If it was invented, you just saved yourself.
How a bank impersonation scam is actually built
These scams follow a pattern. Once you can see the moving parts, the pressure loses most of its power.
1. The spoofed number or sender. Caller ID can be faked. So can the sender name on a text. This is called spoofing, and it means your phone can honestly display your bank’s real name or real number while a stranger is on the line. “It showed my bank’s actual number” feels like proof. It is not. It is the easiest part of the whole scam to fake, which is exactly why scammers lean on it.
2. The manufactured emergency. The message opens with alarm: suspicious activity, a large payment you did not make, your account locked or about to be. The goal is to switch you out of calm thinking and into reaction. Fear makes people skip the one step, the callback, that would end the scam.
3. The “move your money to a safe account” step. This is the most damaging move, and it is worth knowing by name. The caller says your money is at risk and offers to help you “protect” it by transferring it to a new, safe, or holding account they name. That account is theirs. No real bank will ever ask you to move your money to keep it safe. The FTC has noted that some of the costliest impersonation scams begin with a fake security alert and end with the victim moving money to “protect” it.
4. The one-time code request. The caller says they are sending a verification code and asks you to read it back, or a text tells you to enter a code on a page. That code is often the final key to your account or to approving a payment. The FBI’s Internet Crime Complaint Center (IC3) has warned that criminals impersonate financial-institution staff specifically to trick people into handing over one-time passcodes and login details, a tactic behind thousands of account-takeover complaints. Here is the line that never changes: no real bank will ever ask you to read back a one-time code, PIN, or full password. Ever. If someone asks, that alone tells you it is a scam.
Notice the shape. Fake identity, then fear, then a request to either move money or share a secret. If you can name the step you are in, you are already out of the trance.
If it is a phone call
Hang up. You do not owe the caller an explanation, and you do not need to prove anything before you go. It is not rude to end a call and verify.
Before you hang up, do not answer questions, even small ones. Confirming your name, your address, or “the last four digits” gives a scammer material to sound more convincing on the next call. A real bank that truly needs to reach you will not mind you calling back.
Then call the number on your card. If the fraud alert was genuine, the real bank will find it. If the representative resists you hanging up to verify, or pressures you to stay on the line, treat that resistance itself as the red flag. Urgency that punishes you for checking is the tell.
Calls that pretend to be your bank are a form of voice phishing. We break down the differences in phishing, smishing, and vishing explained.
If it is a text message
The safest rule for a bank text is the strictest one: do not tap the link. Not to log in, not to “confirm it is not you,” not even just to look. A fake login page can capture your details the moment you type them, and simply loading the page can tell the scammer your number is live and worth targeting again.
A real bank text may alert you to a suspicious charge, but a legitimate one will not push you to a link to “unlock” your account under time pressure, and it will never ask you to reply with a code, password, or PIN. When in doubt, ignore the text entirely and open your banking app on your own, or call the number on your card. You lose nothing by verifying independently.
If you use text codes to log in, it helps to understand how they fit into account security. See two-factor authentication for banking.
If it is an email
Email gives you a little more room to inspect, but the same discipline applies: do not click links or open attachments from an alert you did not expect.
Two things are worth a calm look. First, the actual sender address, not the display name. Display names are trivial to fake; the address behind them is harder to disguise, though not impossible, so a wrong address is a strong warning but a right-looking one is not proof. Second, generic details, since a mass scam email often lacks anything truly specific to you.
But there is one guaranteed red flag that overrides everything else: any email asking you to provide a one-time code, password, or full card number, whether by replying, entering it on a linked page, or reading it to someone. A real bank does not collect those from you by email. That request alone is enough to delete the message and, if you want to be sure, call the number on your card.
“But they knew my account details”
This is the moment that fools careful people, so it deserves a plain answer. A scammer knowing your name, part of your card number, or a recent transaction does not prove they are your bank. Personal data leaks constantly through breaches at all kinds of companies, and fragments of it are bought, sold, and reused by scammers. Knowing a detail about you is cheap. It is not evidence of who is calling.
So flip the logic. Instead of asking “how would a stranger know that?”, assume a stranger might, and verify anyway. The callback still settles it. Real bank, real number, real conversation. Anything else, and you have lost nothing by checking.
This is also why smart, educated people fall for these scams. It is not about being gullible. It is a designed sequence, a real-looking number, a real fear, a helpful-sounding fix, aimed at the few seconds before you think to verify. Recognizing the machine is the defense, not assuming you are too sharp to be targeted.
What to do next, whichever channel it was
- Call your bank on the number on your card and report the contact, even if you did not act on it. It helps them flag the pattern.
- If you clicked a link, shared any detail, moved money, or read back a code, treat it as urgent. Contact your bank immediately and change the password for that account from a device you trust.
- Report the scam to the right authority for your country so it enters the data that helps others. Our guide on where to report financial fraud lists the reporting bodies, including the FTC and FBI IC3 in the US, Action Fraud in the UK, and their equivalents elsewhere.
For the bigger picture, bank impersonation is one specific case of a wider set of patterns. See our pillar guide, how to protect yourself from financial fraud online, for the full framework.
You can read more about who we are and why we write this way on our about page.
Frequently asked questions
Can scammers really make my bank’s real phone number show up?
Yes. Caller ID and text sender names can be faked, a technique called spoofing. Your phone can display your bank’s genuine number while a scammer is on the line, so a familiar number on the screen is never proof the contact is real.
Will my bank ever ask for my PIN, password, or a one-time code?
No. A legitimate bank will never ask you to share a full password, PIN, or a one-time verification code, whether by phone, text, or email. Anyone who asks for those is running a scam, and that request alone is enough to end the conversation.
What if they tell me to move my money to a “safe account”?
Stop immediately. No real bank asks you to transfer your money to a new or “safe” account to protect it. That account belongs to the scammer. Hang up and call your bank on the number on your card to check.
How do I know if a bank text is real?
Do not judge it by the message. Do not tap any link inside it. Instead, open your banking app yourself or call the number on your card. A real alert will still be there when you check independently, and a legitimate bank will never require you to reply with a code or password.
I already gave them information. What now?
Act quickly. Contact your bank right away using the number on your card, change the password for the affected account from a device you trust, and report the incident to your country’s fraud authority. Fast action gives your bank the best chance to limit any damage.