Table of Contents
- Direct answer: never verify through the message itself
- Why this rule holds even when the message looks completely legitimate
- The out-of-band check: call the number on your card or the number you already have saved, not one from the message
- What a genuine bank message will never ask for
- Short codes and sender names: a useful signal, not proof on their own
- If you already clicked a link or replied
- Frequently asked questions
Direct answer: never verify through the message itself
If you receive a text, email, or push notification claiming to be from your bank, do not tap any link, do not call any number, and do not reply inside that message to verify it, even if it looks completely legitimate. Instead, put the message down and separately open your bank's app or call the number printed on your card or statement.
This one habit, using a channel you already trust instead of one the message hands you, defeats nearly every version of this scam and takes about the same amount of time as clicking would have. This page is the specific action to take once a message is already in front of you; for the broader pattern of banks being impersonated by phone, text, and email, see our guide to bank impersonation scams, and for the wider fraud-prevention picture, our main guide. Bank-branded messages are one of the most common contact methods scammers use precisely because almost everyone has a bank account and expects occasional real messages from it, which is exactly what makes the out-of-band habit worth building once and applying every time.
Why this rule holds even when the message looks completely legitimate
Scammers can spoof a sender's display name or number so a fake text lands in the exact same message thread as your bank's real, past messages, which makes thread placement worthless as a signal. They can also copy a bank's logo, layout, and tone precisely, and in some cases reference a real recent transaction, sometimes pulled from a prior, unrelated data breach, to make the message feel personalized and current. A message that mentions a purchase amount or a city that matches something you actually did recently can feel like proof, but that detail alone only shows the sender has some information about you, not that they work for your bank.
None of this changes what to do. The rule holds regardless of how convincing the message looks, because it is not based on judging the message's appearance; it is based on where you go to verify it. A message that looks perfect and a message full of typos get the identical response.
The out-of-band check: call the number on your card or the number you already have saved, not one from the message
"Out-of-band" simply means verifying through a separate channel that you control, rather than the one the suspicious message provides. It works because a scammer can control everything inside the message they sent you, the number, the link, the reply address, but they cannot control the number printed on your physical card or the app already installed on your phone. In practice:
- Call the number printed on the back of your physical card or on a recent paper or PDF statement.
- Use a number you have saved from a previous, confirmed legitimate interaction with your bank.
- Open your bank's official app directly from your phone's home screen, not via a link, and check its own message or alert center.
- Type your bank's known web address directly into your browser rather than clicking a link or a search result.
Do not use a phone number offered inside the suspicious message itself, even if it is presented as an official "customer service" line. A related trap works the other way around too: searching for a support number online can surface a fake one that outranks the real one, covered in full in our fake support number guide.
What a genuine bank message will never ask for
A real bank message will never ask you to provide, by text, email, or reply, your full card number, your PIN, your online banking password, or a one-time passcode. Banks do sometimes send legitimate alerts about a transaction or ask you to approve a login attempt through their own app's built-in approval flow, but that is a confirmation you initiate inside the app, not a code or password you type back into a message thread. A genuine transaction alert also typically references only the last few digits of a card, never the full number, which is another useful, though not conclusive, difference worth noticing.
If any message, however official it looks, asks you to read a one-time code back to someone or type your password into a page it linked you to, treat that as automatic confirmation of fraud, regardless of anything else about the message.
Short codes and sender names: a useful signal, not proof on their own
Many banks send legitimate texts from a consistent short code, a five- or six-digit number, or a fixed sender name, and checking that against your bank's own published list can be a useful data point. It is not proof by itself, though, because sender names and numbers can be spoofed, and legitimate short codes vary from bank to bank and are not something you can guess or assume. A short code that matches what your bank has published is a mildly reassuring signal; a short code that does not match is a much stronger reason for caution, since scammers rarely bother to spoof one accurately.
Use this as one signal among several, never as the deciding factor on its own, and always pair it with the out-of-band callback above. Text-based impersonation is one channel among several scammers use; our guide to phishing, smishing, and vishing covers how the same underlying tactic shows up by email, text, and phone call.
If you already clicked a link or replied
If you have already tapped a link, entered any login details or card information on the page it led to, or replied with a one-time code, act now rather than waiting to see if anything happens.
- Contact your bank immediately using a number you already trust, from your card, your statement, or the bank's app opened directly, not a number from the message.
- Tell them exactly what happened, including whether you entered a password, a code, or card details, so they can watch for or block suspicious activity.
- Ask about reissuing your card or resetting credentials if you shared anything sensitive.
- Report the incident to your national consumer-protection or fraud-reporting body, separately from contacting your bank.
- Watch your statements closely for the next few weeks, not just the next few days, since a stolen credential is not always used immediately.
None of this means you were careless. These messages are built specifically to be convincing, and falling for one the first time is not a sign you failed to be careful enough.
Frequently asked questions
What if the text comes from the same thread as my bank's real messages?
Sender-name spoofing can place a fake message inside the same conversation thread as genuine past messages from your bank. Thread placement is not proof of authenticity.
Is it safe to call a number that was texted to me if it matches the number on my card?
If you type or dial a number yourself, using the one printed on your card or statement, and it happens to match what was texted, you are fine. The risk is specifically in dialing a number the message displays or a link auto-dials for you.
My bank never texts me, so is any text automatically fake?
Not necessarily, but respond the same way regardless: verify independently before acting, rather than assuming a message is real or fake based only on whether you expected it.
What should I do if I'm unsure whether a request for a one-time code is legitimate?
Never share a one-time passcode with anyone, including someone claiming to be your bank's own staff. A genuine bank employee never needs you to read that code back to them.
Does it matter which app or browser I use to check my account?
Not particularly, as long as you opened it yourself, directly, rather than through a link. The security of the verification comes from choosing the channel independently, not from any specific app or browser.
This page describes a general verification routine; specific app features and message formats vary by bank, so treat your own bank's stated official channels as the final check. Please also read our full Disclaimer. FinMateMastery is not affiliated with any bank or telecom carrier named or described here.