What is changing now
The current pattern.
Current warnings describe criminals impersonating financial-institution support by text, email and phone. They may know real personal details, spoof caller ID, reference a genuine transaction or send a copied fraud-reporting page before requesting credentials or a transfer.
How it works
Confidence first, then pressure.
The contact opens with a believable threat: a suspicious payment, hacked account, expiring card or urgent security investigation. The scammer may already know your name, address, bank or partial account information from stolen or commercially available data.
They offer immediate protection, but the proposed solution gives them control. Common requests include reading out a one-time passcode, installing remote-access software, approving a notification, adding a new payee or moving money to a supposedly safe account.
Caller ID and text-message threads can be spoofed or misleading. A real-looking contact channel does not change the safest response: stop and initiate a new contact through the bank’s established route.
Worked example
A realistic pattern, separated into evidence.
This composite example is educational. It does not describe a real person or reproduce a live malicious message.
The fraud team offers a ‘safe account’
- 01The opening
A caller says a card payment was blocked and correctly names the bank and part of the account holder’s address. The displayed caller ID matches the number printed on the bank card.
- 02The escalation
The caller says an employee may be involved, so branch staff cannot be trusted. They ask the customer to move the balance to a newly created account and approve a mobile-banking notification while staying on the line.
- 03The decision point
Knowledge of personal data and a familiar caller ID increase confidence but do not authenticate the call. The instruction to move money, conceal the conversation and approve access is the controlling evidence.
Warning signs
Reasons to stop and verify.
- A caller asks for a one-time password, PIN, full password or card security code
- Instructions to transfer money to protect it, reverse fraud or help an investigation
- A request to install screen-sharing or remote-access software
- Pressure to keep the call secret from bank staff, relatives or police
- A warning not to hang up or a claim that delay will make you liable
- Contact details supplied in the warning instead of the bank’s normal channels
Independent verification
Test the request without using its evidence.
These checks deliberately move the decision away from the person, link, number or account that introduced the request.
- 01
Break the live call
Do not let the caller keep control of the pace. End the call even if they claim that disconnecting will make you liable or stop an investigation.
- 02
Open a trusted banking route
Use the official app, a saved bookmark, a recent statement or the number printed on the physical card. Avoid paid search advertisements and message links.
- 03
Describe, do not repeat, the instruction
Tell the real bank that a caller requested a code, approval, new payee or transfer. Do not carry out the action merely to let staff observe it.
- 04
Review account-control changes
Check contact details, devices, payees, cards and recent transactions. A scam may aim at account access even when no transfer has completed.
Safer response
Move the decision outside the contact.
- 01
End the conversation
Hang up even if the caller says the account is in immediate danger. Do not call a number from the message or a paid search advertisement.
- 02
Contact the real bank
Use the official app, the number on your physical card or a recent statement. Explain that you received an impersonation attempt.
- 03
Review rather than transfer
Check recent activity inside the real account. A legitimate fraud team can secure an account without asking you to move money to a stranger’s instructions.
- 04
Keep codes private
A code proves control of your account. Do not read it to anyone who contacted you, regardless of the story they give.
If you already acted
Protect access and contact the real provider.
- Call the bank immediately and ask for its fraud team; speed can affect recovery options.
- Ask the bank to review new payees, transfers, cards, devices and changed contact details.
- Change exposed banking and email passwords from a trusted device.
- Remove remote-access software and seek trusted technical help before using the device for banking again.
- Report the impersonation through the bank’s official channel and the relevant authority where you live.
Sources
Official guidance used for this article.
Stop & Verify summarises these sources for general education. Reporting routes and legal protections vary by location.