A message lands that looks like it is from your bank. There is a problem with your account, a payment has been flagged, or someone has tried to log in. It asks you to tap a link, call a number, or read back a code. Most of the time, a few seconds of skepticism are all it takes to tell a genuine alert from a fake one, as long as you know what to look for.
Scammers use the same playbook across every channel. When it arrives by email, it is called phishing. By text message, it is often called smishing. By phone, it is usually described as an impersonation or imposter scam. The tools differ, but the tactics are remarkably consistent.
The stories scammers tell
The FTC lists the stories that phishing emails and texts typically use. Scammers may claim they have "noticed some suspicious activity or log-in attempts," that there is "a problem with your account or your payment information," or that you need to confirm personal details. Generic greetings, fake invoices and warnings that an account is on hold are all common.
What these stories share is that they give you a reason to act before you think. CISA describes the same warning sign in its phishing guidance: "urgent or emotionally appealing language, especially messages that claim dire consequences."
The FTC's guidance on phone scams makes the contrast clear: "Most honest businesses will give you time to think their offer over and get written information about it before you commit." A message that insists you act in the next few minutes is giving you the clearest signal it can.
Why the sender name and number prove nothing
It is natural to trust a message that shows your bank's name, or a call that displays its real phone number. Unfortunately, those details are easy to fake.
The FTC puts it bluntly: "Scammers can make any name or number show up on your caller ID. That's called spoofing." The same is true of the display name on an email, which the sender can set to anything they like. CISA advises looking closely at the actual address and links, and gives the example of an address like "amazan.com" in place of the real thing.
CISA also notes that AI tools now help scammers write messages with perfect grammar, so tidy spelling is no longer a reliable sign that a message is genuine. Focus on the request being made, not on how polished it looks.
Inspecting links without clicking them
Links are where most phishing attacks do their damage, leading to a fake login page or a download. The FTC notes that legitimate companies "won't email or text with a link to update your payment information." That alone rules out a large share of fake bank messages.
A few checks before you tap anything:
- Look for lookalike spellings. Swapped or extra letters, added words or unusual endings in the address are warning signs.
- Be wary of shortened links. CISA lists "untrusted shortened URLs" among its phishing signs, because they hide where you are being taken.
- Watch for generic greetings. The FTC flags a "generic greeting" as a common feature of phishing.
- When in doubt, go the long way round. Instead of using the link, open your bank's app, or type its web address yourself, and check for any alerts there.
What your bank will never ask for
Two requests should end any conversation immediately, however convincing the caller or message seems.
Your one-time verification codes
The codes your bank sends by text or shows in an app exist to prove you are you. The FTC explains why sharing them is so dangerous: "If you share that code, the scammer can use it to prove they're you." Its guidance is unambiguous: "No caller — especially someone from your bank or investment company's fraud department — will ever ask for the verification code. That's always a scam."
The same reasoning applies to your password and PIN: they are the keys to your account, and they are for you alone.
Moving your money to "protect" it
One of the most damaging versions of the scam starts with a warning that your account has been compromised, and ends with a request to transfer your savings to a "safe" account. The FTC is direct about this: "Never move or transfer your money to 'protect it.' Your money is fine where it is."
The FTC adds that these scammers often sound credible and may already know personal details about you. If you are asked to send money by wire, gift card, cryptocurrency or a payment app, treat that as a red flag. The FTC notes that "anyone who insists that you can only pay that way is a scammer," and it warns that if you are tricked into moving money out of your own account, you may not get it back.
A real fraud team protects your money where it is; only a scammer needs you to move it.
How to check if a message is real
You do not need to work out whether a message is fake to stay safe. You only need to avoid using the contact details it gives you.
- Stop. Do not click, reply, call back or share anything from the message itself.
- Contact your bank independently. The FTC recommends contacting your bank using the number on your account statement, never one the caller or message gives you. For apps and websites, use the official app or type the address yourself.
- Ask whether the alert is genuine. If there really is a problem, the bank will be able to tell you through its own channels.
How to report a fake
Reporting takes a minute and helps protect other people. The official channels are:
- Spam texts: Copy the message and forward it to 7726 (which spells SPAM), as the FTC advises. You can also use your messaging app's "report junk" or spam option.
- Phishing emails: Forward them to reportphishing@apwg.org, and use your email provider's report-spam button.
- Any scam attempt: Tell the FTC at ReportFraud.ftc.gov.
- Online crime and losses: File a complaint with the FBI's Internet Crime Complaint Center at ic3.gov. The FBI describes IC3 as "the central hub for reporting cyber-enabled crime" and encourages people to file even if they are unsure whether their complaint qualifies.
The habit that beats almost every scam
Every fake bank message is trying to make you do one thing: act on its terms, through its link or its phone number, before you have time to check. The best defence is a habit rather than a skill. Slow down, never share a code, never move money because a message told you to, and reach your bank through a route you chose yourself.