Skip to main content

Fake bank calls (vishing): how to spot one in ten seconds

Published September 16, 2026 Β· Updated September 16, 2026 Β· 6 min read

Quick answer

A real bank never asks for the code you received by SMS, never asks you to install a remote-access app, and never moves your money to a "safe account". If a call asks for any of those three, it is fraud β€” hang up and call the number printed on the back of your card.

Vishing is a phone call that impersonates your bank. It is not a clumsy scam: the caller usually knows your full name, sometimes the last four digits of your card, and speaks with the calm authority of someone reading from a script. The caller ID can show your bank's real number, because the number is not verified by the telephone network.

The entire call exists to obtain one short string of digits β€” the one-time password your bank sends by SMS. With it, an attacker can approve a transfer or add a payee to your account without ever holding your card.

How the call is built

  1. A recording or a synthetic voice announces "a suspicious transaction" on your account.
  2. You are told the transaction can be stopped, but only now, on this call.
  3. You are asked to confirm your identity β€” in practice, to read out the SMS code that has just arrived.
  4. If you hesitate, you are handed to a "supervisor" or to a "fraud department" colleague who is simply the next person in the same room.
  5. Failing a code, the caller asks you to install a remote-support app so an "operator" can secure your device β€” which actually hands over the phone.

The four tells that give it away

  • Urgency that removes your options: "if we hang up now, the money is gone".
  • Any request for an SMS code or a card PIN. Your bank already has both β€” it does not need to hear them.
  • A request to install software you did not go looking for: AnyDesk, TeamViewer, QuickSupport, a "security certificate", or an APK file sent by message.
  • Instructions to keep the call secret from family or bank staff, or to move money to a "safe account" that belongs to you. No such account exists.

Spoofed numbers and why they prove nothing

Caller ID is a field in the signalling data, not a fact. For a few euro a month, fraud platforms let a caller set any number they like, including your bank's published support line. Calling that number back after a suspicious call is useful only if you dial it yourself on a different handset or after a few minutes β€” a line kept open by the fraudster still routes to their own call centre.

The same goes for the messages that follow the call: a link to your bank's domain can be a look-alike with a swapped character, and a genuine-looking PDF on bank letterhead is a file printed from Microsoft Word.

What to do if you already answered

  1. Hang up. Do not explain, do not argue, do not wait for the supervisor.
  2. Call your bank from the number on the back of your card and ask for the card to be blocked.
  3. Change the password on your internet banking and revoke any payee or standing order you do not recognise, including "beneficiaries" you never added.
  4. If you installed an app, uninstall it, then review which apps hold accessibility or notification-listener permissions β€” that access is what lets a remote tool read your SMS codes.
  5. Report it: to your bank's fraud line the same day, and to the police (in Romania, a report at any police station or online) if money left the account. A same-day report is what makes a refund request realistic.

Check the number before you trust it

Paste the number that called you into the BaitScan phone checker to see the pattern behind it β€” premium ranges, number ranges used only by short-lived SIMs, and formats that banks do not call from. If a message accompanied the call, the link checker shows where the link really points before you open it.

Frequently asked questions

The questions this article gets asked most, answered directly.

Can a fraudster really call from my bank's own number?

Yes. The calling number is supplied by the caller and is not verified end to end, so it can be set to anything β€” including the bank's real support line. Treat the displayed number as a suggestion, never as proof of identity.

The caller knew my name and my card's last digits. Am I compromised?

No β€” that data is widely available after old data breaches and from leaked databases sold online. It is used to sound convincing, not to prove access. What matters is that you never read out a code or install an app.

I read the code out. What happens now?

Assume the attacker can authorise one transaction or add a payee immediately. Call your bank, block the card, change the internet banking password, then report. Under PSD2 you may be liable for unauthorised payments made before you notified the bank, which is why notifying the same day matters.

Should I call the number back to check?

Only by dialling your bank's published number yourself. Calling back the number that just called you reconnects you to the same operation β€” the line is theirs, not the bank's.

Written by The BaitScan editorial team

Results are automated risk estimates based on public indicators and heuristics.