Skip to main content

Scam reference

Someone claiming to be your bank

A caller, message or page poses as your bank and invents an emergency. The goal is a transfer you authorise yourself.

The story always involves urgency and a reason you cannot simply hang up: a fraudulent transaction in progress, a compromised card, a colleague who needs you to confirm something in the next two minutes.

The distinguishing feature is that the payment is made by you, with your own credentials and your own confirmation. That is why the money becomes very hard to recover.

The three shapes it takes

  • A phone call. The number on your screen matches your bank's, because caller ID is easy to forge.
  • A text message with a link to a page that copies your bank's login screen.
  • A screen-share session. The caller asks you to install remote-support software to 'fix' the problem, then watches you log in.

What a real bank never does

  • Asks for your full PIN, your password, or a one-time code you just received. Those exist to prove that you are you, and sharing one destroys that guarantee.
  • Asks you to move money to a 'safe account', a 'reserve account' or an account in your own name at another bank.
  • Asks you to install remote-access software.
  • Keeps you on the line while you log in, or tells you not to discuss the call with anyone — including staff in a branch.

If it is happening now

  1. 1Hang up. A real bank will call back, and you can always dial the number printed on your card.
  2. 2If money has left, call the bank's emergency number immediately — the faster a transfer is flagged, the better the chance of a recall.
  3. 3Reset your online-banking password from a device you own, and check for a new payee you did not add.
  4. 4Change the password anywhere you reused the same one.
  5. 5Report the number and the message to your bank and to the national fraud reporting service for your country.

Frequently asked questions

The caller knew my name, my address and part of my card number. How?

Those details circulate after data breaches and are traded long before they are used. Knowing them proves that the caller has data about you, not that the caller is the bank.

The number on my screen was my bank's real number. Does that prove anything?

No. Displayed caller numbers can be set to anything. Treat the caller ID as decoration, and judge the request by what is being asked for.

I authorised the transfer myself. Can I get the money back?

It is harder, and the outcome depends on your bank and your country's rules for authorised push payments. Report it the same day, in writing, and keep every reference number you are given.

Written by The BaitScan team

Last updated September 16, 2026

Results are automated risk estimates based on public indicators and heuristics.