Is that fraud-alert call from my bank a scam?
If the caller asks you to read out a code, share your password, or move money to a 'safe account,' yes — hang up and call the number on your card. Real fraud departments never ask for any of those.
The call opens exactly like the real thing: caller ID shows your bank's actual number, and a calm 'fraud department agent' — increasingly an AI-generated voice, unhurried and accent-perfect — reads off a suspicious charge and asks if you authorized it. You didn't, of course, because the charge is invented. Now that you're alarmed and grateful someone caught it, the 'agent' gets to work: to reverse the charge they need to 'verify' you with the one-time passcode your bank just texted, or your online-banking password, or — the expensive ending — your balance needs to move to a 'safe account' while they investigate.
Every one of those asks is theft in progress. The texted code is your bank's own login or payment authorization — read it out and the scammer, who triggered it by attempting a login with your leaked credentials, walks straight into your account. The 'safe account' is theirs, and money you transfer yourself is the hardest fraud to reverse. AI has sharpened the con at both ends: cloned voices make call centers sound native and unflappable, and some crews now clone customers' own voices from social-media clips to beat banks' voice-ID systems. Caller ID proves nothing — spoofing it costs nothing.
How does the scam work?
- 01
A spoofed number and a fake charge open the door
Caller ID showing your bank's real number is trivial to fake. The invented charge does two jobs: it makes the call urgent, and it casts the scammer as your protector — so your guard drops exactly when it should rise.
- 02
The 'verification' is the theft
While you're on the line, the scammer is on your bank's website with credentials from a data breach. The login triggers a real one-time passcode to your phone. When you read it back 'to verify your identity,' you hand over the last key to your own account.
- 03
The 'safe account' finishes the job
The escalated version: your money is 'at risk' and must move to a secure holding account — sometimes with a texted link to a 'secure transfer portal.' Because you authorize the transfer yourself, banks often treat it as an authorized push payment, making recovery painfully hard.
- 04
AI voices scale it, and sometimes clone yours
Voice cloning lets one crew run flawless, patient 'agents' around the clock in any accent. Some operations also harvest seconds of your voice — from a call where you just say 'yes, speaking' — to attack voice-authentication systems later. Treat any unsolicited voice, however natural, as unverified.
What are the red flags to check?
They ask for a one-time passcode
This is the brightest line in banking: no bank's fraud department will ever ask you to read back a code they texted you. The codes exist to stop the person on the phone. Any request for one is the scam, full stop.
You're asked to move money to 'protect' it
Banks secure compromised accounts by freezing cards and reversing charges — never by having you wire funds to another account, buy gift cards, or deposit at a crypto ATM. A 'safe account' is the scammer's account.
The caller wants your password, PIN, or card CVV
Your bank already has whatever it needs and asks for none of these on a call it made. Anyone requesting them is impersonating, however perfect the hold music and phone tree sound.
Pressure to stay on the line and act now
"Don't hang up — the money leaves in minutes" exists to stop the one move that kills the con: calling your bank back yourself. Real fraud teams block first, at their end, and are happy for you to call the number on your card.
A texted 'secure portal' link mid-call
Banks don't text login or transfer links during fraud calls. A mid-call link to a 'verification' or 'secure transfer' page is a phishing site — and its days-old domain will say so.
Unsure even after checking these? That’s exactly what the $2 Instant URL Check is for — paste the link and get a researched verdict with evidence, instead of guessing.
What should you do right now?
- Hang up — even if caller ID shows your bank and the agent sounds flawless. Politeness is how these calls succeed; ending them is always safe.
- Call back yourself using the number printed on your card or shown inside your banking app. If there's a real fraud alert, it will be waiting in your account.
- Never read out a texted code, share a password or PIN, or transfer money on the instructions of an inbound caller — no exceptions, no matter the story.
- If you already shared a code or moved money, call your bank's real fraud line immediately, change your online-banking password, and report at reportfraud.ftc.gov and ic3.gov. Minutes matter for transfer recalls.
What the check does: a one-time, researched risk report on the URL you paste. What it doesn’t do: continuous monitoring, takedowns, fund recovery, or legal advice — and we’ll never pretend otherwise.
Not ready to check a link yet?
Get this guide's red-flag checklist by email.
We'll send you the red flags and the 3-step plan from this page, so it's in your inbox the moment a suspicious text actually arrives.
One email, no spam, no subscription — that’s the whole deal.