How to tell if a text from your bank is a scam
You’re carrying groceries when your phone buzzes. Your bank says an $842.19 transfer is waiting, and you have ten minutes to stop it.
I spend time around the DEF CON crowd every year, and the social-engineering demos there keep teaching the same lesson the hacker community already knows: the best scams don’t beat technology first. They borrow trust, add pressure, and get you to act before you step outside their story.
That odd amount and short clock aren’t decoration. They’re controls. One makes the problem feel real; the other keeps you from checking it safely.
Here’s the move I’d teach my mom: leave the bank text scam alone and open the bank’s official app yourself. You don’t need to outsmart the message. You just need to leave the path its sender built for you.
The 5-minute version
- Don’t tap the link, call the number, or reply.
- Open the bank app you already use. Don’t open it through the text.
- Check recent activity and alerts inside the app.
- If anything looks wrong, call the number on the back of your card.
- Use your phone’s built-in Report Junk or Report Spam option, then delete the text.
Start outside the text
A scammer wants to keep you inside the message: read this claim, tap this link, call this number. In security, that’s an attacker-controlled path. In plain English, they picked every signpost.
A real-looking logo, familiar wording, or local phone number doesn’t prove who sent the text. Neither does a message appearing beside earlier bank alerts. Those details can feel reassuring, which is why scammers use them.
You don’t have to inspect any of that. Step off their path and use one you already trust.
Default answer: close the text and open your bank’s official app. If you don’t use the app, type the bank’s web address yourself or call the number printed on your card.
Don’t use a phone number or website supplied by the suspicious message. That includes a number a supposed “fraud agent” sends next. The second message is still part of the same path.
🟢 Relax: You received the text but didn’t tap, call, reply, or share anything. Report it and delete it.
Scam anatomy
Here’s a realistic example. The bank name and web address are fictional.
FIRST NATIONAL ALERT: $842.19 transfer pending.
Not you? Verify now:
https://firstnational-secure.example/stopFailure to respond in 10 minutes will lock your account.
Line 1 — “$842.19 transfer pending.”
An attacker chooses a precise amount because $842.19 looks like a record, while “a large transfer” sounds like bait. Your brain gets a concrete problem to solve. The number may look official, but it proves nothing by itself.
Line 2 — “Verify now” plus a link.
The link keeps you on the attacker’s route. “Verify” may lead to a fake sign-in page built to collect your username, password, card details, or security code. It doesn’t need to fool you for long. It only needs one entry and one tap.
Line 3 — “10 minutes” and an account lock.
The short deadline is there to prevent a second thought. Attackers know pressure narrows your choices: tap now feels faster than finding your card. A real fraud alert can be urgent, but you can still check it through the official app or the number on your card.
Those are the three tells: a believable problem, a route controlled by the sender, and pressure to act before you check. Once you see the design, the text gets much less impressive.
What if the text knows my name or bank?
Treat it the same way. Personal details make the story more believable, not the sender more trustworthy.
Your name, phone number, and bank may have come from old marketing lists, public records, stolen data, or a lucky guess. To an attacker, those details are props. You don’t need to work out where they came from. Open the bank app yourself.
🟢 Relax: A stranger knowing your name or bank isn’t proof that your account is open to them. Check the app, then move on if the account looks normal.
What if there really is a strange charge?
Call your bank using the number on the back of your card. Tell the representative you found the transaction in the official app, not just in a text.
Don’t move money to a “safe account.” Don’t share a one-time security code. That code proves possession of your phone during an action you started. A caller asking for it may be trying to finish a sign-in or transfer you didn’t start.
🔴 Today: An unfamiliar charge, transfer, or newly added payee appears inside your real bank account. Contact the bank now through a trusted number.
What if I already tapped the link?
No shame. These messages are engineered for a fast reaction, and everyone has hurried through the wrong screen before.
If you only opened the page and entered nothing, close it. Don’t download anything it offers. Check your bank through the official app.
🟢 Relax: You opened the page, entered nothing, downloaded nothing, and approved nothing. Close it, report the text, and check your account.
If you entered a bank password, card number, personal identification number, or one-time code, call the bank using the number on your card. Ask it to lock down the account and review recent activity. Then change the bank password through the official app or website. If you reused that password elsewhere, change those accounts too, starting with your email.
🔴 Today: You entered account details, shared a security code, approved a sign-in, or downloaded an app the message requested. Contact the bank immediately through a trusted number.
If money has already moved, tell the bank exactly what happened. Save the text and transaction details until the bank says it no longer needs them.
🔴 Today: Money left the account or you approved a transfer after speaking with the sender. Call the bank now.
Should I reply STOP?
No. For a suspicious bank message, don’t reply at all. STOP is useful for a legitimate mailing list you recognize. A scammer doesn’t need your unsubscribe request.
Use the reporting control built into your phone instead. The Federal Trade Commission also says you can forward unwanted texts to 7726, which spells SPAM on a phone keypad.
🟢 Relax: Reporting and deleting a text you didn’t interact with is enough.
Can I trust a fraud-alert text from my bank?
A bank may send real fraud alerts. You still don’t need to trust the text itself.
Treat the message as a reason to check, not a place to act. This is the defender’s advantage: you choose a trusted route, while the scammer loses control of the conversation. Open the app independently. That rule works whether the text is real, fake, polished, or full of spelling mistakes.
What I’d do
I’d leave the message untouched and open my bank app. If I saw anything unfamiliar, I’d call the number on my card; otherwise, I’d report and delete the text. My one action for you: open the bank app yourself, never through the message.
Where this goes deeper
The bank text scam is one pattern inside a bigger one: someone borrows trust you already handed to somebody else. The handful of habits that block most of these — including the ones aimed at your email and your phone — are the subject of my book, Cybersecurity for Normal People.
Research & sources
- Federal Trade Commission, “How to Recognize and Report Spam Text Messages”: https://consumer.ftc.gov/articles/how-recognize-and-report-spam-text-messages
- Federal Trade Commission, “How To Recognize and Avoid Phishing Scams”: https://consumer.ftc.gov/articles/how-recognize-and-avoid-phishing-scams
- Consumer Financial Protection Bureau, “I received an email and text from my bank or credit union asking me to ‘verify’ my account information. What should I do?”: https://www.consumerfinance.gov/ask-cfpb/i-received-an-email-from-my-bank-or-credit-union-asking-me-to-verify-my-account-information-what-should-i-do-en-999/
Publish log
- 2026-08-10: Draft completed and moved to editing.