Fake fraud alerts, margin calls, wire notices, and new-device logins are among the highest-converting phishing templates. Parallel “loan approved—tap here” SMS: Fake loan approval texts. They clone Chase, Bank of America, Wells Fargo, Capital One, Fidelity, Schwab, Vanguard, E*TRADE, and Robinhood logos, then ask you to “verify,” “unlock,” or “speak to security.” Broader patterns: Phishing and account takeover and Credit and debt scams.
Tells that the alert is fake
| Tell | Why it matters |
|---|---|
Short link in SMS (bit.ly, odd .ru / lookalike domains) | Real apps rarely need you to authenticate via a random URL |
| Urgency + threat (“account seized in 15 minutes”) | Designed to skip your slow-thinking check |
| Asks for full password and SMS/authenticator code | Codes are for you logging in—not for a caller |
| Caller ID matches your bank but voice asks you to dial a different number | Spoofed ID is easy—Fake support numbers |
| Brokerage “margin call” when you do not use margin | Fear prompt; confirm inside the official app |
| Attachment or QR “to secure your account” | Common malware / session-theft path |
Gift-card or crypto “verification” is never a bank or broker policy—see Gift card payment scams.
Safe response in under two minutes
- Do not tap the link or QR.
- Open the official app from your phone home screen (or type the URL from the card / statement).
- If nothing is wrong in-app, delete the message and report phishing in the app when available.
- If something is wrong in-app, use the in-app fraud chat or the number on the back of the card / from the firm’s official site—not the number in the text.
- Never read a one-time passcode to anyone who called you.
Zelle / P2P pressure inside a “fraud fix” is a common second act: Zelle and P2P payment scams.
Worked example: the “Schwab wire” text
Alex gets: “Schwab Alert: Wire for $9,400 to new payee pending. Cancel: https://schwab-secure-review.com/…”. Alex has never wired that amount.
Alex ignores the link, opens the official Schwab app, and sees no pending wire. Alex deletes the text. Cost of the correct path: ~45 seconds. Cost of tapping and entering the SMS code: full brokerage takeover risk.
If the app had shown a strange payee, Alex would freeze transfers in-app, call Schwab using the number from the official site, change the password from a known-clean device, and review email recovery settings.
After a real breach or leaked password
Unexpected alerts increase after credential leaks. Harden logins and freezes using Account takeover after a data breach and Credit freezes and fraud alerts. Turn on real bank/brokerage alerts in the official app so you learn what legitimate messages look like. Bureau and score-app pushes need a different calm checklist: Credit monitoring alerts.
Checklist
- Treat every unexpected “alert” link as hostile until the official app agrees.
- Never share one-time codes with callers or chat widgets from ads.
- Bookmark bank and brokerage sites; avoid search-ad lookalikes when panicked.
- Verify support numbers from the card, statement, or official site (Fake support numbers).
- Enable MFA on email first—reset links go there.
- Report phishing to the institution and delete the message.
Educational only. Not legal, security, or fraud-recovery advice. Tactics change; verify through official apps and statements only.