A text or email that says “Unusual sign-in—call us now” or “Your Chase / Bank of America / Wells Fargo / Capital One account is locked” is one of the highest-converting fraud templates. The goal is a callback scam: you dial the number in the message, reach a thief, and read a one-time passcode or approve a remote session. Broader patterns: Phishing and account takeover, Fake bank and brokerage alerts, and Credit and debt scams.
The same “read the code” script shows up as fake Apple Pay / Google Pay support: Fake Apple Pay or Google Pay scams.
How the callback play works
- You get an SMS, email, or spoofed caller ID that looks like your bank.
- The message includes a phone number or short link—not a prompt to open the official app yourself.
- You call. The “agent” already knows your name or last four digits (scraped or guessed).
- They ask you to “verify” with an SMS code, authenticator code, or screen-share app.
- With that code, they drain Zelle, move wires, or take over online banking.
Real fraud teams at major banks do contact customers, but safe practice is still: hang up, open the official app or dial the number on the back of the card / from the bank’s website you typed yourself. Fake support numbers: Fake customer support phone numbers.
Tells that the “security alert” is fake
| Tell | Why it matters |
|---|---|
| Number to dial is inside the text/email | Real apps prefer in-app secure chat or the printed card number |
| Urgency + threat (“seize in 15 minutes”) | Skips slow thinking |
| Asks for full password and one-time code | Codes are for you logging in—not for a caller |
| Spoofed caller ID matches the bank | Easy to fake; does not prove identity |
| “Refund” or “tax” crossover pitch | Same playbook as fake IRS scams and fake tax refund emails |
| Gift cards or crypto to “unlock” the account | Never a bank policy |
Worked example
Priya gets a text: “BofA Security: login from Texas. Call 1-888-555-0142 immediately.” She almost dials. Instead she opens the Bank of America app from her home screen. No alert. She deletes the text and reports it in-app.
Her coworker Raj dials a similar “Wells Fargo” number, reads a code “so we can cancel the wire,” and loses $2,800 via Zelle before the real fraud line can reverse anything. The difference was one callback.
Safe response in under two minutes
- Do not call the number in the message. Do not tap the link.
- Open the official bank app or type the URL from a statement.
- If nothing is wrong in-app, delete and report phishing.
- If something is wrong, use in-app fraud chat or the number on the card.
- Never read a one-time passcode to anyone who contacted you first.
- Never install remote-access software because a “banker” asked.
Checklist
- Treat any alert that demands an immediate callback as hostile until the official app agrees.
- Dial only numbers from the card, statement, or bank site you navigated to yourself.
- Never share OTP / authenticator codes with callers.
- Screenshot the message, then delete; report inside the real app when available.
- After any code disclosure, change passwords from a clean device and call the real fraud line.
- Teach one household member the “no callback from texts” rule this week.
If the “alert” becomes a refund or remote-access script, see Fake tech-support refund scams.
Phone-verification and Google Voice fee impersonation (codes and gift-card “unlocks”) is a sibling callback trap: Fake Google Voice verification scams.
Apple/iCloud storage-full phish that layers a fake bank callback: Fake iCloud storage-full scams.
Educational only. Not legal, security, or fraud-recovery advice. Tactics change; verify contacts through official apps and statements.