Skip to main content
My Consumer Finance

Fake bank security alerts and callback scams

Fake bank security alerts and callback scams: how Chase, Bank of America, and Wells Fargo impersonators push you to call a fake number or read a one-time code.

A text or email that says “Unusual sign-in—call us now” or “Your Chase / Bank of America / Wells Fargo / Capital One account is locked” is one of the highest-converting fraud templates. The goal is a callback scam: you dial the number in the message, reach a thief, and read a one-time passcode or approve a remote session. Broader patterns: Phishing and account takeover, Fake bank and brokerage alerts, and Credit and debt scams.

The same “read the code” script shows up as fake Apple Pay / Google Pay support: Fake Apple Pay or Google Pay scams.

How the callback play works

  1. You get an SMS, email, or spoofed caller ID that looks like your bank.
  2. The message includes a phone number or short link—not a prompt to open the official app yourself.
  3. You call. The “agent” already knows your name or last four digits (scraped or guessed).
  4. They ask you to “verify” with an SMS code, authenticator code, or screen-share app.
  5. With that code, they drain Zelle, move wires, or take over online banking.

Real fraud teams at major banks do contact customers, but safe practice is still: hang up, open the official app or dial the number on the back of the card / from the bank’s website you typed yourself. Fake support numbers: Fake customer support phone numbers.

Tells that the “security alert” is fake

TellWhy it matters
Number to dial is inside the text/emailReal apps prefer in-app secure chat or the printed card number
Urgency + threat (“seize in 15 minutes”)Skips slow thinking
Asks for full password and one-time codeCodes are for you logging in—not for a caller
Spoofed caller ID matches the bankEasy to fake; does not prove identity
“Refund” or “tax” crossover pitchSame playbook as fake IRS scams and fake tax refund emails
Gift cards or crypto to “unlock” the accountNever a bank policy

Worked example

Priya gets a text: “BofA Security: login from Texas. Call 1-888-555-0142 immediately.” She almost dials. Instead she opens the Bank of America app from her home screen. No alert. She deletes the text and reports it in-app.

Her coworker Raj dials a similar “Wells Fargo” number, reads a code “so we can cancel the wire,” and loses $2,800 via Zelle before the real fraud line can reverse anything. The difference was one callback.

Safe response in under two minutes

  1. Do not call the number in the message. Do not tap the link.
  2. Open the official bank app or type the URL from a statement.
  3. If nothing is wrong in-app, delete and report phishing.
  4. If something is wrong, use in-app fraud chat or the number on the card.
  5. Never read a one-time passcode to anyone who contacted you first.
  6. Never install remote-access software because a “banker” asked.

Checklist

  1. Treat any alert that demands an immediate callback as hostile until the official app agrees.
  2. Dial only numbers from the card, statement, or bank site you navigated to yourself.
  3. Never share OTP / authenticator codes with callers.
  4. Screenshot the message, then delete; report inside the real app when available.
  5. After any code disclosure, change passwords from a clean device and call the real fraud line.
  6. Teach one household member the “no callback from texts” rule this week.

If the “alert” becomes a refund or remote-access script, see Fake tech-support refund scams.

Phone-verification and Google Voice fee impersonation (codes and gift-card “unlocks”) is a sibling callback trap: Fake Google Voice verification scams.

Apple/iCloud storage-full phish that layers a fake bank callback: Fake iCloud storage-full scams.

Educational only. Not legal, security, or fraud-recovery advice. Tactics change; verify contacts through official apps and statements.