Skip to main content
My Consumer Finance

Fake loan-approval texts and phishing links

How to spot fake loan-approval texts and phishing links that push upfront fees, remote-access apps, or credential theft.

A text that says “You’re pre-approved for $5,000–$35,000—tap to claim” is one of the most common consumer-finance phishing patterns. Real lenders (SoFi, LightStream, Discover, a local credit union, or your bank’s loan desk) do not need you to tap a random short link from an unknown number to “unlock” money you never applied for.

Broader phishing patterns: Phishing and account takeover. Upfront-fee variants: Advance-fee loan scams. Landscape: Credit and debt scams.

Common script

  1. Cold SMS or iMessage: “Final notice: your loan is approved.”
  2. Link to a page that clones a bank or “federal relief” logo.
  3. Form harvests SSN, driver’s license, debit card, or one-time codes.
  4. Optional twist: “Pay a $99–$499 insurance / processing fee” by gift card, crypto, or wire before funding.
  5. Optional twist: download a remote-access app so “underwriting” can “verify your device.”

Related alert clones: Fake bank and brokerage alerts.

Red flags

TellWhy it matters
You did not apply or soft-prequalifyReal approvals follow an application you started
Guaranteed approval / “no credit check” + urgencyUnderwriting is not a countdown timer
Shortened links or misspelled domainsCredential and malware delivery
Upfront fee before any depositClassic advance-fee pattern
Asks for gift cards, crypto, or wire to a personPayment rails scammers prefer
Caller demands a one-time code aloudAccount takeover in progress

Legitimate shopping still uses soft prequalification and clear APR disclosures (How to compare personal loan offers; Hard vs soft credit checks).

Worked example

Sam gets a text: “Chase Loan Center: Your $12,000 personal loan is ready. Confirm within 2 hours: bit.ly/…”. Sam does not bank loan applications by bit.ly. He opens the official Chase app from the phone home screen (not the text link). No loan offer exists. He deletes the text, reports the number as junk/spam, and does not call any number inside the message.

If Sam had tapped the link and entered a debit PIN, he would freeze cards, change passwords on a different device, and follow takeover steps in Phishing and account takeover, plus consider freezes at Equifax, Experian, and TransUnion (Credit freezes and fraud alerts).

What to do instead

  • Apply only through the official app/site of a bank, credit union, or lender you chose.
  • Prefer soft-pull prequalification when comparing APRs.
  • Never pay an “insurance fee” before funds arrive in your account.
  • Verify customer-support numbers from the official site, not the text (Fake customer support phone numbers).

Checklist

  1. Ignore tap-to-claim loan texts you did not invite.
  2. Open lenders only from the official app or typed URL.
  3. Treat upfront fees and gift-card payments as scams.
  4. Never share one-time codes or install remote-access apps for “underwriting.”
  5. Report spam and, if you interacted, monitor bank and bureau activity.
  6. Shop real offers with written APR, fees, and soft-vs-hard disclosure.

Educational only. Not legal, fraud-recovery, or credit advice. Report active scams to the FTC and your bank’s fraud line.