Phishing is a fake message designed to steal a password, one-time code, or remote access. Account takeover is what happens after the thief logs in as you—drains a checking account at Chase or Bank of America, opens a Capital One card, or changes your Equifax login. The pitch often looks like your bank, the IRS, Apple, Amazon, or a credit bureau.
Fake Apple Pay / Google Pay “support” calls that ask you to read a wallet code or add a stranger’s phone: Fake Apple Pay or Google Pay scams.
Broader scam patterns: Credit and debt scams. Fake adjuster / claim-fee texts after a crash or storm: Fake insurance claim scams. After a breach or stolen credentials, lock new credit with Credit freezes and fraud alerts. Fee-first “loan forgiveness” texts that harvest FSA IDs are covered in Fake student loan forgiveness scams.
Tax season spikes fake “refund deposit failed” messages—treat them like any credential harvest: Fake tax refund emails. Carrier “relabel / postage due” QR texts are the shipping twin: Fake shipping labels and QR scams.
Common phishing channels
Celebrity livestream “crypto giveaways” that ask you to send coins first are a sibling pitch: Fake cryptocurrency giveaway scams.
| Channel | Typical tell | Safer move |
|---|---|---|
| SMS / “smishing” | Short link + urgency (“card locked—verify”) | Open the bank app you already installed, or type the URL from the card—Fake bank and brokerage alerts |
Lookalike domain (chase-secure-login.com), mismatched Reply-To | Bookmark official sites; hover links before clicking | |
| Voice / “vishing” | Caller asks you to read a one-time passcode; spoofed caller ID | Hang up; call the number on the back of the card—Fake support numbers |
| Fake collector / warrant text | Gift cards, crypto, arrest in one hour | Same rules as fake debt collectors |
| Fake utility shutoff | “Pay in 30 minutes” + gift cards / P2P | Hang up; check balance on the official app—Utility scams |
| Fake tech support | Remote-access app “to secure your account” | Never install from a cold call; full scripts in Tech support and refund scams |
Gift-card and prepaid PIN payments are nearly irreversible—see Gift cards and prepaid debit risks before you “verify” anything with a GameStop or Target card. Dating-app “trading platform” installs and recovery-room remote access: Fake romance investment apps.
What account takeover looks like
Once credentials or a session cookie are stolen, thieves often:
- Change your email and phone on file so recovery codes go to them
- Add a new payee or Zelle contact and move cash
- Open a new credit card or personal loan in your name
- Drain rewards or request a balance transfer
- File a change-of-address so paper alerts never reach you
Pull free files at AnnualCreditReport.com if anything looks off (How credit reports work). Unauthorized card charges follow a different path: Disputing a credit card charge.
Worked example: the “locked card” text
Priya gets a text: “Chase Fraud Alert: Your debit card ending 4412 is locked. Unlock: http://chase-verify-now.net/a9x.” The page clones Chase’s logo and asks for username, password, and the SMS code that arrives next.
Physical terminal theft is a different path—skimming and card cloning—but cleanup often overlaps with phishing recovery.
Priya does not tap the link. She opens the official Chase app from her phone home screen. No lock warning appears. She deletes the text and reports it inside the app’s fraud menu. If she had entered the code, she would immediately: change the password from a different device, call the number on the back of the card, freeze Equifax/Experian/TransUnion, and review recent transfers.
Cost of clicking: full checking access. Cost of opening the real app: about 30 seconds.
Government-impersonation variants (fake IRS warrants, SSA “SSN suspended,” Medicare card fees) have their own payment tells—see Fake IRS and benefits scams. Fake donation sites after disasters use the same urgency + look-alike domains—Fake charity donation scams. Cloned crisis crowdfunding pages: Fake charity crowdfunding scams.
Hard rules that stop most takeovers
- Type or bookmark—never trust a link in an unexpected message.
- One-time codes are for you only. Anyone who called you and asks for the code is the attacker.
- Prefer app-based or hardware multi-factor authentication over SMS when the bank (Ally, Capital One, Fidelity, etc.) offers it.
- Separate email passwords from bank passwords; use a password manager.
- Freeze credit when you are not shopping so a stolen SSN cannot easily open new tradelines (How to protect your Social Security number). Breach notice in your inbox: Account takeover after a data breach.
First hour if you already clicked or gave a code
- From a different device, change the password and revoke sessions.
- Call the fraud number on the back of the card or on a paper statement—not the number in the phishing message.
- Turn on account alerts for transfers, new payees, and large purchases.
- Place freezes at Equifax, Experian, and TransUnion; consider a fraud alert.
- Review recent ACH, Zelle, wire, and card transactions; dispute unauthorized ones in writing (Unauthorized card charges). Authorized P2P sends to scammers are a different problem—see Zelle and P2P payment scams.
- If a new account appeared, follow CFPB identity-theft recovery and FTC ReportFraud.ftc.gov steps.
Fake trading dashboards used in romance and pig-butchering scams are phishing with a longer social build-up - never trust a broker URL from a chat. Fake “postage due” texts and QuickBooks-lookalike invoices are the same family—see Shipping and invoice scams.
Loan-approval SMS variants: Fake loan approval texts.
Bank “security alert—call now” texts are a common callback path: Fake bank security alerts.
If the thief also pulled money by bank ACH (routing/account), dispute that separately with How to handle an unauthorized ACH debit.
Tax-season variant that clones IRS Get Transcript and ID.me: Fake IRS transcript phishing.
Checklist
- Hover or ignore unexpected links; open banks from the official app.
- Never read a one-time code to an inbound caller.
- Use unique passwords + stronger MFA than SMS-only when available.
- Freeze bureaus when idle; thaw only for planned applications.
- Screenshot phishing messages before deleting; report to the bank and FTC.
- After any credential exposure, audit payees, addresses, and credit reports within 48 hours.
Refund-plus-remote-access cons: Fake tech-support refund scams. Student-loan “servicer unlock” phishing: Fake student-loan servicer scams. Fake FAFSA / StudentAid.gov login and paid “aid portal” fee pitches: Fake student-aid portal scams.
Compromised realtor or title threads that swap closing wire instructions are a high-dollar cousin: Fake escrow wire instruction scams.
Fake Ticketmaster or venue “transfer” links that harvest logins sit next to ticket-resale cons: Fake ticket resale scams.
Phished parking-pay pages behind fake meter QR stickers: Fake QR code parking scams.
Fake Google Voice “unlock fees” and strangers who ask you to read a verification code: Fake Google Voice verification scams.
Fake Instagram “verified badge” or unlock-fee DMs that harvest passwords and 2FA codes: Fake Instagram verified-badge scams.
Fake Discord Nitro gift DMs and token-stealer “unlocker” downloads: Fake Discord Nitro scams.
WhatsApp verification-code handoffs and hijacked-chat money asks: Fake WhatsApp account-takeover scams.
Malicious NFT mint / wallet-connect approval prompts: Fake NFT mint-fee scams.
Telegram “VIP signal” bots that ask for seed phrases or wallet-connect approvals: Fake Telegram wallet-drain scams.
Fake TikTok Shop refund DMs, overpayment-return scripts, and remote-access “refund desks”: Fake TikTok Shop refund scams.
Fake Roblox Limited / Robux generator phishing and session-cookie steals: Fake Roblox limited-item scams.
Fake Snapchat login pages, recovery-fee DMs, and credential harvests: Fake Snapchat login scams.
Fake iCloud “storage full” upgrade pages and Apple ID credential harvests: Fake iCloud storage-full scams.
Fake Spotify Family-plan invite phishing and account-takeover scripts: Fake Spotify family plan scams.
Fake LinkedIn job-offer credential and remote-access cons: Fake LinkedIn job offer scams.
Fake Twitch Bits claim pages and Creator Dashboard clones: Fake Twitch Bits scams.
Fake YouTube copyright-strike emails, appeal portals, and remote-access “reinstatement” helpers: Fake YouTube copyright-strike scams.
Fake Reddit modmail / account-suspension appeal links and gift-card unlock fees: Fake Reddit modmail scams.
Fake Apple Support iMessage / lock-screen phishing that harvests Apple ID codes: Fake Apple Support iMessage scams.
Fake USPS Informed Delivery login pages and package-hold payment lures: Fake USPS Informed Delivery scams.
Spoofed Amazon “duplicate charge / refund desk” calls and texts: Fake Amazon refund scams.
Fake Spotify account-hold and “Premium support” phishing: Fake Spotify support scams.
Fake Uber account-hold / Trust & Safety phishing and gift-card unlock fees: Fake Uber account-hold scams.
Fake Netflix billing and account-suspension phishing: Fake Netflix billing scams.
Fake DoorDash dasher Instant Pay / account-hold phishing and gift-card unlock fees: Fake DoorDash dasher pay scams.
Fake Facebook Ads Manager / Meta Business Suite billing phishing: Fake Facebook Ads Manager scams.
Fake Google Ads billing / suspension phishing and gift-card unlock fees: Fake Google Ads account scams.
Fake eBay Managed Payments / payout-hold phishing and gift-card unlock fees: Fake eBay Managed Payments scams.
Educational only. Not legal, security, or fraud-recovery advice. Tactics change; verify contacts through official apps and statements.