Skip to content
Clear information. Thoughtful guidance. A way forward. You are in the right place to begin.
WorldwideEvidence & security3 min read

Fake bank texts and emails: how to verify and respond safely

Recognise phishing even when a message looks genuine, and take targeted steps if you clicked a link, shared a code or made a payment.

A suspicious paper message beside a ceramic phone and a brass shield
AI-generated illustration, not a photograph of real events.
The short answer

Do not use the message’s links or phone number to verify it. Open the bank’s official app or contact it through a known channel. If you shared credentials, codes or money, tell the bank immediately and secure the affected accounts from a trusted device.

Phishing tries to make you act through a false message: verify a payment, unlock an account or stop a supposed fraud. The design may copy your bank, and the message may appear in a familiar-looking conversation. Urgency is part of the tactic.

Good spelling is not proof of authenticity. Nor is a sender name or familiar logo. The safest check bypasses the message completely and starts at a channel you independently know belongs to the bank.

Verify the issue without following the message

Use the official banking app or the number on your card. Ask whether the alert and any referenced transaction are real. Do not call a number embedded in the suspicious message, even if the caller answers with the bank’s name.

A link preview can help reveal an unexpected domain, but it is not a substitute for independent contact. Shortened links and copied website design can hide the destination. Do not enter credentials to “see whether the page is genuine”.

Match your response to what you disclosed

If you only opened a message, that is different from downloading software, entering a password or approving a payment. Tell the bank which actions occurred. If credentials were entered, change them from a trusted device and revoke unknown sessions; reused passwords need changing elsewhere too.

If you shared card or identity information, ask the relevant issuer what protective steps are available. If money moved, provide the transaction details and ask about stopping, recalling or disputing it. Do not let uncertainty about the message label delay notification.

Be careful with codes and “safe account” instructions

A scammer may say a verification code cancels a fraudulent transaction when it actually approves access or a payment. Read the real bank prompt carefully and do not share codes with an unverified caller. Never transfer funds merely because a message says your account needs to be protected elsewhere.

If a code or prompt was used, preserve the text and tell the bank what it said. Avoid claiming that a code never arrived if it did. The context of deception matters and is best explained accurately.

Report and preserve without spreading the link

Use your bank’s phishing-reporting channel and the official route for your location. Belgium’s Safeonweb provides a route for suspicious messages; FTC reporting instructions concern the United States. Local forwarding numbers and services are not automatically worldwide.

Save the message and URL as evidence if needed, but avoid circulating a clickable malicious link to friends. Warn them with a redacted screenshot or description. If you downloaded something or granted remote access, treat it as a device-security incident as well as a message scam.

A short checklist

  • Bypass the message to contact the bank.
  • Record whether you clicked, downloaded, entered details or paid.
  • Secure exposed credentials and sessions.
  • Never act on a “safe account” instruction.
  • Report through the correct local channel.

Common questions

Does a text in the bank’s usual thread prove it is real?

No. The displayed sender or thread should not replace independent verification. Open the official app or call using a known number.

Should I reply “stop” to a suspicious bank text?

Do not engage to verify it. Follow your provider’s reporting and blocking process. If you already responded or shared information, focus on securing the relevant accounts.

References

  1. How to recognize and avoid phishing scamsFederal Trade Commission · United States; security guidance
  2. What to do if you were scammedFederal Trade Commission · United States; practical prevention guidance
  3. What to do if you've been scammedASIC Moneysmart · Australia
  4. Report an incidentCentre for Cybersecurity Belgium / Safeonweb · Belgium