Scam explained

Is that really your bank texting you?

A text message that looks like it came from your bank is one of the easiest things in the world to fake. Here are three checks that take ten seconds and settle it for good.

You are in the kitchen. Your phone buzzes. The message sits in the same conversation as every real message your bank has ever sent you, and it says there has been a suspicious charge. There is a link. It asks you to confirm it was not you.

The unsettling part is not that the message looks convincing. It is that it looks convincing because the system allows it to. The name that appears at the top of a text message is not verified by anyone. A sender can simply choose to appear as „CHASE" or „WELLS FARGO", and your phone will file it neatly alongside the genuine ones.

So the sender name proves nothing. Not the name, not the logo, not the fact that it appears in an existing conversation. None of it can be trusted, because none of it is checked.

The three checks

1. Do not tap the link

The message itself cannot harm you. Reading it is safe. The link is the entire trap — it leads to a page built to look exactly like your bank's login screen, and everything you type there is captured.

This is worth sitting with for a moment, because it is the single most useful thing to know about text scams: the danger is never in the message. It is always one tap further on.

2. Go to your bank yourself

Open your banking app the way you always do, from your home screen. Or type the address into the browser by hand. If there really is a problem with your account, you will see it there.

If your account looks perfectly normal, the message was false. It is that simple.

3. When in doubt, call the number on your card

Not the number in the message. The number printed on the back of your own bank card, which no stranger can change. Say what you received and ask whether it came from them. They will know within seconds, and they will not mind being asked.

What a genuine fraud alert actually looks like

Real banks do send text messages. The difference is what they ask of you.

  • A genuine alert usually asks you to reply with YES or NO, or to call the number on your card.
  • It does not ask you to log in through a link.
  • It does not ask for your password, your PIN, or a code you have just been sent.
  • It does not threaten to close your account within the hour.

If a message pushes you towards a login page, it is not your bank. However well it is written. However correct the logo looks.

The other versions of the same trick

Once you recognise the shape of it, you will see it everywhere. It is rarely about banks alone:

  • „Your package could not be delivered." With a link to „reschedule". Delivery companies do not send unsolicited links — check your tracking number at ups.com, fedex.com or usps.com instead.
  • „Unpaid toll charge." A small amount, a short deadline, a payment page.
  • „Your subscription will renew tomorrow." With a link to cancel it, which of course asks you to log in first.

Different stories, one structure: a plausible reason, a short deadline, and a link. The link is always the point.

If you already tapped

Tapping a link alone is very rarely enough to cause harm. The problem only begins if you entered something. If you did:

  • Change that password immediately — and start with your email account, because whoever controls your email can reset everything else.
  • Call your bank on the number on your card. Have the card locked and reissued if you entered card details.
  • Turn on two-factor authentication if it is not on already.
  • Report it at reportfraud.ftc.gov.

Then block the sender and delete the message. On an iPhone: tap the sender, tap the number, then Block this Caller and Report Junk.

Read next

Would you like help setting this up?

I visit you at home, at your pace, and explain everything in plain language — no jargon, no rush, and never any pressure.