Bank Fraud Alert Text Scam: How Smishing Works & What to Do Next
A fake bank fraud alert text is the opening move in a bank impersonation scam. Learn how smishing works, the three requests that are always fraud, and the recovery steps that still work.
11 minute read
Written by ScamAlert Editorial Team
Fraud research and consumer protection reporting
Checked against primary sources
FTC, FBI IC3 and CFPB — how we verify
- Published:
- Updated:
The short answer
A text asking you to reply YES or NO to a suspicious charge is the bait, not the scam. Replying tells the fraudster your number is live and triggers a phone call from a spoofed bank number — and everything they ask for on that call is designed to move your money out. Never reply, never call the number in the text, and never repeat a code aloud.
- The text itself cannot take your money. The follow-up phone call is where the loss happens.
- A real bank will never ask you to move money to a "safe account" — that account does not exist.
- One-time passcodes are the fraudster’s target. Reading one aloud authorizes the transaction.
- Wire and Zelle transfers you were tricked into sending are far harder to reverse than card charges — speed of reporting is everything.
It arrives at an inconvenient moment, which is not an accident. "FREE MSG: Chase Fraud Alert — Did you authorize a $412.87 purchase at BEST BUY #2214? Reply Y for yes, N for no." Your bank name is right. The amount is plausible but large enough to alarm. The formatting looks exactly like the alerts you have genuinely received before. And the only action requested is a single keystroke, which feels harmless.
That single keystroke is the entire point. This is smishing — SMS phishing — and the message is not trying to steal anything by itself. It is a filter, designed to sort millions of blasted phone numbers into the small subset belonging to people who bank at that institution, read their texts, and are willing to engage. Everyone who replies has just self-identified as a live, responsive customer, and moves into the next stage of the operation.
That next stage is a phone call, and it is where the actual theft happens. Understanding the difference between the two stages is what makes this scam survivable. The text is cheap and harmless. The call is expensive and dangerous. This guide walks through both, then covers exactly what to do in the first hour if you have already engaged — because in bank impersonation fraud, the recovery timeline is measured in minutes, not days.
$12.5 billion
Reported to the FTC in consumer fraud losses in 2024, with imposter scams the most-reported category
How the smishing script actually works
Bank impersonation crews run a repeatable four-stage script. Each stage exists to make the next one more believable, and each has a specific tell that you can learn to recognize before any money moves.
- Stage 1 — The blast. Tens of thousands of numbers receive an identical fraud alert naming a large bank. The sender has no idea whether you bank there. Statistically, enough recipients will that the campaign pays for itself.
- Stage 2 — The filter. You reply "N" or "NO" to dispute the charge. You have now confirmed three things: the number is active, a human reads it, and you bank at the named institution. Your number is promoted to a call list, often within seconds.
- Stage 3 — The callback. Your phone rings, often within one to five minutes. The caller ID displays your bank’s real customer service number, because outbound caller ID is trivially spoofable and nothing about it is verified. A calm, professional voice thanks you for flagging the transaction.
- Stage 4 — The extraction. The caller "secures" your account. Everything they instruct you to do from this point — read a code, move funds, install software, approve a prompt — transfers money or account control to them, using your own credentials and your own authorization.
Why the caller sounds so convincing
People who lose money to this scam are not careless. They are talking to someone who sounds exactly like a competent bank employee, because the operation has been refined across thousands of calls and the script borrows every trust signal a real bank uses.
The caller often already knows fragments of your data — the last four digits of your card, your city, sometimes your account opening year — harvested from earlier breaches or bought wholesale. They use partial verification against you: instead of asking you to prove who you are, they prove who they are by reciting information "only your bank would know." It is data that thousands of people have access to, but in the moment it lands as authoritative.
They also weaponize your own security instincts. The urgency is framed as protection: your money is at risk, and they are helping. Objecting feels like obstructing a rescue. This is deliberate — it converts your caution into cooperation, which is why "I was suspicious but they were so helpful" is the single most common thing victims say afterward.
| Behavior | Genuine bank fraud team | Impersonator |
|---|---|---|
| Asks for a one-time passcode | Never. Codes are for you to enter, not to say out loud. | Always — usually framed as "verifying it’s really you." |
| You offer to call back on the card number | Encourages it. Will give you a case reference. | Resists, stalls, or warns the line is "monitored." |
| Asks you to move money | Never. Banks freeze accounts in place; they do not relocate funds. | Core of the script — a "safe", "protected" or "holding" account. |
| Asks you to install software | Never for fraud resolution. | Common — remote access tools framed as "secure connection". |
| Pressure and timing | Will let you pause, consult a spouse, or visit a branch. | Manufactured deadlines; discourages telling anyone. |
| Asks for full card number / PIN / full SSN | Never asks for a PIN. Verifies with partial data only. | Requests full credentials, often "to close the compromised card." |
The four requests that mean it is always a scam
You do not need to evaluate the caller’s credibility, their accent, their hold music, or the number on your screen. You only need to listen for four specific requests. Every bank impersonation scam requires at least one of them, and no legitimate bank process requires any of them.
Hang up immediately if the caller asks you to…
These are not "warning signs to weigh." Any single one ends the call.
- Read back a one-time passcode, verification code, or any number that arrived by text or app notification.
- Transfer, wire or Zelle money to a "safe account", "secure holding account", or an account in your own name they have set up.
- Install remote-access or "bank security" software — AnyDesk, TeamViewer, or an app sent by link.
- Provide your full card number, PIN, full Social Security number, or online banking password.
- Withdraw cash, buy gift cards, or purchase cryptocurrency as part of a "fraud investigation" or "sting operation".
- Keep the call secret from family, or stay on the line while you drive to a branch or ATM.
What to do in the first hour
If you replied to a text but did nothing else, your exposure is low — your number was confirmed as active, nothing more. If you spoke to a caller and followed any instruction, treat the next sixty minutes as the recovery window. Funds that have not yet left the receiving institution can often be frozen; funds that have been cashed out rarely come back.
Bank impersonation recovery timeline
Work top to bottom. Do not skip ahead to reporting before you have contacted your bank.
- 1
Minutes 0–10
Call the number on the back of your card
Not the number the caller gave you, not a number from a search result, and not a callback in your recent-calls list. Read the number physically printed on your card or from your bank’s official app. Say the words "I am reporting fraud in progress" — that phrasing routes you to the team with authority to place immediate holds.
- 2
Minutes 10–20
Request a freeze, a recall, and new credentials
Ask explicitly for three things: a hold on the account, a recall or reversal attempt on any transfer that left, and reissued cards plus a forced password reset. Get a case or claim reference number before you hang up and write it down.
- 3
Minutes 20–40
Lock down the digital perimeter
Change your online banking password and email password from a different device if you installed anything the caller sent. Remove unrecognized devices from your banking app’s trusted list. If you granted remote access, disconnect that device from the internet and have it inspected before you use it for banking again.
- 4
Hours 1–24
File the written dispute
A phone report is not a dispute. Ask your bank how to submit written notice of unauthorized activity and submit it the same day. Written notice is what starts your formal protection clock under federal rules, and it creates the paper trail you will need if the first decision goes against you.
- 5
Days 1–3
Report to the FTC and IC3
File with ReportFraud.ftc.gov and, if a wire or online transfer was involved, with the FBI’s IC3. IC3 operates a recovery asset process that has succeeded in freezing domestic wire transfers, but it works on very short timelines — same-day filing matters materially.
- 6
Week 1
Add credit protections and escalate if needed
Place a free fraud alert and consider a credit freeze at all three bureaus. If your bank denies the claim and you believe the transaction was unauthorized, file a CFPB complaint — regulated institutions must respond substantively to those.
What you can actually get back
This is where honest guidance matters more than reassurance. Your protection depends almost entirely on how the money moved, and the differences are severe. The critical legal distinction is between an unauthorized transaction — one you did not make or approve — and an authorized push payment, where you were deceived into sending the money yourself. Consumer protection law is strong on the first and much weaker on the second.
| How money left | Realistic recovery odds | What governs it |
|---|---|---|
| Credit card charge | Strong | Fair Credit Billing Act dispute rights plus card network chargeback rules; liability for unauthorized use is capped at $50 and most issuers waive it. |
| Debit card charge | Good if reported fast | Regulation E. Liability escalates sharply with delay — report within two business days of learning of the loss to stay at the lowest tier. |
| Unauthorized online transfer | Good | Regulation E covers electronic transfers you did not authorize; notify within 60 days of the statement showing it. |
| Zelle / P2P you were tricked into sending | Limited but improving | Treated as authorized. Network rules have expanded reimbursement for imposter scams — always file the claim; do not assume refusal. |
| Domestic wire transfer | Only if caught within hours | Recall requests depend on the receiving bank’s cooperation and whether funds remain. IC3’s recovery asset team can help if filed same-day. |
| Gift cards, crypto, cash | Very poor | No reversal mechanism exists. Report anyway — card issuers occasionally freeze unspent balances. |
Where to report it
Reporting will not usually recover your money on its own, but it feeds the datasets that drive enforcement and carrier-level blocking. Forwarding the original text to 7726 takes ten seconds and is genuinely useful — it routes the sending number into carrier blocklists.
Report a bank impersonation scam
File with all that apply. Keep your bank case number handy — several forms ask for it.
These are official government resources. ScamAlert is not affiliated with any government agency and receives no compensation for these links.
Making yourself a harder target
You cannot stop the texts. Phone numbers leak through breaches you had no part in, and blasting them costs the sender almost nothing. What you can do is make sure that a text landing on your phone never leads to a loss — which mostly means building one habit and turning on a few settings.
- Adopt the callback rule permanently: no financial conversation ever happens on a call you did not dial. Say it out loud to the caller — a real agent will accommodate it.
- Move off SMS-based two-factor authentication for your bank wherever an authenticator app or passkey is offered. SIM-swap attacks and code-reading scripts both target SMS specifically.
- Turn on transaction alerts in your banking app rather than relying on texts. In-app alerts cannot be spoofed; SMS can.
- Set a low-friction family verification phrase — a word only your household knows — and use it whenever anyone calls about money. It defeats both this scam and AI voice cloning.
- Never search for your bank’s phone number. Scam call centers buy search ads against those exact queries. Use the card, the app, or a statement.
- Freeze your credit at all three bureaus if you are not actively applying for credit. It is free, reversible, and blocks the most profitable follow-on use of stolen identity data.
One last framing that helps people more than any checklist: a bank never needs your cooperation to protect your own account. Every genuine protective action — freezing a card, blocking a charge, reissuing credentials — is something the bank can do unilaterally, from their side, without you reading them anything. So the moment a caller needs you to do something in order to secure your money, you are not talking to your bank. You are talking to someone who needs your hands on the controls, because they do not have access themselves.
What to do after replying to a fake bank fraud alert text
A step-by-step recovery procedure for consumers who engaged with a bank impersonation smishing text or the follow-up phone call.
- 1
Stop the call and do not act on any instruction
Hang up without explaining yourself. Do not read any code aloud, approve any app prompt, or move any funds, even if the caller says the transfer is already in progress.
- 2
Call the number printed on your bank card
Use the number physically on your card or inside your official banking app. Say you are reporting fraud in progress so you are routed to the team that can place immediate holds.
- 3
Request a freeze, a recall and new credentials
Ask for a hold on the account, a recall attempt on any transfer that already left, reissued cards and a forced password reset. Record the case reference number.
- 4
Secure your devices and logins
Change your banking and email passwords from a clean device. Remove unknown trusted devices. If you installed remote-access software, disconnect that device and have it inspected.
- 5
Submit a written dispute
Follow your bank’s written notice procedure the same day. A phone call alone does not start your formal protection clock under federal rules.
- 6
File official reports
Report at ReportFraud.ftc.gov, file with the FBI IC3 if a wire or online transfer was involved, and forward the original text to 7726.
- 7
Add credit protections
Place a free fraud alert or credit freeze with all three credit bureaus, and escalate to the CFPB if your bank denies a claim you believe was unauthorized.
Frequently asked questions
Is it dangerous just to reply to a bank fraud alert text?
Replying does not by itself give anyone access to your money or your phone. What it does is confirm that your number is live, monitored by a real person, and likely attached to the named bank — which promotes you onto a priority call list. The danger is the phone call that usually follows within minutes, not the reply itself. If you already replied, do not panic; simply do not accept the callback, and dial your bank yourself if you want to verify your account status.
How can the caller ID show my bank’s real phone number?
Caller ID is not a verified security signal. The number displayed on an incoming call is supplied by the caller’s own carrier or VoIP provider and is trivially set to any value, including your bank’s published customer service line. Anti-spoofing frameworks like STIR/SHAKEN reduce this for some traffic but do not eliminate it. Treat the caller ID as decoration, never as identification.
I read a one-time passcode to the caller. What did that authorize?
Almost certainly a real action on your real account — a login from their device, a new payee, a password reset, or a transfer. That is precisely why the code was requested at that moment. Call your bank immediately on the number on your card, tell them a passcode was disclosed under impersonation, and ask them to review and reverse any activity in the last hour, force a password reset, and remove unrecognized devices from your profile.
Will my bank refund money I sent to a "safe account" myself?
It depends on how it was sent and how the claim is categorized. Because you initiated the transfer, it is legally an authorized payment rather than an unauthorized one, which places it outside the strongest federal protections. However, reimbursement expectations for imposter-scam transfers have expanded, banks apply discretion, and outcomes vary widely by institution. Always file the claim, state clearly that you were deceived by someone impersonating the bank, and escalate to the CFPB if denied.
Should I click the link in the text to see if the site looks fake?
No. There is no safe amount of investigation on a phishing link. Even when the page is only a credential-harvesting clone, visiting it confirms your engagement and the page may closely replicate your bank’s real login. Screenshot the message for your report, forward it to 7726, and delete it. If you want to check your account, open your banking app directly.
How do I protect an older parent who keeps receiving these?
Two things outperform everything else. First, set a family verification phrase — a word known only within the household — that must be used in any conversation involving money, which defeats both impersonation calls and AI voice cloning. Second, write the bank’s real number on a card taped near their phone with a single instruction: "Hang up. Call this number." Removing the decision from the moment of pressure is far more effective than teaching a list of warning signs.
Sources & further reading
Every guide on ScamAlert is checked against primary sources from US consumer protection and law enforcement agencies.
- [1]How to Recognize and Report Spam Text Messages — Federal Trade Commission
- [2]Phishing Scams — Consumer Advice — Federal Trade Commission
- [3]Internet Crime Complaint Center (IC3) filing portal — Federal Bureau of Investigation
- [4]Electronic Fund Transfers (Regulation E) — consumer protections — Consumer Financial Protection Bureau
- [5]Submit a complaint about a financial product or service — Consumer Financial Protection Bureau
Topics covered
- bank fraud alert text
- fake bank sms refund
- smishing scam recovery
- bank impersonation scam
- did you authorize this transaction text
- fake fraud alert text message
Editorial note: This guide is general consumer education, not legal or financial advice. Dispute deadlines, liability limits and reimbursement policies vary by institution and change over time. Confirm your specific rights with your bank or a qualified professional. See our editorial policy for how we research and review this content.
Sponsored content
Related guides
Cards & Payments
P2P Accidental Transfer Scam
Money arrives in your Venmo or Cash App "by mistake" and a stranger asks you to send it back. Here is why returning it costs you twice, and how P2P payment fraud really works.
AI & Cyber
AI Voice Cloning Scams
A few seconds of public audio is enough to clone a relative’s voice. Learn how AI voice cloning emergency scams are built, why they defeat instinct, and the one habit that stops them.
AI & Cyber
QR Code (Quishing) Scams
Fake QR code stickers on parking meters, restaurant tables and package slips route you to convincing payment clones. Learn how quishing works and how to check a code before you scan.