goJumboGPT

Everyday Money online: payments, refunds and subscriptions

Online banking: the habits that make fraud hard

How banking fraud actually starts, the settings and habits that block it, and how to tell a genuine bank contact from a convincing fake.

9 min read How we write

The short answer

  • Open the bank app yourself rather than following any link, because that one habit removes the attacker's control over where you end up signing in.
  • No legitimate organization will ever ask you to move money to a safe account, and that single rule defeats the entire family of bank impersonation scams.
  • Transaction alerts at a low threshold are your earliest warning, since card fraud usually opens with a small test payment to check the card is live.
  • Your email account protects your bank account, so it needs the stronger second factor, a unique password and a check for forwarding rules you did not create.
  • Daily transfer limits, new payee delays and name checking are friction working in your favor, and being urged past them is itself the warning sign.
  • This is general information rather than advice about your own accounts, and reimbursement rules for scam transfers differ considerably between countries.

Bank fraud almost never starts with a broken bank. It starts with you being persuaded to do something, or with an account elsewhere that holds the keys to your bank. So the habits that matter are the ones that remove the persuader from the loop: open the bank app yourself instead of following any link, turn on alerts so the bank tells you about money moving before anyone else does, lock the email account that can reset everything, and keep savings somewhere that is slow to reach. None of it is technical. This is general information rather than advice about your own accounts, and your bank's terms and your country's rules decide the details.

How bank fraud actually starts

Three routes, needing different defenses.

Credential theft. Someone obtains your login details from a fake sign in page reached through a text or an ad, or from a password reused on a site that was breached. They then have to defeat your second factor, which is why the follow up call asking for a code exists.

Account takeover through email. Nobody needs your banking password if they control the mailbox that receives password resets and security notices. This route is quiet, because the first thing an attacker does is set a rule hiding the bank's messages.

Authorized push payment fraud. You are talked into sending the money yourself. No password is stolen and no system is breached, which is why it is the hardest kind to reverse. The main script is set out in how the safe account scam works.

Notice what is missing: someone intercepting your connection on public wifi. Banking traffic is encrypted, and the real risk on a shared network is a fake login page rather than eavesdropping, a distinction drawn out in what is still risky on public wifi and what is not. Worry about the message that reached you, not the network you are on.

This is the habit with the best return. If a message, email or call raises anything about your account, close it and open the banking app yourself. If the concern is real it will be there: a card block, a pending payment, a message in the secure inbox. If the app shows nothing, there was nothing.

It works because it removes the attacker's control over where you land. A link can point anywhere, a display name can say anything, and a sign in page can be copied in an afternoon. The app on your phone points at the bank whatever anyone tells you.

Two extensions. Do not reach your bank through a search engine, because paid results at the top of a search page have repeatedly been used to place fakes above the real site. And never approve a sign in prompt or type a code you did not just request: a code arriving out of nowhere means someone is standing at the login page holding your password. Which kinds of code are strongest is covered in two-factor authentication explained in plain English.

If your bank still supports sign in with only a password, change that today. An authenticator app beats text message codes, since text codes can be redirected by a number takeover, and the setup including the backup step nobody does is in setting up an authenticator app properly.

Alerts, limits and an account layout that contains damage

Speed decides outcomes in fraud, so arrange to find out fast and make large movements slow.

Turn on transaction alerts for every card and account at a threshold low enough to catch a test charge, since card fraud often opens with a tiny payment to check the card is live. Then add alerts for the events that precede a theft rather than the theft itself: a new payee added, a change of address or phone number, a password reset, a card ordered.

Then set limits down. Most banks let you cap daily transfers, lower the contactless limit, disable overseas or online card use until you need it, and freeze a card instantly. A transfer limit set to what you actually move, raised deliberately on the rare day you need more, converts a catastrophic loss into an annoying one.

Account layout does the same job structurally. Keep the spending account thin, with the card and the online transfers attached to it. Keep savings separate, with no card, ideally at a different institution and able to pay out only to an account in your own name. Money that cannot reach a stranger in one session cannot be taken in one phone call.

Finally, read the statement on a schedule rather than when something feels wrong. Once a month, line by line. The charges people miss are the small recurring ones, and a claim only works inside the time limits described in how chargebacks and payment disputes actually work.

Why your email account is the real target

Your bank account is protected by your email account. Password resets and security alerts arrive there, and for many services the address is the identity. An attacker who owns the mailbox can work slowly, and can hide every warning the bank sends.

So it needs stronger protection than the bank does: a long unique password, an authenticator app or a passkey rather than a text code, and current recovery options. Then check the parts nobody checks. Look for forwarding rules and filters you did not create, since a rule that sends anything containing the word bank to an outside address is the classic quiet takeover, and review which devices are signed in. The full list is in locking down the email account that is the master key.

Consider a separate address used only for financial accounts and never given to shops or newsletters. It will not appear in the breach lists that seed targeted phishing, and any message arriving there that is not from a bank is immediately suspect. Running several addresses and a unique password each is only practical with a password manager holding the vault.

Confirmation of payee and friction that works for you

Banks have added deliberate obstacles to sending money, and the reflex is irritation. Understand what each one checks and it becomes a free safety net.

Name checking. UK banks run confirmation of payee: you type the recipient name and the bank compares it with the name on the destination account, reporting a match, a partial match or none. The EU is rolling out an equivalent check for euro transfers. A no match warning is the most useful signal you will ever get, and victims click past it because the caller warned them in advance that the account is in a different trading name. That explanation is itself the tell.

New payee delays and limits. Many banks cap the first payment to a new recipient, or hold it for a number of hours. Do not ask for the delay to be lifted while someone is on the phone with you. The delay exists precisely for the situation you are in.

Warning screens. The questions about why you are paying are not a form to click through. They change what the bank can do afterwards, and in the UK they feed the reimbursement rules for scam transfers.

Verifying that a caller is really your bank

Caller ID can be faked. A call can arrive showing the number on the back of your card, and a text can land inside the same thread as genuine bank messages, because the sender name is a label. Neither proves anything, which is why spoofed numbers and pressure tactics work on careful people.

The method is always the same. End the call, wait a minute, then dial the number on the back of your card, not one the caller gave you and not one from a search result. On a mobile that is enough. On an older landline use a different phone if you have one, since a caller can occasionally hold the line open. Genuine fraud teams never object to being called back.

What the caller or message asksDoes a genuine bank do this?What it means
Move your money to a new safe or holding accountNever, in any countryIt is a scam, every time, with no exception
Read out a code they just sent youNo, codes are for you to type in yourselfSomeone is at the login screen right now
Give your full password or PINNo, staff never need eitherHang up immediately
Install a remote support or screen sharing appNoThey want to watch you bank, or to bank as you
Withdraw cash, buy gift cards or send cryptocurrencyNeverChosen because it cannot be reversed
Confirm whether a specific payment was yoursYes, fraud teams do thisReasonable, but call back to answer it
Freeze the card or cancel a paymentYou can do it yourself in the appNo conversation needed at all

One rule defeats the whole family of safe account scams: no legitimate organization will ever ask you to move money to keep it safe. Not your bank, not the police, not the tax office. If those words appear in any form, the person saying them is the fraud.

The setup worth doing this week

  1. Install the official bank app and delete any saved link you did not create.
  2. Turn on transaction alerts at a low threshold, plus alerts for new payees, contact changes and resets.
  3. Set the daily transfer limit near what you actually move, and lower the contactless limit.
  4. Move savings to a separate account with no card, ideally one that pays out only to accounts in your own name.
  5. Put the email account on an authenticator app or a passkey, then check it for forwarding rules you did not set.
  6. Give every financial account a unique password, and book fifteen minutes a month for the statement.

If something does go wrong, the first hour carries most of the recoverable value. Call the bank on the number from the card, ask it to attempt recall and to freeze the account, get a reference number, and write down the timeline while it is fresh. The rest of the sequence is in what to do in the first hour after sending money to a scammer. Reimbursement rules differ sharply by country, so treat the outcome as something to pursue rather than assume, and take a refusal on a large loss to your national ombudsman.

Common questions

Is a banking app safer than using the website?

Yes, for most people. The app came from an official store and always points at the real bank, while a browser can be steered to a convincing copy by a link, an ad or a mistyped address. Apps also keep their data in an isolated area of the phone and can use fingerprint or face unlock. If you prefer the website, reach it from a bookmark you created yourself, never from a search result.

Can someone empty my account if they know my account number?

Not directly. Account and routing or sort code numbers are printed on cheques and given out to receive payments, so they are not secret. The risk is that those details make a scam call sound convincing, or allow an attempt at a direct debit you did not authorize. Incorrect direct debits can be reversed, and your alerts are what make you notice one in the first place.

Should I use my bank app on public wifi?

It is fine. The connection between the app and the bank is encrypted, so someone on the same network cannot read it. The real risks on a shared network are being redirected to a fake sign in page, or someone simply watching your screen. Use the app rather than a browser, use mobile data if you have a choice, and shield the screen while typing a passcode.

How do I know if a text from my bank is real?

You cannot tell from the message itself. Sender names are labels that anyone can set, so a fake can appear inside the same thread as genuine messages from your bank. Treat every message as a prompt to check rather than an instruction to act: open the app and look for the same information there. If it matters, the bank will have put it in the app or the secure inbox.

Will my bank refund me if I get scammed?

It depends on the type of fraud and the country. Payments you never authorized are generally refundable under US and EU rules, usually quickly. Payments you made yourself after being deceived are treated differently, and the UK now requires reimbursement for many of those subject to caps and exclusions while other countries do not. Report immediately either way, because speed affects both the recall attempt and the assessment.