goJumboGPT

Security Scams: how they work and what to do if you fall for one

Bank impersonation: the safe account scam and how it works

The most costly scam there is: a convincing call from your bank asking you to move money to safety. How it is set up, the single sentence that gives it away, and what to do after.

8 min read How we write

The short answer

  • No bank will ever ask you to move money to a safe account, because a real bank protects money by freezing it where it already is.
  • The call works because of preparation: breach data, a warm up text about a suspicious payment, and a caller ID set to the number printed on your card.
  • A one time code read aloud is you completing the attacker's login, which is why no legitimate employee ever asks for one.
  • Hang up and call back on the number from your card, ideally from a different phone, since a held open line only works on some older landlines.
  • Because you authorized the payment yourself, refunds depend on where you bank: the UK now has a mandatory reimbursement scheme, the US and EU largely do not.
  • If it already happened, the first hour matters most, and the recovery expert who contacts you afterwards is part of the same operation.

Bank impersonation is the scam that takes the largest amounts of money from ordinary people, because it does not steal anything. It persuades you to send it. Someone calls, sounds exactly like a bank fraud officer, tells you your account has been compromised, and walks you through moving your balance to a new account that has been opened to keep it safe. The safe account does not exist. It belongs to the caller or to a money mule. One sentence settles every version of this call: no bank will ever ask you to move money to another account to protect it.

How the call is set up before it happens

By the time the phone rings, work has already been done, and that is why the call feels credible.

They start with data. Your name, address, bank and the last four digits of a card are routinely available from breach dumps, an earlier phishing page, or a fake shop that took a real order. None of it proves who is calling, but all of it sounds like the inside of your account.

Then they warm you up. A text asks whether you authorized a payment to an unfamiliar merchant and tells you to reply NO or call a number. You are now expecting a call about fraud, which is the point of the message. The giveaway is usually the number itself, and the wider patterns are in scam text and email red flags.

Some operations add a small real transaction, a charge of a few dollars on your card, so that when the caller mentions a genuine recent payment you stop doubting them.

Finally they set the caller ID to your bank's published number. That costs almost nothing, because the displayed number is supplied by the caller and not verified by the network, as how spoofed numbers work explains. When the screen matches the card in your hand, most people stop evaluating and start cooperating.

The script, minute by minute

The call is not improvised. It moves through stages, and the early ones are deliberately calm.

First, identification. They read out details you recognize, then ask you to confirm others. This flips the usual direction of a bank call and puts you in the position of the one being verified, which feels normal because it is how real calls start.

Second, the alarm. There is a payment in progress, an attempted transfer abroad, a device added to your account, or an employee at your branch under investigation. The amount is usually large enough to frighten and specific enough to sound real.

Third, the rapport. They become the person helping you. Victims often describe the caller as patient and reassuring rather than aggressive, which is why this works on people who would hang up on a threat.

Fourth, the ask. Move your balance to a safe account. Read out the code we just sent. Install this tool so we can secure your device. Withdraw cash for the courier collecting counterfeit notes. The wrappers differ, the direction is the same: value leaves you irreversibly.

Fifth, the containment. Do not tell the cashier the real reason for the withdrawal, because the investigation is confidential. Stay on the line while you do it. That instruction exists to remove the one person who might interrupt.

The one sentence that ends it

A bank that believes your account is compromised freezes it. It blocks the card, stops the payment, and locks the account where it stands. No bank keeps a special account for customers to transfer into. If a caller suggests one, the call is fraudulent and nothing else needs analyzing.

The same goes for one time codes. Each arrives with text saying what it authorizes: a new payee, a new device, a password reset. Reading it aloud completes the attacker's login rather than confirming your identity, and no real employee asks for one. It is the known weakness of text codes in how second factors work: they are only as safe as your silence.

The tricks that make it convincing

Four techniques do most of the heavy lifting.

The callback trap. You say you will hang up and call the bank yourself, which is the right instinct, and they encourage it. On some older analog landlines the caller can hold the line open briefly after you put the receiver down, so your dial reaches the same person. A mobile disconnects instantly. Using a different phone removes the doubt.

The relay to a second authority. A colleague from the police or the fraud squad comes on the line with a badge number and a case reference. Both are invented. Police forces do not call to arrange transfers, collect cash, or ask you to keep an operation secret from your bank.

The trust builder. A small transfer first, which they confirm arrived safely. It did. It also taught you that the process is fine, and it is followed by the large one.

The voice. Cloned audio of a familiar person, and synthetic voices with a convincing local accent, are now cheap enough to be part of routine fraud operations, which AI powered scams covers in detail. Assume that a voice proves nothing about who is speaking.

What a real bank does and does not do

SituationA real bankThe impersonator
Suspected fraud on your accountBlocks the card and freezes the account where it isAsks you to transfer the balance somewhere safe
Verifying who you areAsks for selected characters of a memorable word, or sends you to the appAsks you to read back a code it just sent you
You want to call backEncourages it and gives you timeObjects, or keeps you on the line while you dial
Your device may be infectedTells you to visit a branch or contact the manufacturerTalks you into installing remote access software
Cash or cards need collectingNever sends anyone to your homeSends a courier, sometimes with a fake ID card
TimingLets you think it over and call tomorrowInsists the window closes in minutes

Print that middle column mentally. Every single row of the impersonator column is also true of the fake refund and fake virus calls, which is why tech support scams feel familiar once you have seen this one.

Whether you get your money back

This is general information rather than advice about a specific case, and the answer depends heavily on where you bank and how you paid.

The legal problem is that you made the payment. Most consumer protection was written for unauthorized transactions, meaning payments you did not make, and a transfer you typed in yourself is treated as authorized even though you were deceived. The industry term for this category is authorized push payment fraud.

In the United Kingdom, rules from the payments regulator now require banks to reimburse most victims of this fraud within a few business days, with the cost shared between the sending and receiving bank. There is a cap, a deduction the bank may apply, and an exception for gross negligence, which is a high bar rather than a general excuse. Refusals can be escalated to the Financial Ombudsman Service.

In the United States there is no equivalent mandatory scheme. Electronic transfer rules cover unauthorized transactions, so a bank wire or a person to person payment you sent yourself is usually outside them. Some banks and payment networks have adopted their own reimbursement policies for imposter scams, so it is always worth claiming rather than assuming.

In the European Union, payment rules refund unauthorized transactions but cover self sent payments poorly, and payee name checking is being rolled out to catch mismatches before money leaves. If you paid by card rather than transfer, the route is different and often better, as disputing a payment explains.

What to do in the next hour

Speed changes the outcome more than anything else, because funds can sometimes be frozen at the receiving bank before they are moved on.

  1. Call your bank on the number printed on your card, using a different phone if you have one. Say the words fraud and, if you know them, authorized push payment, so the call is routed correctly.
  2. Ask explicitly for the payment to be recalled and for your account to be secured. Note the time and the name of who you spoke to.
  3. Report it nationally: the FBI internet crime complaint center and the FTC in the US, Action Fraud in the UK, the Canadian Anti-Fraud Centre, or Scamwatch in Australia.
  4. Change the password on your online banking and your email, sign out all sessions, and check for new payees, new devices and mail forwarding rules that were added during the call.
  5. If you gave identity details rather than money, watch for accounts opened in your name, using the early warning signs in identity theft basics.
  6. Expect a follow up offering to recover the funds for a fee. It is usually the same operation selling you the second half of the loss.

The full order of the first sixty minutes is set out in what to do after sending money to a scammer. And if you are reading this because a call already sounds wrong: hang up, wait two minutes, and dial the number on your card. Nothing legitimate is lost by doing that.

Common questions

How do I know if a call from my bank is real?

You cannot tell from the call itself, so do not try. End it and dial the number on the back of your card or in your banking app. A genuine fraud team will have logged the case and will pick up where the call left off. In the UK, some banks also accept a short dial service that connects you directly to your own bank's fraud line.

The number matched my bank exactly, how is that possible?

Caller ID is set by whoever places the call, not verified by the phone network, so any number can be displayed including one printed on your card. Some networks now label suspected spoofed calls, but the labeling is incomplete and a missing warning proves nothing. Treat the display as decoration rather than identification.

Will my bank refund me if I transferred the money myself?

It depends on your country. In the UK, banks are now required to reimburse most victims of this type of fraud, subject to a cap and a narrow gross negligence exception. In the US and most of the EU there is no equivalent requirement for transfers you authorized, although some banks and payment networks reimburse imposter scams voluntarily. Claim anyway, and escalate if refused.

Is it safe to call back on the same phone straight away?

On a mobile, yes, because the line disconnects the moment you end the call. On some older analog landlines a caller can hold the line open briefly, so your redial reaches them instead of your bank. If you only have a landline, wait a few minutes, or use a neighbor's phone, and listen for anyone answering before the line has rung.

What if I already gave them a code but no money left my account?

Act as if something did happen. Call the bank on a known number, tell them exactly which code you shared, and ask them to check for new payees, new registered devices and changed contact details. Then change your online banking password and your email password, and sign out of all active sessions on both.