Security Scams: how they work and what to do if you fall for one
Phone scams: spoofed numbers, robocalls and pressure tactics
Why the caller ID showing your bank means nothing, the scripts fraudsters use, and a simple hang up and call back rule that defeats almost all of them.
The short answer
- The number on your screen is supplied by the caller, so it can show your bank, the police or your own number.
- One rule handles nearly every scam call: hang up and call back on a number you already had.
- Real organizations let you call them back, and a caller who argues against that is telling you what they are.
- Pressure, secrecy and an unusual payment method are the three tells that appear in almost every script.
- On a mobile, hanging up ends the call instantly, so the old advice about waiting before you redial applies only to some older landlines.
The number shown on an incoming call is not evidence of anything. Caller ID is data that the calling system sends along with the call, and a caller can set it to almost any value, including the number printed on the back of your bank card, a local police station, a government office, or a number from your own contacts. This is called spoofing, and it is why the single most useful phone habit is to end the call and dial back on a number you already have. Everything else in this article supports that one move.
Why the display cannot be trusted
When a call is placed, the caller's phone system attaches a number to be displayed. Networks pass it along. For decades there was no strong check that the caller had any right to that number, because the system was built when only telephone companies could originate calls. Internet calling made call origination available to anyone, cheaply, from anywhere.
Regulators have responded with call authentication schemes that mark calls as verified when the originating network can vouch for the number, and you may see labels such as "Scam Likely" or a verified tick in your call log. These help with high volume robocalls. They do not help reliably with a targeted call, and a missing label is not a guarantee either. Treat the label as weather, not proof.
The scripts, and what each one wants
Fraud calls are not improvised. They follow scripts that have been tested on thousands of people, and they are usually run by someone whose only job is to keep you on the line.
| Script | The opening line | What it is really after |
|---|---|---|
| Suspicious transaction | A payment of 780 dollars to a foreign account is pending | A code, or a transfer to a "safe account" |
| Tax or customs debt | There is a warrant, or a case filed in your name | Immediate payment, often by card, transfer or gift cards |
| Refund owed | We are closing and owe you 320 dollars | Remote access to your computer, then a staged overpayment |
| Family emergency | It's me, I'm in trouble, please don't tell anyone | A fast transfer before you can check |
| Utility cut off | Your service will be disconnected within the hour | Card details over the phone |
| Tech support | We detected a virus on your machine | Remote access and payment |
The currency changes, the structure does not. Notice how many of them end at the same three places: a code, a transfer, or software installed on your device. The virus warning and the refund are two openings onto one operation, taken apart in the fake virus and fake refund routine.
The three tells that do not change
Pressure. Every script includes a reason why this must happen now, in the next few minutes, while you are on the line. Real fraud teams are perfectly happy for you to call them back. Real tax offices write letters and allow weeks.
Secrecy. You will be told not to tell staff at the counter, not to tell your family, or that the investigation is confidential and involves a corrupt employee at your own bank. That instruction exists purely to remove anyone who might interrupt the spell.
An unusual payment channel. Gift cards, crypto, cash couriers, wire transfers to a new account, or money moved to an account "in your name". Every one of these is chosen because it is fast and hard to reverse.
Hang up and call back, properly
- End the call. You do not need a reason and you do not owe an explanation.
- Find the number yourself: the back of your card, a statement, an official app, or the site you typed in your browser. Never the number the caller gave, and never the one in the text message that preceded the call.
- If you can, use a different phone. On a mobile the call is fully disconnected the moment you hang up, so redialing is safe. On some older analog landlines the caller can hold the line open for a short time, so an unfamiliar voice answering your "call" is the giveaway.
- Wait a minute or two, then dial. If the original call was genuine, nothing is lost. The bank's fraud team will see the same alert and continue from there.
- If it was a family emergency call, call the person directly on their usual number, and call someone else in the family if there is no answer.
Voice cloning has made that last step more important, because a familiar voice is no longer proof of identity. A short agreed family phrase, decided in advance and never shared online, is a cheap and effective check, which is covered in more depth in AI powered scams.
Cutting the number of calls you get
Silence unknown callers. Both iPhone and Android can send calls from numbers not in your contacts straight to voicemail, where you can read a transcript and call back if it mattered. This is the single biggest reduction most people can make, and it is one of the first settings worth changing for an older relative you help with technology.
Let voicemail screen. Legitimate callers with real business leave a message. Robocallers mostly do not.
Turn on the carrier's filtering. Most major carriers in the US, UK, Canada, Ireland and Australia offer free spam call labeling or blocking, usually in the account settings or a free app.
Register on the national do not call list. In the US that is donotcall.gov, in the UK the Telephone Preference Service, in Canada the National DNCL, in Australia the Do Not Call Register. It stops legitimate marketing, which is useful, because after a while every unsolicited call becomes suspicious by default.
Be careful about publishing your number. A number on a public profile, a classified ad or a business listing attracts far more calls than a private one.
Reporting, and where it actually goes
In the United States, report fraud calls at reportfraud.ftc.gov, and losses involving money at ic3.gov. In the United Kingdom, report to Action Fraud, and forward scam texts to 7726. In Canada, use the Canadian Anti-Fraud Centre. In Australia, report through Scamwatch. In Ireland, contact your local Garda station and your bank. In most of these countries, forwarding a scam text to 7726 works too, free of charge.
Reporting rarely gets your specific call investigated, and it is still worth two minutes: patterns are what get numbers blocked and prosecutions opened.
If the call already worked
Speed matters more than blame. Call your bank on a known number and say plainly what happened, including any second factor codes you read out. If money left your account, the first hour is the part that counts, and the order of actions is set out in what to do after sending money to a scammer. If the caller claimed to be from your bank's fraud team, the specific version of that script and the rules that expose it are in bank impersonation scams.
Common questions
How can a scammer show my bank's real number?
Caller ID is information the calling system sends along with the call, not something the network verifies end to end. Anyone with the right calling service can set it to any number, including one printed on your card. Networks in several countries now label suspected spoofed calls, but the labeling is incomplete.
Is it safe to just say hello?
Yes. The idea that saying yes records your consent to a charge is not how any payment or contract system works. The real cost of answering is that it marks your number as live, which usually means more calls.
They knew my last two transactions, surely that is proof?
No. That information often comes from an earlier phishing message, a data breach, or a receipt you shared. Knowing details about you proves someone has data, not that they work for your bank.
What should I do if I already gave them information?
Call your bank on the number from your card, tell them exactly what was said, and ask them to block the card and flag the account. If you gave a password, change it on any other account that used the same one.