Banking

Bank-Impersonation Scams: Warning Signs That Deserve a Second Look

Unexpected urgency, requests for codes and instructions to move money are strong reasons to stop and contact a bank through a trusted channel.

Suspicious phone call beside a bank card with details safely obscured

A bank impersonation scam succeeds by making an ordinary security concern feel urgent. The caller, text or email may claim there is a suspicious transaction, compromised account or technical problem. The proposed solution is usually immediate: disclose a code, install software or transfer money to a “safe” account.

Modern impersonation can look convincing. Caller identification can be manipulated, messages can appear beside genuine bank texts and criminals may know personal information from earlier data breaches. Recognition of a logo or phone number is therefore not enough to establish who is making contact.

Urgency and secrecy are deliberate pressure

A criminal may say money will disappear unless action is taken during the call. They may discourage contact with family, bank staff or police, or claim that employees are involved in the fraud. This isolates the customer from the independent check most likely to stop the transfer.

A genuine bank will not ask a customer to move money to another account to keep it safe. It will not need an online banking password, PIN or one-time security code read aloud over an unsolicited call. A code generated by the real bank can still authorise the scammer’s action if it is shared.

Remote-access software is another major warning. It allows the other person to view or control the device, including banking activity. Ending the call is not enough if the software remains installed and permissions are still active.

Break the contact and verify independently

Do not call a number contained in the suspicious message or rely on a transferred call. Use the bank’s official app, the number on the back of the card or a number independently found on its official website. A reference number supplied by the caller can be noted, but it is not proof.

Take time. Criminals use apparent urgency because verification works against them. A real fraud team can record the concern while the customer hangs up and reconnects through a trusted channel. If a caller objects to that process, the objection is itself useful information.

Check recent transactions from a separate, trusted device where possible. Do not click links in the message, and do not approve an in-app prompt unless the action displayed is one the customer deliberately initiated.

Respond quickly after contact or loss

If details or money were provided, contact the bank immediately and explain exactly what occurred. Ask the bank to secure accounts, cards and digital access, and preserve the transaction information. Fast reporting can improve the possibility of intervention, though funds cannot always be recovered.

Change affected passwords from a clean device, starting with email because it can be used to reset other accounts. Contact the mobile provider if a SIM takeover is suspected. Keep messages, numbers, receipts and screenshots rather than deleting the evidence.

Report the scam to Scamwatch and follow official guidance for identity compromise. If the bank’s response does not resolve the matter, its internal complaint process is normally the next step. Eligible unresolved complaints may then be taken to the Australian Financial Complaints Authority.

Families and businesses can agree on a simple rule: no urgent transfer requested by an unexpected caller is made until a second trusted person or independently contacted institution confirms it. The rule reduces the burden of making a perfect judgement under pressure.

Impersonators may follow an initial fraud with a recovery scam. Someone claiming to be a regulator, investigator or recovery specialist offers to retrieve the lost money for an upfront fee or asks for more account access. Treat that contact as a new unverified approach. Use official channels for every report and do not assume that knowledge of the original loss proves legitimacy.

Businesses can add procedural defences: two-person approval for changed payment details, verbal confirmation for first payments and limits appropriate to staff roles. Email security matters because a criminal inside a mailbox can copy tone, invoices and genuine conversation history. Multi-factor authentication and prompt removal of former staff access reduce that exposure.

Emotional response matters too. Shame can delay reporting and give criminals more time. Bank impersonation is engineered to exploit trust and fear; experienced and careful people can be caught. A factual, immediate report is more useful than trying to reconstruct perfect judgement before asking for help.

This article provides general information only and is not personal financial or legal advice. Anyone facing an active incident should contact their financial institution through verified details without delay.

Sources and further reading