Your phone rings. The caller ID shows your bank’s name. A polite “fraud department officer” says someone is trying to drain your account right now — and that the only way to stop it is to move your money to a “safe account,” or read back the one-time code the bank just texted you. It feels helpful. It feels urgent. And it is a bank impersonation scam: one of the costliest frauds in the world.
The scale is staggering. The US Federal Trade Commission reported that people lost $3.5 billion to imposter scams in 2025 — nearly triple the 2020 figure — with imposter scams the single most-reported fraud category, accounting for nearly one in three fraud reports. Of that, people reported losing nearly $1 billion to business impersonators, with the highest reported losses tied to criminals pretending to work for banks [1].
This article breaks down exactly how these scams work, why your real bank will never ask for certain things, and the verification steps that stop the scam cold.
How a bank impersonation scam works
Step 1: The hook — spoofed caller ID and a fake “fraud alert”
Scammers use caller-ID spoofing to make your phone display your bank’s real name and number. The call — or a text that looks identical to your bank’s fraud alerts — claims there is suspicious activity on your account: an unauthorized transfer, a new device login, or a “security upgrade” you must complete.
The FBI has documented variants of this trick in detail. In one scheme, scammers impersonating bank representatives call customers from a number that caller ID shows as the bank’s own, describe “recent transactions” to sound credible, and convince the customer their card is compromised [3]. In another, the scam begins with a call from someone posing as a financial-institution representative, then escalates — victims are transferred to a fake “FBI agent” with a fake badge number who pressures them to act in secrecy [4].
Step 2: The urgency — manufacturing panic
Once you believe the caller is your bank, they create artificial urgency: the “fraud” is happening now, your money is at risk this minute, and there is no time to think. The FTC notes that some of the costliest impersonation scams start with a fake security alert, after which victims are “convinced to move money to ‘protect’ it, with their losses often limited only by their available funds” [1].
The urgency is deliberate. Panic narrows your thinking and suppresses the question that would kill the scam: why would my bank call me to ask for this?
Step 3: The theft — OTPs, PINs, and screen sharing
There are three common ways the money actually leaves your account:
- OTP theft. You receive a genuine one-time passcode texted by your real bank — because the scammer, on another line, is attempting a transfer or password reset on your account. The scammer asks you to read back “the verification code to confirm your identity.” You do, and they complete the theft. Your bank will never ask you for a code it just sent you.
- The “safe account” transfer. The scammer instructs you to move your money — by wire, Zelle-style payment, or even cash — to a “secure” or “protected” account. That account belongs to the scammer. The FTC’s rule of thumb: “Never move your money to protect it. That’s a scam.” [1]
- Screen-sharing and remote access. The scammer asks you to install a screen-sharing app (AnyDesk, TeamViewer, and similar) so the “fraud department” can “secure your device.” Once they can see your screen — or control your phone — they watch you enter passwords, approve transactions, and hand over everything they need.
Step 4: Variations on the script
- The card-collection scam. The FBI warns of a scheme where impersonators tell customers to cut up their bank card (leaving the chip intact), then send an “accomplice” to the customer’s home to collect it — obtaining the PIN through social engineering along the way. With the chip and PIN, they drain the account [3].
- The escalation chain. Fake bank rep → fake police/FBI agent → demands for secrecy and payment. The FBI notes scammers spoof trusted numbers, provide fake badge numbers, and insist communications stay “confidential” — real agents will never do this [4].
- Fake bank ads and lookalike websites. Scammers buy search ads impersonating banks, leading to phishing pages that harvest logins. Use your bank’s official app or a verified bookmark instead.
Why your bank will never ask for these things
Memorize this, because scammers rely on you not knowing it:
- Your bank will never ask for your one-time passcode (OTP). Not by phone, not by text, not by email. Ever.
- Your bank will never ask for your full PIN or online banking password.
- Your bank will never ask you to move money to a “safe account” to protect it from fraud. Real banks freeze suspicious transactions themselves; they don’t deputize you.
- Your bank will never ask you to install screen-sharing software.
- Your bank will never threaten you, demand secrecy (“don’t tell anyone, not even family”), or rush you off the phone so you can’t verify.
The FBI’s guidance is equally absolute for government impersonation, which scammers often layer onto bank scams: the FBI will never call or email private citizens to demand payment, threaten arrest, or request personal information — and real agents will never ask you to communicate via an encrypted messaging app [4].
Red flags of a bank impersonation scam: the checklist
- Caller ID shows your bank’s name — but the caller asks for information or actions. Spoofing makes caller ID meaningless as proof [3].
- Urgency and threats: “Your account will be emptied in 20 minutes,” “You’ll be arrested,” “Don’t hang up or the transfer can’t be stopped.”
- They ask for your OTP, PIN, or password — the single clearest signal. Hang up immediately.
- They tell you to move money to “protect” it — including to a “safe,” “secure,” or “government” account [1].
- They ask you to install a screen-sharing app or grant remote access to your phone or computer.
- They demand secrecy: “Don’t tell your spouse / don’t call the bank’s main number / this is confidential.” Secrecy serves the scammer, never you [4].
- They contact you first about fraud and then ask you to prove your identity to them. Real fraud departments verify themselves to you — or ask you to call back on a number you trust.
- Payment demanded in gift cards, crypto, wire transfers, or cash handoffs — no legitimate bank or government agency operates this way [4].
How to verify a real bank call: the 4-step rule
1. Hang up
It feels rude. Do it anyway. A real bank employee will understand completely — banks train their staff to expect this. You are not ending your banking relationship; you are ending a phone call.
2. Call the number on your card or statement
Find your bank’s phone number yourself: the back of your debit/credit card, your paper statement, or your bank’s official app (opened from your phone’s home screen, not from a link). Call that number and ask whether there is actually a fraud alert on your account. Never call back the number that called you, and never use a number or link from the suspicious message itself [2].
3. Log in independently
Open your bank’s app or type the bank’s web address into your browser yourself. Check your recent transactions. If there were genuinely suspicious transactions, you’ll see them — and your bank’s real fraud team will already have flagged or frozen them.
4. When in doubt, visit a branch
For large or confusing situations, walk into a physical branch. No phone scammer can follow you there.
One more critical habit: never act on a fraud alert text by tapping its links or calling its numbers. The FTC’s advice applies broadly — reach out using a phone number or website you know is real; don’t use the information from the message [2].
What to do if you shared an OTP or sent money
Act fast — the first hour matters most:
- Call your bank immediately on the number from your card. Tell them exactly what happened: which code you shared, what you authorized, and when. Ask them to freeze the account, reverse unauthorized transactions, and issue new cards/credentials.
- Change your passwords for online banking and any account sharing the same password. Enable app-based two-factor authentication if available.
- Report the fraud: In the US, file at ReportFraud.ftc.gov (FTC) and ic3.gov (FBI Internet Crime Complaint Center); the FBI specifically asks victims of bank impersonation schemes to report promptly and contact their financial institution immediately [3]. In the UK, report to Action Fraud and notify your bank — transfers made on or after 7 October 2024 may be covered by Payment Systems Regulator reimbursement rules for authorized push-payment fraud; ask your bank directly.
- Contact local police and get a crime reference number — your bank may require it.
- Monitor your accounts and credit reports for weeks afterward. Scammers who obtained your details may try again or sell them.
- Warn your circle. These scams spread through fear; telling family members — especially older relatives, who are disproportionately targeted — how the script works is genuine protection [1].
The bigger picture: why this scam keeps growing
The FTC’s data shows imposter scams were the #1 reported fraud category for the ninth year in a row, with more than 1 million reports in 2025 and reported losses up nearly 20% year over year to $3.5 billion [2]. Scammers reach victims through texts, calls, emails, social media, and even search-engine results [1].
Regulators are responding: the FTC finalized its Impersonation Rule in 2024, giving it stronger tools against scammers impersonating businesses and government agencies, and has since brought a dozen enforcement actions obtaining over $70 million in consumer redress [1]. But enforcement can’t keep pace with spoofing technology — which is why your own verification habits are the real defense.
Conclusion
A bank impersonation scam succeeds by borrowing your bank’s credibility — its name on your caller ID, its logo in a text — and spending it on manufactured panic. The defense is simple and absolute: your bank will never ask for your OTP, your PIN, or your password; it will never ask you to move money to “protect” it; and it will never object to you hanging up and calling back on a number you trust. Make that four-step verification a reflex — hang up, call the number on your card, log in independently, visit a branch if unsure — and the scammer’s entire script falls apart before your money moves.
Sources
- U.S. Federal Trade Commission, “FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025” (June 2026) — $3.5B in imposter-scam losses, ~$1B to business/bank impersonators, fake security alerts, the Impersonation Rule: https://www.ftc.gov/news-events/news/press-releases/2026/06/ftc-data-show-people-reported-losing-3-point-5-billion-imposter-scams-2025
- U.S. Federal Trade Commission, Consumer Advice, “New trends in reports of imposter scams” (May 2026) — #1 scam nine years running, 1M+ reports, verify via known-real numbers: https://consumer.ftc.gov/consumer-alerts/2026/05/new-trends-reports-imposter-scams
- FBI Internet Crime Complaint Center (IC3), PSA240802, “Safety Concern Related to Recent Trend in Financial Institution Customer Fraud Scheme” — bank impersonators, spoofed caller ID, card-chip collection scheme, reporting guidance: https://www.ic3.gov/PSA/2024/PSA240802
- Federal Bureau of Investigation, Boston Division, “FBI Boston Warns of New Agent Impersonation Scam Spoofing FBI’s Phone Number Before Urging Victims to Switch to Encrypted Application” (Aug. 19, 2026) — spoofing, fake badge numbers, urgency tactics, 32,424 victims / $797M+ in government impersonation losses in 2025: https://www.fbi.gov/contact-us/field-offices/boston/news/fbi-boston-warns-of-new-agent-impersonation-scam-spoofing-fbis-phone-number-before-urging-victims-to-switch-to-encrypted-application
Last reviewed: October 2026
This article is for education only and is not financial or legal advice.