Table of Contents
ToggleA financial message may be a phishing scam when it pressures you to click a link, verify an account, provide a password, share a security code, or move money quickly. The sender may pretend to be your bank, credit card company, payment app, tax agency, employer, or a government department.
Do not use the link, telephone number, QR code, or reply button in the message. Open the company’s official app, type its address into your browser, or call the number printed on your card or statement.
The catch is that fake messages can look polished. They may include the correct logo, your name, part of an account number, and details from a real purchase or data breach.
You do not have to prove that a message is fake. You only need to verify the claim through a separate channel before giving away information or money.
Key takeaways
- Phishing messages impersonate trusted organizations to steal information, money, or account access.
- Email phishing, text-message smishing, voice phishing, and QR-code phishing use the same basic trick.
- Urgency, fear, unexpected refunds, and threats of account closure are common warning signs.
- Never share a password, PIN, or one-time security code with someone who contacted you unexpectedly.
- A bank will not ask you to move money to a “safe” account to protect it.
- Caller ID, logos, professional grammar, and familiar message threads do not prove that a message is real.
- Use the official app or a trusted telephone number to verify suspicious activity.
- If you entered a password on a fake site, change it immediately and secure any account using the same password.
- If you sent money, contact the bank or payment company immediately and ask whether the transfer can be stopped or reversed.
- Report phishing attempts, then delete them.
What is a phishing scam?
Phishing is a scam in which criminals send messages that appear to come from a trusted person or organization. The message tries to persuade you to reveal information, open a harmful attachment, visit a fake website, or send money.
The FTC explains that phishing emails and texts commonly attempt to steal passwords, Social Security numbers, bank account details, and credit card information. Stolen information may then be used to access existing accounts or commit identity theft.
The message is the bait.
The link, attachment, telephone number, QR code, or requested reply is the hook.
Phishing can arrive through several channels
- Email phishing: A fake email appears to come from a bank, retailer, government agency, employer, or service provider.
- Smishing: A phishing attempt arrives by SMS or another text-messaging service.
- Vishing: A scammer calls or leaves a voice message while pretending to represent a trusted organization.
- Quishing: A message, letter, parking notice, or sign contains a QR code that leads to a fake website.
- Spear phishing: The message is tailored using information about a particular person, household, or workplace.
The delivery method changes.
The financial goal is usually the same: obtain information, gain access, or persuade you to make a payment.
Why fake financial messages are effective
Financial messages already involve subjects that create a strong reaction:
- A suspicious card purchase
- A frozen bank account
- A missed loan payment
- A tax refund
- A debt collection claim
- A benefit suspension
- A loan approval
A scammer does not need you to believe the message for an hour.
It only needs you to react for 30 seconds.
The message creates a problem and offers the button that fixes it
A typical phishing message follows this pattern:
- Something has gone wrong.
- You must act immediately.
- The message gives you a link, number, or code to use.
For example:
“Your account has been restricted because of suspicious activity. Verify your identity within 30 minutes to prevent permanent closure.”
The safest response is not to use the offered solution.
Open the official banking app and see whether the same warning appears there.
Scammers borrow trust from real companies
A scammer may copy:
- A bank logo
- A familiar color scheme
- A real employee’s name
- Official-looking legal language
- A government seal
- A genuine customer service number
Caller ID and sender names can also be spoofed. The FBI’s Internet Crime Complaint Center advises people not to trust caller ID and to call companies back using a telephone number found independently. It also warns that companies generally do not contact customers to ask for usernames, passwords, or one-time passcodes.
Warning sign 1: the message creates urgency
Urgency is one of the most common phishing tools.
The message may say:
- “Respond within 15 minutes.”
- “Final warning.”
- “Immediate verification required.”
- “Your account will be closed today.”
- “Your payment has failed.”
CISA identifies urgent or emotionally appealing language as a common phishing sign. The purpose is to move you into action before you check whether the claim is true.
A legitimate problem may need attention.
It rarely requires you to trust an unexpected link without verification.
Warning sign 2: it asks you to verify financial information
A fake bank message may ask you to confirm:
- Your account number
- Online banking password
- Debit card number
- Card security code
- Social Security number
- Date of birth
- Home address
The CFPB warns that an email or text asking you to verify bank or credit union account information may be phishing. It advises contacting the institution directly rather than using information in the message.
Your bank may send a genuine fraud alert asking whether you recognize a transaction.
That does not mean you should provide your complete card number, login password, or PIN in the reply.
Warning sign 3: it asks for a one-time security code
One-time codes are designed to confirm that the person logging in has access to your phone, email, or authentication method.
A scammer may already have your username and password. The remaining obstacle is the security code sent to you.
The scammer may say:
- “Read me the six-digit code to cancel the transfer.”
- “Reply with the code to confirm you are the account owner.”
- “The code is required to reverse the fraud.”
Do not share it.
A security code may authorize the exact login, password reset, new device, or transfer the scammer claims to be stopping.
If you receive a login approval request you did not initiate, reject it and change the account password through the official app.
Warning sign 4: the link does not match the company
A phishing link may resemble the real address with a small change.
Examples might include:
- An extra letter
- A missing letter
- A hyphen added to the company name
- A different domain ending
- A long address that hides the real domain
- A shortened link
On a computer, hovering over a link may show where it leads. On a phone, pressing and holding may display a preview.
Do not depend on link inspection alone.
A convincing fake address can still fool a careful reader. Opening the official app yourself is safer.
Warning sign 5: the sender address looks almost right
The display name may say “Fraud Department” or show the exact name of your bank.
Open the sender details.
You may find:
- A free personal email account
- A misspelled domain
- A string of random letters
- A different company name
- An unusual reply-to address
An official-looking sender address is useful evidence, but it is not final proof. Email accounts and legitimate message threads can be compromised.
Verify the request separately when it involves money, passwords, invoices, or account changes.
Warning sign 6: it asks you to move money for protection
A fake bank representative may claim that your account has been compromised and your money must be transferred to:
- A safe account
- A secure wallet
- A government holding account
- A temporary protection account
- Another account in your own name
Do not transfer the money.
The “safe account” belongs to the scammer.
Government impersonators also use this method. The FBI warns that fake officials may offer to protect financial accounts while demanding an upfront payment or transfer to a supposedly secure account.
A real bank can protect an account internally. It does not need you to send your savings to a stranger’s routing number.
Warning sign 7: it requests an unusual payment method
Be suspicious when a financial or government message demands payment through:
- Gift cards
- Cryptocurrency
- A wire transfer
- A payment app
- Prepaid debit cards
- Cash sent by courier or mail
- Gold or another precious metal
These payment methods can be difficult to trace and reverse.
The Social Security Administration warns that scammers may demand gift cards, cryptocurrency, wire transfers, cash, prepaid cards, or precious metals. It advises people to pause, ignore suspicious messages, and verify the situation separately.
Taxes, fines, account problems, and benefit issues are not resolved by buying gift cards at a grocery store.
Warning sign 8: the attachment is unexpected
A phishing email may attach:
- An invoice
- A payment receipt
- A bank statement
- A loan document
- A tax notice
- A shared file
- A voicemail transcript
The attachment may install harmful software or send you to a fake login page.
Be careful even when the file looks like a PDF or ordinary document. File names and icons can be misleading.
If the message claims that your bank has sent a statement, sign in through the official banking app and retrieve it there.
Warning sign 9: the QR code demands action
QR codes hide the destination until they are scanned.
A fake code may appear in:
- An email
- A text attachment
- A parking notice
- An invoice
- A letter claiming to come from a bank
- A flyer offering a financial benefit
The FTC warns that a malicious QR code can direct you to a convincing fake website or cause harmful software to be downloaded. Information entered on the fake site may be stolen.
Do not scan a code merely because the message says it is safer than clicking a link.
Open the official website or app instead.
Warning sign 10: it offers unexpected money
Not every phishing message uses fear.
Some use excitement:
- A tax refund
- A government payment
- A loan approval
- A class-action settlement
- A prize
- A rebate
- An investment opportunity
A January 2026 FTC warning described fake loan texts that claimed the recipient had reached the final step of a loan process. Replying or providing information could lead to identity theft.
A separate 2026 warning described fake tax refund texts and emails designed to steal information that could be used for tax fraud or identity theft.
Unexpected money is still unexpected.
Check whether you actually applied, filed a claim, or have an account with the sender.
Warning sign 11: the message contains information about you
A message is not proven legitimate because it knows:
- Your full name
- Your address
- Your employer
- Your bank
- The last four digits of an account
- A recent purchase
Personal information can come from data breaches, public records, social media, stolen mail, compromised accounts, or earlier scams.
A targeted message may be more convincing because it uses real details.
Treat those details as part of the disguise, not proof of identity.
Warning sign 12: it looks polished
Poor spelling can expose a scam.
Perfect spelling does not prove that a message is real.
Criminals can copy templates, use official graphics, and produce fluent messages with artificial intelligence. The FBI has warned that criminals use generative AI to create convincing text, images, video, and voice content for financial fraud and impersonation.
A 2026 Social Security warning described fraudulent statement emails using official-looking wording, logos, colors, and formatting. The messages led to fake sites or harmful downloads.
“It looks professional” is no longer a useful safety test.
Common fake financial messages
Fake bank fraud alert
The message says a purchase was attempted and asks you to click a link or reply with account details.
A genuine alert may ask whether you recognize a transaction. Verify it in the banking app. Do not provide login credentials or a security code through the message.
Fake payment app transfer
The message claims that a transfer is pending, a payment failed, or your account must be upgraded before money can be received.
Open the payment app directly and review the account. Do not send money to receive money.
Fake tax refund
The message promises an unclaimed refund or says you need to confirm banking details.
The IRS warns that phishing and smishing scams use fake refunds, tax credits, payment demands, and legal threats to obtain information or money. It advises taxpayers not to click unexpected links or attachments.
Fake Social Security warning
The message says your Social Security number has been suspended, linked to criminal activity, or placed under investigation.
Social Security scam texts have threatened legal action and asked recipients to call a number to resolve an alleged problem. SSA advises people to ignore suspicious messages, avoid links and attachments, and verify matters through official channels.
Fake loan approval
The message says you have been approved for a loan you did not request, or that one final verification step is needed.
The goal may be to collect your Social Security number, bank details, or an advance fee.
A lender does not need payment by gift card before releasing a legitimate personal loan.
Fake subscription or invoice
The email claims that a large renewal, purchase, or computer security charge has been processed.
The message provides a telephone number to cancel.
Calling connects you to the scammer, who may ask for remote access to your device or banking account.
Fake delivery fee
The text says a package cannot be delivered until you update your address or pay a small fee.
The amount may be only $1 or $2. The fake page is designed to capture the card number and personal information rather than collect the small fee. The FTC has warned consumers about bogus delivery messages that link to fraudulent sites.
Use the 30-second verification rule
Before interacting with an unexpected financial message, take these steps.
1. Stop
Do not click, reply, call, scan, or download.
2. Identify the claim
What does the message say happened?
Write it in plain language:
“The message claims my debit card was used for a $420 purchase.”
3. Open the official account
Use an app you already installed or type the known address into your browser.
Do not copy the address from the suspicious message.
4. Check activity and notifications
Look for the transaction, warning, secure message, or notice.
5. Call a trusted number when needed
Use the number printed on the back of the card, shown on a statement, or listed in the official app.
The FTC recommends contacting the company through a telephone number or website you know is real rather than using information in an unexpected text.
What to do with a suspicious message
Do not reply
Replying can confirm that your number or email address is active.
Do not reply with “STOP” unless the message is from a legitimate company whose marketing texts you originally agreed to receive.
Do not click the unsubscribe link
A real marketing email should provide an unsubscribe method.
A phishing email may use the unsubscribe button as another harmful link.
Use your email provider’s spam or phishing reporting feature instead.
Take a screenshot when useful
A screenshot can help when reporting the message to your bank, employer, government agency, or fraud investigator.
Do not keep opening the message to study it.
Report and delete it
The FTC advises forwarding phishing texts to 7726, using email-provider reporting tools, and reporting scams to the FTC.
Report impersonation to the organization being copied as well. Banks, payment services, retailers, and government agencies often have their own fraud-reporting methods.
What to do if you clicked the link
Clicking does not always mean your identity has been stolen.
What you did after clicking determines the next steps.
You clicked but entered nothing
Close the page.
Do not download files or approve notifications. Update your browser and device software, then run a security scan when you believe the link may have downloaded something.
The FTC advises updating security software, scanning the device, and removing anything identified as harmful after clicking a phishing link or opening an attachment.
You entered a password
Change that password immediately through the official website or app.
Then:
- Sign out other devices and sessions.
- Turn on multifactor authentication.
- Check account recovery email addresses and telephone numbers.
- Review recent logins and security events.
- Change the password anywhere else you reused it.
Start with your email account when the same password was reused. Email often controls password resets for your other accounts. The FTC warns that a criminal with access to email may intercept reset messages and use them to take over more accounts.
You entered bank or card information
Contact the bank or card issuer immediately.
Ask it to:
- Block or replace the card
- Review recent transactions
- Flag the account for fraud
- Change the account number when necessary
- Explain how to dispute unauthorized transactions
Do not wait for a purchase to appear.
You shared a one-time security code
Assume the scammer may have accessed the account.
Call the financial institution immediately, change the password, review transfers and account details, and remove unfamiliar devices.
Check whether:
- A new recipient was added
- A transfer was scheduled
- The contact email changed
- A digital wallet was linked
- A new device was trusted
You downloaded an attachment
Stop signing in to sensitive accounts from that device until it has been checked.
Disconnect it from the internet when you believe harmful software is active. Update the security software, run a scan, remove identified malware, and change passwords from a clean device.
The FTC recommends avoiding online banking and other sensitive logins on a possibly infected device until the malware has been addressed.
What to do if you sent money
Contact the company that handled the payment immediately.
Tell it that the transaction resulted from fraud and ask whether it can be stopped, recalled, disputed, or reversed.
Contact:
- Your bank for a wire or bank transfer
- The card issuer for a card payment
- The payment app for an app transfer
- The gift card issuer for a gift card
- The cryptocurrency platform for a crypto transfer
Recovery is not guaranteed.
Speed matters.
Also report the incident to the FTC and, for internet-enabled financial crime, the FBI’s Internet Crime Complaint Center. The CFPB directs consumers to those reporting channels for suspected scams.
Do not pay a recovery scammer
After losing money, you may be contacted by someone claiming to be an investigator, lawyer, government official, or recovery specialist.
The person promises to recover the loss after you pay a fee.
This may be another scam using information from the first one.
What to do if you shared identity information
Identity information may include:
- Your Social Security number
- A photograph of your driver’s license
- Your passport details
- Your date of birth
- Health insurance information
- Answers to security questions
Report the exposure through the FTC’s identity theft recovery system and follow the steps based on the information involved. The FTC specifically directs people whose Social Security number, account number, or other identity information was exposed through phishing to use that recovery process.
Depending on the information lost, consider:
- Freezing Equifax, Experian, and TransUnion
- Placing a fraud alert
- Replacing compromised identification
- Contacting your health insurer
- Securing tax and government accounts
- Checking credit reports for unfamiliar activity
Protect your accounts before the next message arrives
Use a different password for every important account
A reused password turns one fake login page into access to several accounts.
Use a password manager to create and store long, unique passwords. CISA recommends strong passwords and a password manager as basic protections against account and financial theft.
Turn on multifactor authentication
Multifactor authentication adds another login requirement beyond the password.
Depending on the account, this may involve:
- An authenticator app
- A security key
- A device prompt
- A biometric check
- A texted code
CISA advises enabling multifactor authentication on important accounts because it makes access harder even when a password is compromised. Phishing-resistant methods, including security keys and supported passkeys, provide stronger protection than a code that can be shared with a scammer.
Turn on account alerts
Set financial alerts for:
- Every card transaction
- Bank transfers
- ATM withdrawals
- New payees
- Contact information changes
- Password resets
- New device logins
A real alert may help you detect account misuse quickly.
Still verify it through the official app rather than clicking the message.
Install updates
Software updates fix known security weaknesses. CISA recommends enabling automatic updates for devices and applications so security fixes are installed promptly.
Protect your email first
Your email account may contain financial statements, identity documents, receipts, and password-reset messages.
Use a unique password and strong multifactor authentication. Review forwarding rules and recovery settings occasionally, especially after a suspicious login.
Special rules for government messages
IRS messages
The IRS warns that scammers use fake refunds, tax debts, legal threats, and account problems to pressure taxpayers into clicking links or giving away information.
Do not use an unexpected link claiming to come from the IRS. Report suspicious tax-related emails and texts according to IRS phishing instructions.
Social Security messages
Ignore messages claiming that your Social Security number has been suspended, that immediate legal action is coming, or that benefits will stop unless you pay.
SSA advises people not to click suspicious links or attachments and never to pay through gift cards, cryptocurrency, wire transfer, or cash.
Messages with badges and government documents
A photograph of a badge, letter, case file, or official credential is not proof.
Federal agencies have warned that impersonators send real or altered images of credentials to make demands appear legitimate.
End the conversation and contact the agency independently.
Phishing at work
A workplace phishing message may pretend to come from:
- Your manager
- Payroll
- Human resources
- An executive
- A supplier
- The information technology department
Common requests include:
- Changing direct deposit details
- Buying gift cards
- Opening an invoice
- Resetting a password
- Sending employee tax information
- Updating a supplier’s bank account
Verify unusual financial requests through another method. Call the manager, supplier, or employee using a known telephone number.
Do not reply to the same email asking whether the request is real. A criminal controlling the account will simply say yes.
CISA advises organizations to train staff to recognize urgent requests, strange financial instructions, unexpected links, and attempts to obtain sensitive information.
Common phishing myths
A real logo means it is safe
No. Logos and templates are easy to copy.
Scam emails always contain spelling mistakes
No. Some do, but many are polished and may use AI-generated text.
The sender knows my name, so it must be real
No. Names, addresses, employers, and account details may have been exposed elsewhere.
Caller ID proves who is calling
No. Telephone numbers and business names can be spoofed.
Clicking is safe as long as I do not enter information
It is safer than entering credentials, but a link or attachment may attempt to install harmful software. Close the page and scan the device when needed.
A small payment is not worth stealing
A $1 delivery fee may be bait used to capture your complete card details.
A security code is safe because it expires
No. It can be used immediately to access an account or authorize a transaction.
A bank employee can ask me to transfer money to safety
No legitimate bank needs you to transfer your funds to an outside account to protect them.
Frequently asked questions
How can I tell whether a bank text is real?
Do not decide from the text alone. Open the bank’s official app or call the number printed on your card. Check whether the transaction or account warning appears there.
Do banks send fraud alert texts?
Many do. A genuine alert may ask whether you recognize a transaction. It should not require your full password, PIN, card details, or one-time login code.
Should I reply to a suspicious text?
No. Do not reply, click, or call the supplied number. Report it as spam or phishing and verify the claim independently.
Can opening a phishing email infect my phone or computer?
Simply viewing a message is usually less risky than opening an attachment, clicking a link, granting permission, or installing software. Keep your device and email software updated.
What should I do if I clicked but entered nothing?
Close the page, update security software, and run a scan when a download may have occurred. Watch the device and accounts for unusual activity.
What should I do if I entered my password?
Change it immediately through the official site, sign out other sessions, enable multifactor authentication, and change any other account using the same password.
What if I gave the scammer a security code?
Contact the affected institution immediately. Change the password, remove unknown devices, and review transfers, contact details, and security settings.
Can a phishing message appear in a real conversation thread?
Yes. A compromised email or messaging account can be used to send fake payment instructions inside an existing conversation. Verify bank-detail changes through a separate channel.
Are QR codes safer than links?
No. A QR code can hide a link to a fake website or harmful download. Use the organization’s official app or address instead.
Can scammers copy a bank telephone number?
Yes. Caller ID can be spoofed. End the call and use a known number from your card, statement, or official app.
Should I call the telephone number in a suspicious email?
No. The number may connect directly to the scammer. Find the real number independently.
What if the message mentions a real purchase?
Check the official account. A real detail may have been obtained from a compromised retailer, email account, receipt, or earlier data breach.
How do I report a phishing text?
Use your phone’s spam-reporting function and forward the message to 7726. You can also report it to the FTC and the company being impersonated.
How do I report a fake IRS message?
Do not reply or click. Follow the IRS process for sending suspected tax-related phishing emails and text information to its phishing reporting team.
What if I already sent money?
Contact the payment provider immediately and request a stop, recall, or reversal. Report the fraud to the FTC and the FBI’s Internet Crime Complaint Center.
Should I freeze my credit after phishing?
Consider freezing all three reports when you shared your Social Security number or enough identifying information for someone to open accounts. A password-only incident may require account security steps rather than a credit freeze.
Step away from the message
A phishing message wants to keep you inside its version of events.
It gives you the problem, the deadline, the telephone number, and the button that supposedly fixes everything.
Leave that path.
Open the real app. Call the number on your card. Ask the company whether the warning exists. Take five minutes when the message says you have only two.
That small pause breaks the scammer’s control.
You do not need to become a cybersecurity expert. You need one dependable habit:
Never use an unexpected financial message to verify an unexpected financial message.