Received a suspicious bank text? Learn how to spot fake bank text messages and bank scam texts, the warning signs to check, and how to verify a fraud alert safely.
A text message from your bank is designed to get your attention fast. It lands on the lock screen of the phone you carry everywhere, uses words like "fraud" or "unusual activity", and asks you to act before you have time to think. That urgency is exactly what scammers exploit. A fake bank text message copies the tone and format of a genuine alert, then steers you toward a link, a phone number, or a request for information your real bank would never make by text.
Bank impersonation is one of the most damaging forms of smishing (SMS phishing) because the stakes feel high and the window to respond feels short. According to the Federal Trade Commission, impersonation messages sent by text and email remain among the most reported fraud categories year after year, and bank-branded texts are a consistent favourite because almost every adult has a bank account.
The good news is that fake bank texts leave clues. This guide breaks down how these scams work, the warning signs you can check in under a minute, and how to verify a fraud alert safely without tapping anything in the message. Many of the same principles apply to text scams more broadly, which we cover in our guide on how to tell if a text message is a scam. Bank impersonation texts are one form of phishing, which we explain in our guide on what phishing is and how phishing scams work. If you want an instant assessment of a specific message, paste it into Scamlify's SMS Scam Checker.
The attack follows a predictable pattern. Understanding the steps makes the warning signs easier to spot.
The scammer sends a high-volume blast of text messages impersonating a bank. Common wording includes "Unusual activity detected on your account", "Your card has been suspended", "A payment of £450 was attempted", or "You have a new payee added". The message is short, references money, and creates a reason to act immediately.
The text either contains a link to a fake "verify" or "secure" page, or a phone number to call. Sometimes it asks you to reply with "STOP" or "YES" to confirm a transaction you never made. Every element of the message exists to move you off your bank's official app and onto a channel the attacker controls.
If you tap the link, you land on a convincing copy of your bank's login or verification page. It uses the real brand's colours, logo, and layout, and asks for your username, password, one-time passcode, or full card details. If you call the number, a "fraud agent" answers, builds trust, and talks you through transferring money to a "safe account" or reading back a code your real bank just sent you.
Once you submit your details or read back a code, the attacker has what they need. They log in to your real account, authorise a payment, or relay your one-time passcode into a live session. The whole interaction can take under a minute, and many victims only realise what happened when they check their balance hours or days later.
You do not need technical knowledge to spot a fake bank text. Run through these checks before you tap anything or call any number in the message.
This is the single most important check. Most legitimate UK and US banks do not send clickable links in SMS messages. A genuine fraud alert tells you something happened and asks you to log in through the bank's official app or a website you already trust. A bank text that contains a link asking you to "verify", "confirm", or "secure" your account is almost always a scam.
No real bank fraud team will ever text you to ask for your password, full card number, CVV, or a one-time login code. These details are never needed to "verify" your identity by text. If a message asks you to read back a code your bank just sent you, it is a scam. Real bank fraud teams never request your one-time passcode. If someone does, hang up and report it.
If there is a link, look at the domain before you tap. On most phones you can long-press a link to preview the destination without opening it. A genuine Barclays link uses barclays.com. A genuine Chase link uses chase.com. Anything else, such as barclays-secure-verify.com, chase-alert.support, or natwest-login-uk.net, is a lookalike. Watch for:
"Your account will be closed in 2 hours." "Confirm this £999 transfer now." "Respond immediately or your card will be blocked." Urgency is the scammer's most effective tool because it pushes you past the moment where you would normally stop and verify. Real banks do not close accounts or block cards within a two-hour window triggered by a text. If a message insists you must act immediately, that pressure is itself the warning sign.
Legitimate banks sometimes send texts, but a fraud alert from an ordinary mobile number, especially one you do not recognise, is a strong signal of spoofing. Sender IDs can be faked, so a name like "Barclays" or "Chase" on the message is not proof either. Your phone threads messages by sender string, and a spoofed ID can land in the same conversation as genuine alerts. If a message in a trusted thread suddenly asks you to do something unusual, do not assume the thread proves the sender.
Many fake bank texts name a specific amount, merchant, or payee to make the alert feel real. If you do not recognise the transaction, that is not a reason to tap the link. It is a reason to open your bank's official app and check your activity there. Scammers rely on the alarm of an unfamiliar charge to override your normal caution.
A text that tells you to call a "fraud hotline" or "security team" is trying to move you onto a channel where a fake agent can talk you into handing over details or moving money. If you want to call your bank, use the number printed on the back of your card or on your bank's official website, never the number in the text.
This is one of the most damaging variants. A fake agent, sometimes after a follow-up call, convinces you that your account is compromised and that you need to transfer your balance to a "safe account" for protection. No real bank will ever ask you to move money to a different account to keep it safe. This is always a scam, and the "safe account" belongs to the attacker.
Mass-sent scam texts use generic language: "Your account" rather than "Your Barclays account" often means the attacker is mass-sending before knowing which bank you use. Misspellings, odd capitalisation, or a brand name written incorrectly are all tells. A bank will almost never misspell its own name in an official message.
If a bank text has you worried, verify it through a channel you already trust, never the link or number in the message.
If none of these confirm a problem, the text is not real. Report it and delete it.
Act quickly. The faster you respond, the more you limit the damage.
Yes, and it is often faster and more reliable than checking each sign manually, especially when a message looks convincing. An AI scam checker reads the full text, evaluates the sender, the link, the language, and the behaviour the message asks for, and returns a risk score along with the specific warning signs it triggered.
If a bank text has you unsure, copy the message (and the sender, if visible) into Scamlify's SMS Scam Checker for an instant assessment. It runs the same checks described in this guide automatically, and it works for any suspicious text, not just bank scams. The same tool is useful if you receive a parcel-related message, which we cover separately in our guide to fake delivery text scams.
Some banks send security alerts by text, but they will not include a link asking you to "verify" or "confirm" your details, and they will never ask for a one-time passcode. If a bank text contains a link and a request for information, treat it as suspect and check in the app instead.
Not necessarily. Scammers send bank texts in huge volumes, and some recipients will have a recent transaction that roughly matches the wording. Recognising a transaction does not confirm the text is from your bank. Verify through the app or the number on your card.
No. Tapping a link can load a credential-harvesting page, trigger tracking, or in some cases attempt to install malware. Long-press the link to preview the destination where your phone supports it, and if you are unsure, do not tap. Verify through an official channel instead.
Tell your bank's fraud department immediately. One-time passcode relay scams move in under a minute, so speed matters. The bank can attempt to block the fraudulent transaction and secure your account.
No. Scammers impersonate whichever bank is most recognised in a given region, such as Barclays, NatWest, Lloyds, and HSBC in the UK, or Chase, Bank of America, Wells Fargo, and Citibank in the US. The pattern is the same regardless of the brand being faked.
The warning signs above are exactly what our tool checks for, instantly and for free. Use Scamlify's free SMS Scam Checker the next time a bank text feels off, and share it with someone who might need it.