Bank impersonation scams and the 'safe account' trick

    The single most expensive consumer scam is not a hacked account. It is a phone call that persuades an ordinary, careful person to move their own money, using their own banking app, of their own accord. Understanding the script is the defence, because the technology the caller relies on is easy to fake and the psychology is not.

    By Rui Matos · Cybersecurity Editor · Updated 18 September 2026

    How the call is set up

    The caller display can be forged. Spoofing a bank's published number is trivial, and many people treat a matching number as proof. The caller may also know your name, your address, the last four digits of a card, or a payment you genuinely made, all of which can come from a breach, a previous phishing page or a small test transaction they triggered themselves.

    Often the call follows something else: a fake delivery-fee payment, a lookalike login page, or a text warning of a suspicious transaction. The earlier step exists to make the call credible, which is why the two feel unrelated when they are not.

    The script, step by step

    First comes alarm: unusual activity has been detected, a payment to an unfamiliar merchant is pending, someone has tried to add a new device. Then comes authority: the caller offers to transfer you to the fraud department, or invites you to hang up and call back, while keeping the line open on older landlines.

    Finally comes the instruction. Move your balance to a 'safe account' opened in your name. Read out the code we just sent. Install this support tool so we can secure your device. Do not mention this to branch staff because the investigation is confidential. Each instruction is something no real bank will ever ask for.

    • 'We need to move your money to a safe account in your name'
    • 'Read me the code we just sent to your phone'
    • 'Install this remote support app so we can secure your device'
    • 'Do not discuss this with branch staff, it is a confidential investigation'
    • 'Withdraw the cash and hand it to our courier for safekeeping'

    The four rules that make the scam fail

    You do not need to identify a scam call to be safe from it. You only need a fixed habit: end any unexpected call about money and re-establish contact yourself, through the app or the number on your card. A genuine fraud team will find your case; a criminal cannot survive the callback.

    Wait a couple of minutes before dialling, or use a different phone, because on some landlines the original caller can hold the line open. Then verify in the banking app, which is the only channel that cannot be spoofed.

    • Banks never ask you to move money to another account
    • Banks never ask for a one-time code, PIN or full password
    • Banks never ask you to install remote-access software
    • Banks never send a courier for your card or cash
    • Any unexpected call about money ends, and you call back yourself

    Business variants: invoice and CEO fraud

    The same approach targets companies through changed bank details on a real invoice, or an urgent message that appears to come from a director asking for a quick payment. The email may come from a compromised mailbox in the supplier's own domain, so the address is genuine and the content is not.

    The control is procedural: any change to payment details is verified by calling a known contact on a number held in your own records, never one from the email, and payments above a threshold require a second approver.

    If you have already transferred money

    Call the bank immediately, on the number on your card, and use the words 'authorised push payment fraud'. Speed matters: funds are sometimes recallable within minutes and rarely after a day. Ask for the case to be logged formally and get a reference.

    Report to your national fraud reporting body, keep every message, screenshot and timestamp, and check whether reimbursement rules apply in your country. Then secure the surrounding accounts: change the email password first, review recovery options, and remove any remote-access software installed during the call.

    • Call the bank now, using the number on your card
    • Say 'authorised push payment fraud' and request a case reference
    • Report to the national fraud service and keep all evidence
    • Uninstall any remote-access app and scan the device
    • Change email and banking passwords from a clean device

    Frequently asked questions

    The number matched my bank exactly. How?

    Caller ID can be forged with ordinary calling software. A matching number proves nothing at all and should never be treated as verification.

    Is a 'safe account' ever real?

    No. No bank moves your balance to a different account to protect it. If your account is compromised, the bank blocks it, it does not ask you to make a transfer.

    Will I get the money back?

    It depends on your country, the payment type and how quickly you report. Some markets have mandatory reimbursement for authorised push payment fraud; others treat it case by case. Report within minutes if you can.

    They knew a recent transaction. Does that prove it was the bank?

    No. That detail often comes from a phishing page you used earlier, a breach, or a tiny test payment the criminals made themselves specifically so they could quote it.

    How do I protect an elderly relative?

    Agree one rule together: no money moves during an incoming call, ever. Write the bank's number on a card by the phone, and set up transaction alerts on a second phone if the bank allows it.