How the call is set up
The caller display can be forged. Spoofing a bank's published number is trivial, and many people treat a matching number as proof. The caller may also know your name, your address, the last four digits of a card, or a payment you genuinely made, all of which can come from a breach, a previous phishing page or a small test transaction they triggered themselves.
Often the call follows something else: a fake delivery-fee payment, a lookalike login page, or a text warning of a suspicious transaction. The earlier step exists to make the call credible, which is why the two feel unrelated when they are not.
The script, step by step
First comes alarm: unusual activity has been detected, a payment to an unfamiliar merchant is pending, someone has tried to add a new device. Then comes authority: the caller offers to transfer you to the fraud department, or invites you to hang up and call back, while keeping the line open on older landlines.
Finally comes the instruction. Move your balance to a 'safe account' opened in your name. Read out the code we just sent. Install this support tool so we can secure your device. Do not mention this to branch staff because the investigation is confidential. Each instruction is something no real bank will ever ask for.
- 'We need to move your money to a safe account in your name'
- 'Read me the code we just sent to your phone'
- 'Install this remote support app so we can secure your device'
- 'Do not discuss this with branch staff, it is a confidential investigation'
- 'Withdraw the cash and hand it to our courier for safekeeping'
The four rules that make the scam fail
You do not need to identify a scam call to be safe from it. You only need a fixed habit: end any unexpected call about money and re-establish contact yourself, through the app or the number on your card. A genuine fraud team will find your case; a criminal cannot survive the callback.
Wait a couple of minutes before dialling, or use a different phone, because on some landlines the original caller can hold the line open. Then verify in the banking app, which is the only channel that cannot be spoofed.
- Banks never ask you to move money to another account
- Banks never ask for a one-time code, PIN or full password
- Banks never ask you to install remote-access software
- Banks never send a courier for your card or cash
- Any unexpected call about money ends, and you call back yourself
Business variants: invoice and CEO fraud
The same approach targets companies through changed bank details on a real invoice, or an urgent message that appears to come from a director asking for a quick payment. The email may come from a compromised mailbox in the supplier's own domain, so the address is genuine and the content is not.
The control is procedural: any change to payment details is verified by calling a known contact on a number held in your own records, never one from the email, and payments above a threshold require a second approver.
If you have already transferred money
Call the bank immediately, on the number on your card, and use the words 'authorised push payment fraud'. Speed matters: funds are sometimes recallable within minutes and rarely after a day. Ask for the case to be logged formally and get a reference.
Report to your national fraud reporting body, keep every message, screenshot and timestamp, and check whether reimbursement rules apply in your country. Then secure the surrounding accounts: change the email password first, review recovery options, and remove any remote-access software installed during the call.
- Call the bank now, using the number on your card
- Say 'authorised push payment fraud' and request a case reference
- Report to the national fraud service and keep all evidence
- Uninstall any remote-access app and scan the device
- Change email and banking passwords from a clean device
