Fake bank SMS and security officer scam: spot phishing before you pay
Last updated:
The fake bank security officer scam (vishing paired with credential harvesting) is one of the most financially damaging cyber scams. Victims often lose thousands of euros while believing they are assisting their bank's anti-fraud department.
The two-step attack method
Scammers combine an urgent SMS alert to steal initial login credentials, followed by a reassuring phone call to trick victims into bypassing strong customer authentication on their mobile banking app.
Typical progression of the scam
- Step 1 (Urgent SMS bait): “Security alert: a payment of €940.00 is pending. If unauthorized, cancel urgently at [Link]”.
- Step 2 (Credential theft): The victim clicks and enters their username and password on a cloned login screen.
- Step 3 (The phone call): Minutes later, a polite scammer calls using a spoofed caller ID matching the bank.
- Step 4 (The trap): The caller asks the victim to approve in-app notifications or read SMS codes to “cancel the charge”, which actually authorizes the thief's transfer.
Golden rules of banking safety
| Scenario | What your real bank does | What scammers ask for |
|---|---|---|
| Suspicious transaction | Freezes the transaction internally without asking for approval | Asks you to validate an in-app approval notification |
| Security passcodes | Never asks for secret PINs, passwords, or SMS codes | Requests secret codes to “cancel” charges |
| Fund protection | Secures your existing account directly | Asks you to transfer funds to a “secure temporary account” |
What to do if targeted
- Hang up immediately if an incoming caller asks you to validate mobile app notifications.
- Never click links inside banking text messages: open your official app directly.
- When in doubt, call the phone number printed on the back of your physical payment card.
- If credentials were submitted: freeze your accounts immediately and file a police fraud report.
How Resku stops the attack at step one
The fraud relies on harvesting your credentials on the fake web portal. Resku evaluates domain ownership, newly created certificates, and trapped forms in ~200 ms to block the deceptive page before you type.
Official resources
- Banque de France / European Banking Authority : guidance on payment fraud and consumer rights.
- Cybermalveillance.gouv.fr : advisory guide on bank impersonation scams.
- Pharos (internet-signalement.gouv.fr) : online cybercrime reporting portal.
Frequently asked questions
Will a bank ever call or text you to cancel a fraudulent transaction?
No, never. Legitimate bank anti-fraud departments block suspicious transactions internally. They will never ask you to approve a mobile notification, disclose one-time SMS passcodes, or send test wire transfers to “secure” your funds.
How does the fake bank security officer scam work?
The attack begins with an alarming text message (“Suspicious transfer of €950, click to dispute”). When you enter your credentials on the fake portal, a scammer calls you immediately, spoofing your bank's phone number, and walks you through authorizing fraudulent charges in your banking app.
Why does the incoming caller ID match my actual bank?
Scammers use caller ID spoofing technology. Any phone number can be displayed on your caller screen without genuinely originating from that organization.
What should you do if you shared your banking credentials?
Hang up immediately. Open your official banking app independently, change your password, and call your bank's emergency fraud line to freeze cards and dispute unauthorized debits.
Cloned banking portals steal credentials before the fake caller even rings. Resku flags fraudulent banking clones and blocks the site instantly.
Join the waitlist