MalwareZero

Fake bank fraud alert text: why replying NO sets up the call

Updated August 6, 2026

A text reading "FRAUD ALERT: did you authorize a $847.32 charge? Reply YES or NO" is not automatically fake, and that's the whole problem. Real banks send that exact kind of message. What separates the genuine one from the scam is what happens about a minute after you reply NO: your phone rings, the caller ID says your bank, and a very calm person starts walking you toward moving your own money. One rule defeats all of it. Hang up and dial the number printed on the back of your card.

Your Bank (spoofed)Text message
SCAM, NOT REALFRAUD ALERT: Did you authorize a $847.32 charge? Reply YES or NO
Recreated example of the wording used in this scam. Not a real captured message; built to match the pattern described on this page.

Why replying NO is the trap

Replying does two jobs for the scammer, and neither one has anything to do with the fake charge. It confirms your number is live, read by a human, and attached to someone who banks somewhere. It also plants the idea that fraud is already happening to you, which is the emotional groundwork for the call.

By the time your phone rings, you're not being cold-called by a stranger. You're being called back about a problem you already believe in. That's a completely different conversation, and the people running this know it.

Replying YES isn't safer. It just switches the script to "we blocked that transaction, now we need to secure your account." Same destination, different opening line.

The callback, and why the number looks right

Caller ID is not evidence. Spoofing the number printed on the back of your debit card costs a few dollars of internet calling service, and it's been trivial for years. Hold music, a case reference number, a badge ID they'll cheerfully repeat twice: all free to fake.

The caller often knows things about you. Your name, your city, the last four digits of a card. That doesn't prove they work at your bank. Breach data and data broker files are cheap, and a convincing opening line takes almost nothing to assemble.

The FBI's Internet Crime Complaint Center published a warning about this pattern in November 2025. Its figures: since January 2025, IC3 logged more than 5,100 account takeover complaints with losses above $262 million, driven largely by criminals impersonating financial institution support staff by text, phone, and email. That advisory describes a version where a second person joins the call posing as law enforcement, and scripts claiming fraudulent purchases (including firearms) were made in your name. That detail exists purely to frighten you into cooperating fast.

What they're actually after

The safe account con

At some point the language shifts. They'll say your account is compromised and the balance has to move to a "secure" or "protected" account while the investigation runs. Or the version that shows up most often in loss reports: the fraudulent transfer supposedly already cleared, and to reverse it you need to send the same amount back to yourself through Zelle.

None of that exists. Banks freeze cards, close accounts, and issue new numbers. They don't ask you to push money out to fix a problem, and no legitimate fraud department has ever needed you to open a payment app to cancel something. The FTC makes the identical point about government impersonators: real agencies never tell you to move money to protect it, never send you to a Bitcoin ATM, and never ask you to buy gold bars or hand cash to a courier. Your bank is no different.

Once that transfer leaves, you're in far worse shape than a disputed card charge, for reasons laid out on our page about Zelle and Venmo scam texts. Short version: your finger hit send, so federal rules treat the payment as authorized, and "authorized" is a much colder place to stand.

The rule, stated plainly

Hang up. Call the number on the back of your card, or the contact number inside your banking app. Not the number in the text. Never the number the caller reads out to you. And skip the top search result too, because IC3 specifically flags paid ads placed to look like legitimate support listings.

If the caller insists on staying on the line while you "verify," that's your answer right there. Use a different phone, or just wait sixty seconds before dialing. Real fraud departments don't mind being called back. Being called back is their entire job.

If you already replied, or already talked to them

Move quickly, roughly in this order. Call your bank using the card number and say plainly that you may have been targeted by a bank impersonation scam. Change your online banking password from a different device and sign out every active session. Then go looking for anything added while you were on the phone: new payees, a changed phone number or email, a card added to a digital wallet.

For genuinely unauthorized transfers, federal Regulation E gives you deadlines that actually matter. Report within two business days of learning about it and your liability is capped at $50. Wait longer and your exposure grows, and once 60 days pass from the statement showing the transfer you can lose the protection altogether. After you report, the bank generally gets 10 business days to investigate; if it needs the full 45 days allowed, it's supposed to hand you provisional credit in the meantime, though it may withhold up to $50 of that.

Report the text by forwarding it to 7726, which spells SPAM on a keypad and routes the message to your carrier. File at reportfraud.ftc.gov, and at ic3.gov if money actually moved. If you want to talk it through with a person, the AARP Fraud Watch Network helpline is 877-908-3360, weekdays 8am to 8pm Eastern, free, and you don't need to be a member. Our checklist for after you've tapped something you shouldn't have covers the device and credential cleanup in more detail.

How worried should you actually be

Less than the headlines suggest, provided you never take the callback seriously. The FTC's 2025 figures show $3.5 billion in reported imposter scam losses out of roughly $16 billion in total reported fraud, and scams that began with a text accounted for about $470 million in 2024. Big numbers. They also concentrate almost entirely among people who engaged with the message. Deleting it costs you nothing at all.

I couldn't find any credible public figure for what share of these texts turn into a callback, and I'd be skeptical of anyone quoting one. What the reports do consistently show is the same four-step sequence: text, reply, phone call, transfer. Break it anywhere and the scam dies.

Tell your mother. Not about the text, she'll delete a bad text on her own, but about the call that lands a minute after she replies, with her bank's real number sitting on the screen and a calm, apologetic person on the other end of it. Give her the one sentence that ends the whole thing: "I'll call the number on my card." Then she hangs up and does exactly that. And while you've got her on the phone, agree on a phrase a cloned voice couldn't guess, because the same crews run more than one script. Our safe word generator takes about a minute, and the page on AI voice cloning scams explains what these tools can and can't do with a few seconds of her voice.