
Texts and calls
Your bank just texted about fraud. Is it really them?
Updated 6 October 2026
You are sitting in the drive-through when a text lands: suspicious activity on your card, reply YES or NO. The reflex is to reply, because that is exactly what your bank tells you to do, and that reflex is the most expensive habit in your phone right now. The texts that are costing people their savings look almost identical to the ones that are not, and the gap is measured in seconds and one careless word.
The pig butchering pivot, and why the bank text is stage two
For most of the last decade, the bank impersonation text was a one-shot smash and grab: a fake link, a fake login page, drained account, move on. That version is still around. What your bank is actually seeing in October 2026 is a different animal, and it is built on top of a scam the industry calls pig butchering, named for the long patient fattening of a mark before the cut.
Here is how the new version runs. A wrong number text opens the conversation, friendly, short, builds a few days of small talk, then pivots to crypto, investments, a job, a side hustle, or a romance. The money you are persuaded to move often lands at a bank you have never heard of, opened in your name by someone who bought your details on a people-search site, or opened by a money mule who thinks they are doing remote work. The fraud alert you then receive is sometimes real, because your bank has noticed a stranger draining an account you did not know existed, and sometimes fake, sent by the same criminal to push you into a second decision while you are still confused.
The FBI logged more than $4 billion in pig butchering losses in 2023, and the 2024 Internet Crime Report pushed the 2024 figure to $5.8 billion, with roughly half of victims between thirty and forty nine. By 2026 the pattern has hardened: the investment phase ends at a fake platform or a real bank under the criminal's control, and the recovery attempt becomes its own scam. The text that says, we have frozen your account, call this number, is almost always the next hand on the knife.

What a real bank fraud text looks like, line by line
The follow-up call is the real scam
You reply NO. A minute later your phone rings. The caller ID says Chase, or the fraud department, or even a number that matches the one on the back of your card. This is the moment the average loss jumps from a couple of hundred dollars to five figures, because the voice on the other end is calm, professional, sympathetic, and very good at their job. They already have the last four of your card, the merchant, the dollar amount, and possibly a piece of information they bought on a people-search site such as your home address, your date of birth, or the make of your car.
They will walk you through a verification script that feels real, including the last four of your SSN, because that is also for sale. They will then offer to help you secure the account, which means reading back the one time code your bank is sending you right now, a code you asked for, a code the bank is sending because the criminal triggered it. The second you read that six digit number aloud, the criminal uses it to add their device to your account, lock you out, and start the wire.
The law, in the one sentence that matters
Under the Electronic Fund Transfer Act, implemented by Regulation E, your liability for unauthorised card charges is capped at fifty dollars if you report the card lost or stolen within two business days, and capped at five hundred dollars if you wait longer. Most banks, in practice, waive even that, but the clock starts when you notify the bank, not when you notice the charge, and not when you call the number the scammer gave you. The 2024 EFTA amendments, effective April 2026, also require that any consumer who reports unauthorised instant payments through Zelle, Venmo, Cash App, or a similar service be treated under the same two day window, reversing the longstanding peer to peer carve out.
For the investment phase, where the losses are usually largest, the Securities and Exchange Commission and the Commodity Futures Trading Commission treat any crypto or forex platform not registered with them as presumptively fraudulent, and FinCEN treats the bank that processes the withdrawal as having a reporting obligation. None of that gets your money back by itself, but it determines which agency you file with, and which agency has the power to freeze the receiving account before the funds are swept.
What to do in the first ten minutes if you already replied
Step one, call your bank using the number on the back of your card or on the most recent statement. Do not call the number in the text. Do not call the number that just called you. From a different phone if you can, in case the criminal is still on the line. Step two, ask the bank to disable your online banking, rotate your password, and reissue the card, even if the card itself was not used. Step three, if a one time code was read aloud, ask the bank to treat the account as compromised, not just suspicious, because device additions look identical to legitimate sign-ins for the first twenty four hours.
If the loss is investment sized, meaning more than ten thousand dollars, the bank cannot refund it the way it refunds an unauthorised card charge, and you need a different process. Ask the bank for the receiving account details, including the name on the receiving account, the routing number, and the receiving bank, then file a report with the Internet Crime Complaint Center at ic3.gov the same day, and a second report with the Federal Trade Commission at reportfraud.ftc.gov. The IC3 report is the one that goes to the FBI and to the receiving bank through FinCEN's Financial Crimes Enforcement Network, and it is the only path that has any chance of freezing the receiving account before the money is moved again.
Then call your state attorney general's office, every state has a consumer protection line, and file a complaint with the Consumer Financial Protection Bureau at consumerfinance.gov. The CFPB's October 2025 rule on personal financial data rights means that banks are now required to respond to consumer disputes involving third party screen scraping and fake bank domains within fifteen business days, a window that did not exist before.
The new variant: alerts that arrive in your banking app
By the second half of 2026, several US banks have started pushing fraud alerts inside the app, with no text at all, and criminals have noticed. The scam now is a text that says, we have sent a fraud alert to your app, open it now, followed by a link to a clone of the bank's login page. The bank's actual app does not need a link. The bank's actual app already knows it is your phone.
How the criminals got your number in the first place
Most of the phone numbers targeted in 2026 bank impersonation waves were not stolen from the bank. They were scraped from people-search sites, harvested from old data breaches, or bought from lead brokers who package them by income, ZIP code, and length of time at the address. Removing yourself from the major people-search sites cuts the supply, but it does not cut it to zero, and it does nothing for numbers already in circulation.
The FBI's 2024 Internet Crime Report, released April 2025, found that personal data breach reports were up by more than 200 percent year on year, and the majority of those records end up in the same criminal marketplaces that sell bank text scripts. The realistic posture is to assume your number is in someone's database, treat every unsolicited bank text as guilty until proven innocent, and rely on the verification steps above rather than on secrecy of the number itself.
If the money already moved, here is the order that works
Time is the only resource that matters, and it is the one resource the scam has stolen from you. Within one hour: call the bank, ask for the fraud department, get the receiving account details. Within four hours: file the IC3 complaint with those details, and call the receiving bank to flag the receiving account. Within twenty four hours: file with the FTC, your state attorney general, and the CFPB. Within seven days: request a written fraud affidavit from your bank, and consider identity theft monitoring through the free service offered by the FTC at identitytheft.gov.
For investment losses, the recovery picture is bleaker. The Global Anti Scam Organisation, a non-profit that tracks pig butchering cases, published a figure in February 2026 estimating the average recovered percentage at roughly four percent of funds sent, with the median case under twenty thousand dollars. The best predictor of recovery is the receiving bank, not the amount sent, which is why identifying the mule's bank is more important than identifying the criminal.
What the banks themselves are doing, and where it falls short
In March 2026, the Consumer Financial Protection Bureau finalised its rule requiring banks to give consumers the option to delay certain instant payments by up to four hours, a measure pushed heavily by AARP and a coalition of state attorneys general. As of October 2026, the major US banks have implemented the delay in some form, but the default is still instant, and the opt-in is buried in the transfer flow. If you are about to send money to a person you have never met in person, the four hour delay is the most useful feature in your banking app, and almost no consumer knows it exists.
On the text side, the carriers have been slower. AT&T, Verizon, and T-Mobile all filed reports with the FCC in 2025 describing their efforts to block known bank impersonation short code spoofing, and the blocking has improved, but the criminals have moved to rich communication services, the successor to SMS, where the sender's identity is harder to verify. The result is that the legibility of the message, not the technical channel, is the only thing the average consumer can rely on, which is why this article exists.
Three habits that close most of the gap
First, save your bank's real fraud number in your phone under a name that is not Chase fraud or Bank of America fraud, because criminals spoof contact names. Call the number on the card, not the name on the screen. Second, treat every one time code as the keys to your account. No human at your bank will ever ask for it, not for verification, not for security, not for the fraud department. Read it to no one. Third, use the four hour instant payment delay for any transfer above one thousand dollars to a person you have not met in person. The four hours cost you nothing, and they will save you a year of phone calls.
If you do those three things and nothing else, the bank's 2026 fraud data, published in the FDIC's quarterly Consumer Compliance Outlook, suggests your probability of losing more than five hundred dollars to a bank impersonation scam drops into the low single digits. The remaining risk is mostly yourself on a bad day, which is why the verification steps are the part to memorise, not the scam itself.
Quick answers
- Will my bank ever text me a link to log in?
- No. Legitimate bank texts will tell you to open the app you already have, not tap a link. If a text includes a URL, treat it as hostile until proven otherwise.
- What if I already read my one time code to someone?
- Call your bank from a different phone, ask them to treat the account as compromised rather than just suspicious, and rotate every credential linked to the account including your email password.
- Can I get money back if I sent it by Zelle or wire?
- Maybe, but only if you report within two business days under the EFTA amendments effective April 2026. Call the bank immediately, get the receiving account details, and file with IC3 the same day.
- How do I report a fake bank text without clicking it?
- Forward the message to 7726, your carrier will log it. Then file a complaint at reportfraud.ftc.gov and at ic3.gov, especially if you lost money.
- Is a banking app alert safer than a text?
- Yes, but only if you open the app from your home screen. Texts telling you to open the app are themselves a known scam vector in 2026.
This is general safety information, not legal advice. Scams change. If you need an official desk: FTC ReportFraud or IC3.