Recognizing Fraud - When the Call Comes From "Your Bank"

How account takeover fraud actually works, and the handful of habits that stop it.

I’ve had calls from two separate clients in the past year - both victims of fraud.

A message arrives — a text about a suspicious charge, an email from what looks like the bank, a call from a number that shows up as the fraud department. Something feels slightly off, but not off enough to hang up. By the time the pieces fit together, there are charges on a card no one authorized, and the deeply unsettling sense that a stranger has been walking around inside their financial life.

The instinct afterward is usually self-blame: How did I fall for that? But these schemes are built by people who do this for a living, and the tactics have come a long way from the clumsy scam emails of twenty years ago. Understanding how they actually work is the first real line of defense — so let me walk through the mechanics, and then the small set of habits that matter most.

How the schemes work

Most account-takeover fraud follows a recognizable arc, even as the surface details shift.

It usually starts with information that's already out there. Large data breaches have exposed the personal details of hundreds of millions of Americans — names, Social Security numbers, addresses, account numbers. A criminal rarely has to "hack" anyone in the cinematic sense. They begin with data that leaked years ago and now circulates in bulk.

The contact is engineered to feel legitimate. Fraudsters spoof caller ID so the call appears to come from your bank's real number. They copy logos, formatting, and tone into texts and emails — the technique known as phishing. And the message almost always manufactures urgency: a charge you must confirm, an account about to be locked, a delivery that can't go through. The urgency is the whole point. It short-circuits the pause where you would otherwise stop and think.

The goal is to get the one piece they don't have. The criminal often already holds most of your information. What they need from you is the final key: a one-time passcode, an online banking password, or your confirmation to "verify" your identity. A common and effective version runs like this — they claim to be fraud investigators, tell you your account is under attack, and ask you to read back the security code the bank just texted you. That code is the very thing that lets them log in or approve a transfer.

Then they move quickly. Once inside, they change the contact information on the account so alerts stop reaching you, add themselves as an authorized user, make charges, or open entirely new accounts in your name using the personal data they already had.

A few variations are worth naming, because people encounter all of them: the fake fraud-alert text, the "tech support" pop-up warning that your computer is infected, the impersonation of a government agency such as the IRS or Social Security, and the increasingly convincing AI-generated voice call that may even imitate a familiar voice.

How to protect yourself

None of these defenses require technical expertise. The habits matter more than the tools.

Never share a one-time passcode or password with anyone who contacts you. A legitimate bank will never call, text, or email to ask for it. This single rule stops the large majority of account takeovers.

Don't act on the incoming message — initiate the contact yourself. If you get a call or text about your account, set it aside and call the number printed on the back of your card or on your statement. You lose nothing by verifying through a channel you chose rather than one that was handed to you.

Slow down when the urgency spikes. The pressure to act right now is itself the warning sign. A real institution can wait ten minutes for you to call it back.

Turn on transaction alerts for your cards and accounts, so you see activity as it happens instead of at the end of the month.

Use strong, unique passwords and two-factor authentication — ideally through an authenticator app rather than text messages, which can themselves be intercepted. A password manager makes this genuinely painless.

Review your credit reports for accounts you don't recognize. All three bureaus now provide free reports every week through AnnualCreditReport.com — the only federally authorized source.

The strongest proactive step: freeze your credit

A credit freeze — legally, a "security freeze" — blocks new creditors from pulling your credit file. When your credit is frozen, a creditor who tries to open a new account gets a block signal and cannot proceed, which makes it very difficult for an identity thief to open credit cards or loans in your name.

A few things worth knowing: the freeze is free by federal law, it does not affect your credit score, and it does not expire until you lift it. A freeze placed online or by phone generally takes effect within one business day. When you need to apply for credit yourself, you lift the freeze temporarily and then restore it.

The one catch is that you have to freeze at each bureau separately — a freeze at one does not carry over to the others. And a word of caution while you're on their sites: decline the paid "premium" or "credit lock" products the bureaus may promote during the process. The freeze itself is free, and it carries stronger legal protection than the lock products do.

Where to freeze

The three main bureaus:

  • Equifax — equifax.com/personal/credit-report-services/credit-freeze — 888-298-0045

  • Experian — experian.com/freeze — 888-397-3742

  • TransUnion — transunion.com/credit-freeze — 800-916-8800

For a more thorough lockdown — worth doing if you've already been targeted:

  • Innovis (a smaller "fourth bureau") — innovis.com/personalFreeze/freeze — 866-712-4546

  • NCTUE (checked when opening telecom and utility accounts) — nctue.com — 866-349-5355

  • ChexSystems (checked when opening new bank accounts) — chexsystems.com — 800-887-7652

If you think you've already been a victim

Move in roughly this order:

  1. Call your card issuer, dispute the charges, and request a new card number. Federal law caps your liability for fraudulent credit card charges at $50, and most issuers waive it entirely.

  2. Change your passwords on affected accounts and turn on two-factor authentication.

  3. Report it at IdentityTheft.gov. The FTC's site generates a recovery plan and an official identity theft report, which you'll want if you later dispute new accounts or place an extended fraud alert.

  4. Freeze your credit using the list above.

  5. Monitor your reports at AnnualCreditReport.com for anything unfamiliar.

This article is educational and general in nature and is not individualized advice. If you believe you've been the target of fraud, the steps above are the right place to start — and if you're a client, please don't hesitate to call us before you act. We would always rather field a false alarm than help clean up after the real thing.

Next
Next

Focus On The Long Run