Your phone rings and the screen shows your bank’s name. A calm voice tells you there’s a problem with your account, and they just need you to confirm the six-digit code that was texted to you a second ago. Read it back, they say, and everything will be fixed. Stop right there. That code is the single thing your bank will never, ever ask you to say out loud. Not on the phone, not in a text, not in an email. The moment someone asks for it, you are not talking to your bank. You are talking to a thief.
I used to think I was too smart to fall for this stuff. Then I learned how good the scripts have gotten, and how many normal, careful people get caught every year. So let me share the things that surprised me most, because a few of them go against everything your gut tells you.
The one-time code is the whole ballgame
Here is what most people get wrong. They assume the danger is handing over a password. Sure, that’s bad. But the real prize for a criminal is the one-time passcode, that little number your bank sends to your phone when you log in. Your bank already generates that code. They know it. They do not need you to repeat it. The whole point of the code is that only you type it into the app or website. The American Bankers Association is blunt about this in their consumer campaign: a bank will rarely ask for your PIN or password on a call, and will absolutely never ask for a one-time login code. A scammer asks because they are standing at the login screen too, waiting for you to read them the key that opens your account.
No real bank tells you to move money to a “safe account”
This one gets people because it sounds so responsible. The caller says your account is under attack, and to protect your savings you need to transfer everything to a new “safe account” they set up for you. It feels like they’re on your side. They are not. Moving that money sends it straight into the criminal’s pocket, and once it’s gone it is brutally hard to get back. Security experts at the risk firm K2 Integrity put it plainly: a legitimate bank will never call you and tell you to transfer your own money somewhere else. If your account really were compromised, the bank freezes it or reissues your card. They don’t ask you to play banker for them.
There’s a nastier version of this too. The caller says you must “send money to yourself.” That phrase makes no sense when you think about it for two seconds, but under pressure people do it. If anyone claiming to be your bank tells you to send money to yourself, you can be a hundred percent sure it’s a con.
Three seconds of your voice is enough to fake you
This is the part that genuinely rattled me. Scammers now use artificial intelligence to clone a voice, and they need shockingly little to do it. In McAfee’s 2023 study of AI voice scams, its researchers cloned a voice from three seconds of audio and got an 85 percent match to the original. Three seconds. That’s a snippet of a birthday video, a TikTok, a voicemail greeting.
They use it two ways. Sometimes they clone a real bank employee’s voice to sound official, complete with fake call-center noise in the background. Other times they clone a family member, so you get a panicked call that sounds exactly like your grandkid or your kid begging for money. The technology is cheap and the results are convincing. If a call feels emotionally urgent and asks for money or account details, hang up and call the person back on a number you already have saved.
That number on your screen means nothing
People trust caller ID way more than they should. I did. But faking the number that shows up on your phone is easy, and criminals do it constantly. It’s called spoofing, and it can make a call appear to come from your bank’s real customer service line or even your local branch. There’s a version called “neighbor spoofing” where the call looks like a local number so you’re more likely to pick up.
How common is this? The FDIC’s inspector general says a single bank it supervises logged $5 million in spoofing attempts against its business customers. And the scammers often know a little about you already, like the last few digits of your account or your name, which they toss out to sound legit. Partial info is not proof. Real thieves buy that stuff on data breaches all day long.
Don’t even say the word “yes”
This tip sounds paranoid until you understand why. The FCC warns that scammers want you on tape saying “yes,” and that a throwaway question like “Is this the homeowner?” is simply how they get it. That clip can then be played back as your approval for a charge. The Better Business Bureau, which tracks these calls, says nobody has actually reported losing money this way. The calls are real either way, so don’t answer yes-or-no questions from a number you weren’t expecting.
Same goes for those automated messages that say “press 2 to be removed from our list.” Don’t press anything. Pressing a button just tells the scammer your number is real and active, which means they sell it to other scammers and the calls get worse. The best move with a robocall is silence, then a block.
Gift cards, Zelle refunds, and other giveaways
If a “bank” ever asks you to go buy gift cards and read the numbers off the back as a form of payment, that is a scam a hundred percent of the time. No exceptions. A bank explainer spells it out: banks never request gift cards, period. Target and Walgreens gift cards are not how financial institutions handle anything.
Watch out for the Zelle overpayment trick too. Someone claims they accidentally sent you too much money and politely asks you to refund the extra. It’s a well-worn script. There was never any real payment coming in, and the “refund” you send is just your own cash walking out the door. And if anyone tells you to keep the call secret from your family, your branch, or the police, hang up instantly. A real bank never asks you to keep secrets.
The numbers are worse than you think
Here’s the scale of it. Americans reported losing about $16 billion to fraud in 2025, the highest total ever recorded and roughly 25 percent more than the year before. That’s from the Federal Trade Commission. Imposter scams were the most reported fraud again in 2025, making up nearly one in three fraud reports. And of all the businesses criminals pretended to be, banks drew the biggest losses.
The FBI zeroed in on the phone version of this too. Between January and November 2025, its complaint center logged more than 5,100 reports of account takeover fraud with losses over $262 million. A lot of these follow a two-step trick. It starts as a fake bank alert saying your account is compromised, then the “agent” says they’re handing you to law enforcement for an investigation. Both people are the same crook, and the goal is to keep you scared and talking.
What actually protects you
The single strongest habit is almost embarrassingly simple: hang up and call back. Not the number the caller gives you. Not the number in your recent calls list, which could be spoofed. Use the number printed on the back of your debit card or type your bank’s website into your browser yourself. One bank’s advice is to verify independently every single time, because a real rep wants you to check. A scammer wants to keep you on the line.
A few other things worth remembering. Banks usually only call after you reach out first, so treat surprise calls with suspicion. They won’t send email attachments you didn’t ask for, and they won’t email you a login link. If you already gave something up, log into your account from a different device, change your password, and call the number on your card to report it. You can also file a report at reportfraud.ftc.gov, which is the same spot other bank experts point people to.
The oldest, best defense hasn’t changed. Fear and urgency are the tools these people rely on, because a rushed brain skips the obvious question. So slow down. Nobody legitimate loses anything if you hang up and call them back in five minutes. Your elderly parents and your teenagers are the top targets, so tell them tonight. One awkward conversation now beats a drained account later.
