How theScamWorks
Bank impersonation · How it works

The Fake Bank Fraud Alert: The Charge Was Never Real

Published 15 min read
Video: The Fake Bank Fraud Alert: The Charge Was Never Real — 14:27. Watch on YouTube.

The charge in the text does not exist. Replying is not the mistake — it confirms your number is live and sets up the call that follows. Never move money to 'protect it'. Never share a verification code. Hang up and dial the number printed on your statement.

Key facts

1,355 → 25,725
Reports to the FTC about text messages impersonating a bank, 2019 compared with 2022
U.S. FTC, Data Spotlight, 'IYKYK: The top text scams of 2022' (June 2023), note 6
up nearly twentyfold
How the FTC describes the growth of bank-impersonation texts since 2019
U.S. FTC, Data Spotlight, 'IYKYK: The top text scams of 2022' (June 2023)
$3,000
Median reported loss to the copycat bank alert in 2022, against $1,000 for scam texts as a whole
U.S. FTC, Data Spotlight, 'IYKYK: The top text scams of 2022' (June 2023)
They thought the bank was helping them get their money back
What people told the FTC they believed was happening during the call
U.S. FTC, Data Spotlight, 'IYKYK: The top text scams of 2022' (June 2023)
5% → 11%
Share of reported scam texts that came with an actual loss, 2020 compared with 2024
U.S. FTC, Data Spotlight, 'Top text scams of 2024' (14 April 2025), note 2
losses have skyrocketed even as the number of reports declined
The structural fact underneath that: what happened to losses while reports fell
U.S. FTC, Data Spotlight, 'Top text scams of 2024' (14 April 2025)
$470 million
Reported losses to scam texts of every kind in 2024
U.S. FTC, Data Spotlight, 'Top text scams of 2024' (14 April 2025)
limited only by their available funds
What the FTC says bounds the loss when a person believes they are fixing a problem
U.S. FTC, Data Spotlight, 'False alarm, real scam' (7 August 2025)
these scams still depend on a phone call
Why the call exists at all, in the FTC's own words
U.S. FTC, Data Spotlight, 'False alarm, real scam' (7 August 2025)
reports up nearly sevenfold, losses up eightfold
Reports from people aged 60+ losing $100,000 or more to these scams, 2020 compared with 2024, and the money lost in that band
U.S. FTC, Data Spotlight, 'False alarm, real scam' (7 August 2025)
You won't be protected. And you probably won't get that money back
What the FTC says about getting the money back after you move it out of your own account
U.S. FTC consumer alert, 'Got a call about fraud on your bank account? It could be a scammer' (8 July 2024)
rideshare service drivers
Who actually rang the doorbells to collect the cash, according to federal prosecutors
U.S. Attorney's Office, Southern District of California, case announcement, 26 March 2026
documents from 'my grandma' and 'my grandpa'
What prosecutors say the drivers were told they were collecting
U.S. Attorney's Office, Southern District of California, case announcement, 26 March 2026
$86,300
Taken from one person in the San Diego area, in cash, at their own front door
U.S. Attorney's Office, Southern District of California, case announcement, 26 March 2026
36 months, $251,300 restitution, $50,000 fine
The sentence entered in that case — custody, restitution and a fine that only starts after the victims are paid
U.S. District Court, S.D. Cal., No. 3:26-cr-00607, Judgment (docket entry 44, 18 June 2026)
$3.5 billion
Reported losses to imposter scams of all kinds in 2025, with the highest business-impersonation losses going to bank impersonators
U.S. FTC, press release, 15 June 2026 (2025 data)

The charge in the text does not exist. Replying is not the mistake — it confirms your number is live and sets up the call that follows. Never move money to “protect it”. Never share a verification code. Hang up and dial the number printed on your statement.

Every warning you have ever read about scam messages assumes the message wants something from you. A link to click. A password to type. A fee to pay. A form to fill in.

This one wants the opposite. It wants you to say no.

It arrives in the evening. Your bank has spotted a purchase on your card, a large one, and you are looking at it right now and you know for a fact that you did not make it. The message does not ask for your password. It does not ask for your card number. It does not send you anywhere at all. It asks you to do the smallest thing there is: reply YES or NO.

So you reply no, because of course you reply no. And for a moment you feel something almost nobody feels about their bank. You feel looked after.

Nothing has gone wrong yet. Nothing goes wrong for another ninety seconds, which is roughly when your phone rings — and you answer it, because by now you are expecting a call.

What follows is the sequence the Federal Trade Commission has written down from the reports people file, the one federal case in which a man admitted running this nationwide, and the single sentence that ends the conversation.

The case

In March 2026, in a federal courthouse in southern California, a twenty-six-year-old man from Florida pleaded guilty to bank fraud and money laundering. Not accused. Not alleged. Admitted, in a signed plea agreement, in case number 3:26-cr-00607. The details that follow come from the announcement federal prosecutors made the day he entered it.

He and the people he worked with obtained bank customer information. They called those customers and, in the prosecutors’ words, “falsely claimed to be investigating fraud at the victims’ banks”. Then they persuaded them to go to the bank, withdraw their money in cash, and hand it to a bank employee who would come to the house to collect it.

There were no bank employees.

The people who rang those doorbells were rideshare drivers. Ordinary drivers, booked for ordinary fares, sent to an address to pick something up and bring it back. And here is the detail prosecutors put in writing, which is the smallest thing in the entire case and also the thing that explains it:

[He] frequently told the drivers they were picking up documents from “my grandma” and “my grandpa.”

So the driver is not a criminal. The driver is someone doing a small favour for a stranger’s grandmother, carrying an envelope to a car, with no idea what is inside it and no reason to ask. That is worth stating plainly, because a scheme like this quietly borrows the reputation of an entire category of worker who had no part in it.

The geography is in the same announcement. On 26 October 2025 he flew from Houston to San Diego. In that one area he took thirteen thousand dollars from one person, thirty-seven thousand from another, and eighty-six thousand three hundred from a third. Days later, in Las Vegas, he paid twenty-four thousand dollars in cash for a car. In January 2026, in Portland, Oregon, another person handed over forty thousand dollars. Many of the victims, prosecutors noted, were elderly.

Bank fraud in the United States carries up to thirty years. On 18 June 2026 the judgment was entered on the docket: thirty-six months in federal custody, three years of supervised release, restitution of $251,300, and a $50,000 fine which the judgment specifies only begins once the restitution has been paid. That last clause is worth a moment — on paper, it means the people who lost the money get paid before the treasury does.

The case was worked by the FBI, by police in two cities, and by something called the San Diego Elder Justice Task Force, which exists because of who these calls are aimed at.

And the victims in that case did everything a careful person is told to do. They did not click a link. They did not type a password into anything. Nobody hacked any account. They walked into their own bank, in daylight, and asked for their own money.

How it works, step by step

Ten moves. Notice how few of them require you to be gullible, and how many of them are things you do correctly.

  1. The message asks for nothing. No link, no password field, no payment. It works because every fraud test most people know is a test for a request — you have been trained to notice what is being asked of you, and here the answer is nothing. A message that wants nothing does not trip a single alarm you own.
  2. It asks you to say no. It works because saying no does three things at once, none of which feel like anything. It tells a stranger the number is live. It tells them you are the kind of person who reads a fraud alert and acts on it. And it establishes, without you ever agreeing to anything, that a conversation is now open.
  3. It arrives as a text and not as an email. An advisory committee reporting to the Federal Communications Commission put text message open rates as high as 98% and response rates as high as 45%, against 20% and 6% for email. It works because the channel itself does most of the work: the same pitch that would rot unopened in an inbox is read within minutes on a phone.
  4. The call comes while the message is still on your screen. It works because it inverts the thing that normally protects you. A cold call from a stranger claiming to be your bank is suspicious. A call that arrives right after you told your bank about a fraudulent charge is the expected next step in a process you began.
  5. The caller already knows what you said no to. They should — they wrote it. It works because private knowledge reads as proof of identity. The one detail they can recite is the one detail they invented.
  6. The story grows within minutes. The FTC’s description is that scammers “quickly up the ante, often telling people all their money is at risk”. The card is compromised; if the card is compromised the account is exposed; if the account is exposed then everything in it is at risk tonight, while you are on the phone. It works because each step is a reasonable inference from the one before it, and the first step was handed to you as a fact.
  7. Somewhere in there, they ask for a verification code. It works because the code arrives from your bank’s real number, in your real messages, which makes reading it aloud feel like part of the security process rather than the end of it. It does not prove you are you. Handed over, it proves to a computer that they are you.
  8. They keep you on the phone. Not because they need you there — they do not. It works because, as the FTC puts it, keeping you on the phone “is also designed to keep you from talking to anyone who could help – a friend or family member in a calmer state of mind”. The call is not the channel. It is the room they lock, and the lock is politeness.
  9. They send you to your own money, not your card. It works because of an asymmetry most people never learn until afterwards: the FTC states that bank accounts have “different (and fewer) protections than credit cards”. The choice of instrument is not about access. It is about which mistakes can be reversed.
  10. Someone comes to the door. Cash withdrawn, envelope sealed, a car at the kerb. It works because by this point handing it over is not a leap of faith — it is the last step of a rescue you have been participating in for an hour.

What is absent from all ten: no forgery, no malware, no stolen password, no breached account. The only false thing in the entire sequence is the charge in the first message, and by the time anyone thinks to check it, the money is already gone.

What the agency counting these has actually published

The Federal Trade Commission has been tracking this specific message for years, and its own numbers contain a turn that most coverage misses.

On how fast it grew. In 2019 the FTC received 1,355 reports about text messages impersonating a bank. By 2022 that number was 25,725 — a rise the agency describes as “nearly twentyfold since 2019”. That year, 2022, the Commission placed the copycat bank fraud prevention alert at the top of its list of the five most reported text scams in the country. It is worth being precise about what that list is: the agency built it by hand-coding a random sample of 1,000 text fraud reports, with a margin of error of ±3.1% at 95% confidence. It is the top of the FTC’s list, not a national census.

On the money being different. The Commission put the median reported loss for that scam at $3,000, against $1,000 for scam texts as a whole. Three times the damage, from the message that asks you for nothing.

On which names get borrowed. The FTC also published which banks the messages claim to be from: Bank of America in 14% of reports, Wells Fargo 12%, Chase 12%, Citibank 9%. Those four are not accused of anything. They appear on that list because they are the names most worth stealing.

And then the turn. In 2024, Americans reported $470 million lost to scam texts of every kind — more than five times the 2020 figure. But the number of reports went down, and the fake bank alert had actually slipped to third place on the Commission’s list that year, behind fake package deliveries and fake job offers. The FTC states the pattern directly: reported losses “have skyrocketed even as the number of reports declined”. The share of these reports that came with an actual loss was 5% in 2020. By 2024 it was 11%.

The texts did not get more common. They got better. And what improved is not the message — it is what happens in the minutes after you answer.

On what the scam feels like from inside. This is the sentence that reorganises the whole thing, and it is the FTC’s, not ours:

People say they thought the bank was helping them get their money back. Instead, money was transferred out of their account.

Read carefully, that inverts everything. The person on that call is not sitting there being robbed. They are sitting there being rescued. Somebody found the fraud. Somebody is on the phone at seven in the evening helping them undo it. Every minute of the call feels like recovery — and there is no other crime happening in the background that the rescue is distracting from. The charge never existed. The account was never touched. The only thing that has gone wrong is the call that is currently fixing it.

Where the money goes

The loss in this scam has no natural ceiling, and the FTC says why in one clause. When people believe they are fixing a problem rather than sending money to a stranger, their losses are “often limited only by their available funds”.

Not limited by a card limit. Not by a daily transfer cap. By the balance.

That is the structural difference between this and almost every other consumer scam. A fake shop takes the price of the item. A delivery text takes a small redelivery fee. This one takes whatever is in the account, because the amount is set by how much needs “protecting” — and the person deciding how much that is has been on the phone with you for an hour.

The exit routes are documented too, and they are more physical than people expect. Describing this category, the FTC lists what victims are told to do with the money once they have been convinced to move it: transfer it out of the account, deposit cash into Bitcoin ATMs, and “hand off stacks of cash or gold to couriers”.

Couriers. Written by a federal agency, in a report about older adults, as a routine item on a list. The doorbell in the case above was not one man’s strange improvisation. It is a distribution method.

There is also a number that does not exist, and it is worth saying so rather than inventing it. There is no published figure for annual losses to the fake bank fraud alert specifically. The FTC publishes losses to imposter scams overall — $3.5 billion in 2025, part of about $16 billion in total reported fraud, the highest on record — and it publishes that people reported losing “nearly $1 billion to business impersonators with the highest reported losses to bank impersonators”. It does not publish the bank column on its own. Any article quoting “$X billion lost to fake bank alerts, according to the FTC” is quoting something the FTC never published.

The same caution applies to victim counts. The FTC counts reports, and research it cites finds that only about 4.8% of mass-market fraud victims report to a public agency or the BBB at all. Every number on this page is a floor.

How to spot it

Each sign, with the test that settles it.

  • The message asks you to reply YES or NO. Test: ask what the reply is for. A bank that already knows about a suspicious charge can freeze the card without your vote. The reply exists to open a channel, not to close a case.
  • A call arrives within a couple of minutes of your reply. Test: treat the speed as the warning rather than the reassurance. Real fraud departments have queues.
  • The caller ID shows your bank. Test: it is display data, not identity. Nothing you can see on an incoming call is verified by anyone.
  • The problem grows while you are on the phone. One charge becomes the card, the card becomes the account, the account becomes everything. Test: notice that each escalation arrived from the person who also proposes the remedy.
  • Anyone asks for a verification code. Test: this one needs no judgement at all. The FTC’s position is absolute — no caller from any fraud department will ever ask for it. A request for that code is a complete answer on its own.
  • You are asked to move, withdraw, wire or convert your own money. Test: no legitimate fraud process requires your money to leave your account to be protected. Your money is fine where it is.
  • You are told not to discuss it. Sometimes framed as an internal investigation, sometimes as urgency. Test: say you are going to call a relative before doing anything. Watch what that does to the conversation.
  • Someone offers to collect cash from your home. Test: there is no bank in the country that sends a person to your door for cash. This one is not a judgement call either.

What to do if it already happened

In order of urgency, because the first hours are the only ones in which some of this is reversible.

  1. Tell your bank now, and use the word fraud. The FTC’s instruction is to tell your bank or fund right away, especially if you moved money or shared a verification code. Speed is the entire variable: a wire that has not settled can sometimes be recalled, and a compromised login can be locked. What your bank cannot easily do is unwind cash you withdrew and handed over — which is precisely why that route was chosen.
  2. If a code was shared, assume the account is reachable and change what you can. Change the online banking password, and check for new payees, new devices and forwarding rules you did not set. A verification code is a key, and keys get reused.
  3. Report it at reportfraud.ftc.gov. Be clear about what this does and does not do: the FTC does not resolve individual complaints or recover money. It builds the record that federal and state enforcers use to see a pattern. The federal case described above began with reports from people who each assumed theirs was too small to matter.
  4. Report it to your local police, and get a report number. In the case above the investigation involved two city police departments alongside the FBI. If cash changed hands at your door, there is a physical crime scene, a vehicle, and a time window — that is police work, and it is evidence that decays.
  5. If the victim is an older adult, use the line built for it. The Department of Justice publicises the National Elder Fraud Hotline at 1-833-372-8311, which helps people report and connects them to services.
  6. Do not treat this as a verdict on your judgement. This scam is aimed at people who take fraud seriously, and the FTC says so in its own data — it works by using a person’s vigilance about protecting their money against them. Being persuaded by an alert you were right to act on is not carelessness.

How to not be next

Two habits, and neither costs anything.

Decide now that you will never resolve a fraud alert inside the channel that delivered it. Not by replying to the text, not by calling the number in it, and not by staying on a call that came to you. Look up the number yourself — on your statement, on the back of your card, in the app you opened on your own. This single rule defeats the entire sequence, because every version of it depends on you continuing in the channel they control.

And agree, out loud, with the people you would be called about. The reason this scheme reaches for a grandmother’s front door is that isolation is the working condition. A prior agreement that any money emergency gets one phone call to a family member before anything is moved costs nothing to make and is very hard to argue with at seven in the evening.

If you take one sentence away, take the FTC’s:

Never move or transfer your money to “protect it.” Your money is fine where it is, no matter what they say or how urgently they say it.

There is no situation in which that sentence is wrong. Not one.

And one caution against the wrong lesson, because it would be worse than the scam: none of this means you should ignore a fraud alert. Real banks do send them, and real fraud is caught that way every day. The instruction is not to distrust the alert. It is to answer it somewhere else — in the app, on the number you looked up, in a conversation you started. The alert can be right and the messenger can still be a stranger.

Watch the full documentary

The message that asks for nothing, the ninety seconds before the phone rings, and the envelope that left through the front door: watch it here.

The borrowed institutional name — an alert that arrives in the voice of an organisation you already trust — is the same engine behind the fake Microsoft security alert, though there they take the machine and here they take nothing at all. The manufactured emergency that has to be solved before you can check it runs the AI voice clone family emergency call and the virtual kidnapping call, where the proof is a photograph. And the technician who finds a problem that was never there is doing the same trick with a different uniform: the air duct cleaning scam.

Questions people ask

My bank texted me about a charge I did not make. Is it real?

It may well be — real banks do send fraud alerts, and that is exactly why the fake ones work. The problem is that the text itself cannot tell you which kind you are holding. So do not resolve it inside the text, and do not resolve it with anyone who calls you afterwards. Open your banking app on your own, or call the number printed on your statement or on the back of your card. If the charge is real, it will be there when you look. If nobody at your bank knows anything about it, you have just been handed the answer for free.

I replied YES or NO to the text. Have I been hacked?

No. Replying does not install anything, does not give anyone your password, and does not move any money. What it does is confirm that a live person reads that number and that you are the kind of person who responds to a fraud alert — and it sets you up to expect a call. The reply is not the loss. The loss happens later, on the phone, and it requires you to actively do something with your money. If you replied and then hung up on whoever called, nothing has happened to you.

Why would a scam ask me to say NO instead of clicking a link?

Because the link is the part you have been trained to distrust. A message with no link, no password field and no payment request survives every check most people know how to run — it is asking for nothing, so there is nothing to refuse. What it is actually buying is the phone call. When your phone rings ninety seconds later, you are not receiving a cold call from a stranger; you are receiving the follow-up to a conversation you already started. That expectation is the entire product.

The caller ID said it was my bank's fraud department. Doesn't that prove it?

It proves nothing at all. The name and number that appear on your screen are data attached to the call, not a verified identity, and they can be set to display almost anything. This is why every piece of official advice on this scam converges on the same instruction: end the call and dial a number you obtained yourself. The FTC’s wording is to use the number on your statement, ‘never the number the caller gave you’ — and in this case, never the number in the message either.

They asked me for a verification code. What does that code actually do?

It proves to a computer that whoever holds it is you. Handed to a caller, it proves that they are you. The FTC is unusually blunt about this one: ‘Never share a verification code. Ever,’ and it names the fraud department specifically — ‘No caller — especially someone from your bank or investment company’s fraud department — will ever ask for the verification code.’ There is no legitimate exception, no supervisor who needs it, and no verification step that requires you to read it aloud.

Will my bank refund money I transferred to a scammer?

Probably not, and this is the part most people learn too late. A refund here is not automatic and, in most cases, not owed. The FTC states that ‘bank accounts have different (and fewer) protections than credit cards’ and that ‘if you are scammed into moving your money out of your account, you won’t be protected. And you probably won’t get that money back.’ A disputed card charge can often be reversed; cash you withdrew yourself, or a transfer you authorised, generally cannot. That asymmetry is exactly why the call steers you toward your own balance rather than your card — it is not about which is easier to reach, it is about which mistakes are reversible. Tell your bank immediately anyway: speed is the one variable still under your control, and a transfer that has not settled can sometimes be recalled.

Why do they keep me talking for so long?

Not because they need you on the line to move money — they do not. The FTC explains the function directly: a call is ‘the best way to dial up the fear and the urgency so it’s harder for you to think clearly and check things out’, and ‘keeping you on the phone is also designed to keep you from talking to anyone who could help — a friend or family member in a calmer state of mind.’ The call is not the channel for the fraud. It is the room it happens in, and the door is held shut by the conversation itself.

Is this only aimed at older people?

No, but the damage is concentrated there. The FTC reports that between 2020 and 2024, reports from people aged 60 and over who lost $10,000 or more to these scams rose more than fourfold; for losses above $100,000 the number of reports rose nearly sevenfold, and the money lost in that band rose eightfold. The agency also points out the irony in its own data: these scams ‘prey on older adults’ vigilance about protecting their money’. Taking fraud seriously is what the fake fraud alert is built to exploit, which is why it is a poor idea to treat this as a story about other people being careless.