SardineCon SF/2026

Learn More
Scams & social engineering4 分で読めます

Bank impersonation scamとは?

SUBSCRIBE

A bank impersonation scam is a fraudster pretending to be the victim's own bank, often spoofing the real phone number or texting from a lookalike sender, to pressure them into moving money or handing over credentials and codes. Posing as your bank borrows instant trust, which is exactly what the scam exploits.

What is a bank impersonation scam, in plain English?

A bank impersonation scam is a fraudster wearing the bank's face. They call, text, or email claiming to be from the fraud department, security team, or a branch, and warn the customer about a problem: a suspicious charge, a compromised account, or a payment that needs stopping. The whole pitch relies on the victim believing they are talking to their real bank.

To sell it, the scammer often spoofs the bank's genuine phone number so it matches the one printed on the card, or texts from a sender ID that slots into the bank's real message thread. Because the contact looks authentic, the victim drops their guard and follows instructions they would never take from a stranger.

The most damaging version turns into a safe-account scam: the customer is told their money is at risk and must be moved to a new secure or safe account to protect it. That account belongs to the fraudster. The single most important fact for any customer to hold onto is that a real bank never asks you to move money to a safe account.

How the call unfolds

The script is remarkably consistent:

  1. Contact — Reach out looking legitimate. A call or text arrives, often spoofing the bank's real number or sitting in its genuine message thread.
  2. Alarm — Manufacture a threat. The caller warns of fraud on the account, creating fear and urgency so the victim stops thinking clearly.
  3. Extract — Ask for codes or a transfer. They request one-time passcodes, login details, or push the victim to move funds to a safe account.
  4. Drain — Take the money. With the codes or the transfer done, the fraudster empties the account before the customer realizes.

Who is involved?

Who

Their role

The fraudster

Poses as the bank, spoofs its number, and guides the victim through handing over access or moving money.

The victim

The customer who believes they are protecting their account by following the caller's instructions.

The impersonated bank

Its brand and number are hijacked; often blamed by the customer even though its systems were not breached.

The receiving mule account

The safe account the funds are moved to, controlled by the fraudster and drained quickly.

What it looks like in practice

In practice

A customer gets a text that lands inside the same thread as their bank's real alerts, warning of a suspicious login. Minutes later a call comes from what shows as the bank's published number. The caller, calm and professional, says fraudsters are draining accounts and the only safe move is to transfer the balance to a new protected account they will set up.

Panicked, the customer authorizes the transfer themselves and reads out a one-time code to confirm it. The money is gone within the hour. Because the customer approved it under deception, the bank investigates it as an authorized push payment scam, not a system breach.

Why it matters to operators

Bank impersonation is one of the highest-conversion scams because it weaponizes the victim's own trust in you. The customer is trying to do the right thing, protect their account, which is why warnings feel unconvincing in the moment and why these scams so often end in an authorized transfer the customer made themselves.

For operators that creates a hard detection and liability problem. The payment carries the customer's genuine authentication, so it looks legitimate on the surface. Catching it means reading behavioral and contextual signals, a first-time payee, a full-balance transfer, hesitation, or a live phone call during the session, rather than trusting that a properly authenticated payment is a safe one.

What to watch for

  • Out-of-the-blue contact. The bank calling or texting unprompted and immediately demanding urgent action is a classic red flag.
  • Requests for codes. Any ask for a one-time passcode, PIN, or full password; a real bank never needs the customer to read these out.
  • Safe-account language. Instructions to move money to a new safe, secure, or holding account to protect it.
  • New payee, full balance. A transfer to a first-time payee, often for the entire balance, made under time pressure.
  • On the phone while paying. Signs the customer is being coached in real time during the transaction, such as long pauses or reading numbers aloud.

Quick questions

How can the call show the bank's real number?

Through caller ID spoofing, which fakes the number displayed on the victim's screen. The displayed number is easy to forge, so matching the one on the card proves nothing. The safe move is always to hang up and call the bank back on a number you look up yourself.

What is a safe-account scam?

It is the most common outcome of bank impersonation. The fraudster convinces the victim their money is under attack and must be moved to a safe account for protection, but that account belongs to the scammer. No legitimate bank ever asks a customer to do this.

Is this authorized or unauthorized fraud?

Usually authorized, because the customer is tricked into making the transfer themselves. That distinction affects liability and reimbursement, and is why these scams are harder to reverse than a straight account takeover.

Why do victims fall for it despite warnings?

Fear and authority. Being told your account is under attack triggers panic, and the caller appears to be the trusted institution telling you how to stay safe. Under that pressure, people follow instructions they would normally question.

What should a customer do if unsure?

End the contact and call the bank directly using the number on the back of the card or the official website, from a different line if possible. A genuine bank will have no problem with the customer calling back to verify.

How do banks defend against it?

A mix of behavioral monitoring for scam-pattern payments, warnings and friction at the point of transfer, confirmation-of-payee checks, and customer education. The goal is to slow the victim down long enough to break the spell.

Go deeper

  • FTC Consumer Advice: Scams ↗ — US consumer guidance on current scams and fraud, and how to report them.
  • FBI IC3 ↗ — The FBI Internet Crime Complaint Center. Fraud reporting and annual trend reports.

Bank impersonation scamと併せて知っておきたい用語