Skip to main content

Your phone buzzes. It’s your bank. There’s been suspicious activity on your account, and you need to act now. Sound familiar? Millions of Americans receive messages like this every week, and a growing number of them aren’t actually from their bank at all. They’re from fraudsters who have gotten remarkably good at mimicking the language, tone, and even the visual format of genuine financial institutions.

The text message often looks like a bank security message and tries to create a sense of urgency to encourage you to provide your personal information. Understanding how this scheme actually works, step by step, is one of the most practical things you can do right now.

The Scale of the Problem Is Staggering

The Scale of the Problem Is Staggering (Image Credits: Unsplash)
The Scale of the Problem Is Staggering (Image Credits: Unsplash)

New data from the Federal Trade Commission reveal that people reported losing a staggering $3.5 billion to imposter scams in 2025, with reported losses increasing nearly three times since 2020. That number alone should give anyone pause.

People reported losing nearly $1 billion to business impersonators, with the highest reported losses going to bank impersonators, and about $920 million to government impersonators, up from $866 million and $789 million respectively in 2024.

Americans’ savings are at risk as new, technology-driven fraud and scams are surging across the U.S., costing American households an estimated $12.5 billion in 2024, a 25 percent increase over the previous year. These are just reported losses, with actual totals likely much higher.

What the Scam Text Actually Says

What the Scam Text Actually Says (Image Credits: Unsplash)
What the Scam Text Actually Says (Image Credits: Unsplash)

Many people report receiving texts about so-called suspicious activity or a big purchase they didn’t make. These texts often look like they’re from a bank or Amazon. They might give a number to call, or they might say to reply YES or NO to verify a large transaction.

A scammer posing as your bank sends you a text message about a security issue with your account. Maybe it’s an unusual transaction, a request to update your account information, or a general fraud alert. If you don’t respond to the text immediately, it says you’ll face consequences like bank account suspension or freezing.

For example, you might receive a text message asking you to verify a large purchase you didn’t make, and, if you respond, you might get a call from someone pretending to be from the bank’s fraud department, who asks you for your personal information. It feels real because it’s designed to feel real.

How Caller ID Spoofing Makes It Worse

How Caller ID Spoofing Makes It Worse (Image Credits: Unsplash)
How Caller ID Spoofing Makes It Worse (Image Credits: Unsplash)

Fraudsters use call spoofing, a technique where they falsify the information transmitted to a caller ID display to disguise their identity. The phone number then appears to be the bank name and the phone number associated with the bank where a business maintains an account.

In January 2024, a Florida couple was targeted by a sophisticated impersonation scam that resulted in $42,000 being taken out of their bank account. Two years later, the couple was still fighting to get that money back from JPMorgan Chase, which denied their claim and closed the case.

After the initial call ended, the victims received a call from someone else claiming to be from the bank. That supposed representative was reportedly the scammer who had sent the initial text message. Investigators say the caller had “spoofed” JPMorgan Chase’s real phone number, making the call appear to be legitimate on caller ID. Even cautious people can get caught off guard.

Bank Impersonation Scams Are Surging Year Over Year

Bank Impersonation Scams Are Surging Year Over Year (Image Credits: Unsplash)
Bank Impersonation Scams Are Surging Year Over Year (Image Credits: Unsplash)

Bank impersonation scams are surging: the average number of identified scams per bank increased 150 percent from 2024 to 2025. Surveyed banks reported an average of 26,196 such scams in 2025.

Telecom networks, including texts and calls, are a primary vector for these scams, increasing 124 percent from 2024 to 2025. Bank impersonation scams originating on social media are increasing and have more than doubled year over year.

Banks and fintechs are the primary impersonation target in smishing campaigns because the financial urgency of a fraud alert or account suspension notice drives immediate action. Scammers understand human psychology, and they exploit it with precision.

The Three-Phase Scam That’s Catching Everyone Off Guard

The Three-Phase Scam That's Catching Everyone Off Guard (Image Credits: Unsplash)
The Three-Phase Scam That’s Catching Everyone Off Guard (Image Credits: Unsplash)

A particularly nasty three-phase attack known as the “Phantom Hacker” scam involves fraudsters who first pose as tech support staff, then as bank representatives, and finally as government officials. Each layer of the scam gives more credibility to the previous one, making it harder for victims to spot if they are being deceived.

Some of the costliest impersonation scams start with a fake security alert, often from a bank. People are then convinced to move money to “protect” it, with their losses often limited only by their available funds.

These scammers quickly up the ante, often telling people all their money is at risk. The scammers then pressure people into moving money out of their accounts to supposedly keep it safe, but it really goes to the scammers.

Replying – Even Just to Say “Stop” – Can Make Things Worse

Replying - Even Just to Say "Stop" - Can Make Things Worse (Image Credits: Unsplash)
Replying – Even Just to Say “Stop” – Can Make Things Worse (Image Credits: Unsplash)

If you are not completely sure of a text’s sender, do not respond, even to type “Stop” or “No.” Once you do, you’ve confirmed you are active on the device and an imposter pretending to be a bank representative will call and request more information, or the scammer will sell your active number on the Dark Web.

Engaging with these texts, whether by clicking a link or replying, confirms your number is active, opening the door for further exploitation. Many people assume replying with a simple “No” is safe. It isn’t.

The text message usually contains a link to a website that looks like your bank’s official site, but it’s actually a trap set up by the scammers. Once you enter your credentials there, the damage is often done before you realize anything went wrong.

The Biggest Banks Are Named the Most Often

The Biggest Banks Are Named the Most Often (Image Credits: Unsplash)
The Biggest Banks Are Named the Most Often (Image Credits: Unsplash)

The top companies identified in reports about bank impersonation text scams were Bank of America, Wells Fargo, Chase, and Citibank. These brands are targeted precisely because they serve tens of millions of customers, which means the odds of hitting an actual account holder in any random sending campaign are relatively high.

Scammers have been posing as TD Bank and sending text messages indicating that a major charge has been made to your account and providing a link to click to dispute the charge. If you click on the link, you will be taken to a website that appears to be a legitimate website of TD Bank, which prompts you to provide your username and password. Unfortunately, if you do so, you will be providing the scammer with full access to your bank account.

Scammers often impersonate specific bank branches or representatives, for example, in a text message faking a fraud alert. They also imitate senior executives at specific institutions, such as fake ads with images of bank executives giving investment advice, or fake email accounts being created in executives’ names.

Smishing Is Now the Dominant Form of Mobile Phishing

Smishing Is Now the Dominant Form of Mobile Phishing (Image Credits: Pexels)
Smishing Is Now the Dominant Form of Mobile Phishing (Image Credits: Pexels)

In Zimperium’s 2025 mobile telemetry, smishing represented over two-thirds of mobile phishing threats, with SMS accounting for nearly 70 percent of observed mobile phishing vectors. This is one of the clearest recent data points suggesting that, within mobile-targeted phishing, SMS remains dominant.

Verizon’s 2026 Data Breach Investigations Report found that, in phishing simulations, mobile-centric vectors such as voice and text messaging produced median successful click rates 40 percent higher than email. That gap explains why scammers have shifted so heavily toward SMS.

Phishing-as-a-service platforms are now empowering even tech novices to generate revenue from such scams. They do all the heavy lifting, working across SMS, iMessage, and RCS, and offer multiple social engineering lures. The barrier to running a smishing campaign has never been lower.

One-Time Passcodes Are a New Weak Point

One-Time Passcodes Are a New Weak Point (Image Credits: Pixabay)
One-Time Passcodes Are a New Weak Point (Image Credits: Pixabay)

If you’ve initiated a legitimate action, like a password reset, scammers might text you pretending to be the bank and ask for the one-time passcode you just received. They will then use this code to access your account.

You may receive legitimate bank verification codes by text that you use to access your accounts, which is called multi-factor authentication. By requiring multiple forms of verification beyond just a password, MFA enhances your security. However, a bank will never call you and ask for those codes. If you get such a call, it’s a scammer attempting to gain access to your account.

Smishing attacks can also steal user information using fake two-factor authentication messages, which means even security features designed to protect you can be weaponized against you when scammers get creative enough.

Older Adults Are Especially Targeted

Older Adults Are Especially Targeted (Image Credits: Pexels)
Older Adults Are Especially Targeted (Image Credits: Pexels)

Since the Hills are in their 70s and live on a fixed income, their story serves as a cautionary tale for older Americans who are often targeted by these elaborate schemes. Scammers frequently identify and prioritize older targets because they may be less familiar with the evolving tactics being used.

According to a recent Aspen Institute report, 68 percent of Americans reported receiving scam calls at least weekly, 61 percent of Americans reported receiving scam text messages at least weekly, and about one in three Americans say they get scam phone calls at least daily.

In a bank impersonation scam, scammers pretend to be from a bank and request your personal information, like Social Security numbers, credit card or debit card numbers, or your bank account passwords. Once that information is in the wrong hands, recovering from the fallout can take months or years.

What You Should Actually Do When You Get One

What You Should Actually Do When You Get One (Image Credits: Pexels)
What You Should Actually Do When You Get One (Image Credits: Pexels)

Do not respond and never tap any links in a suspicious message. Verify the sender by contacting your bank using a known phone number or official website to confirm the message’s authenticity. Report the scam to your bank. If you believe your personal information may have been compromised, change your passwords for your bank account and other online services.

The FTC advises forwarding suspicious messages to 7726 (which spells SPAM). This helps your wireless provider spot and block similar messages in the future.

If something feels suspicious, hang up and contact your bank using the number on the back of your card or the official website or mobile app. No genuine fraud alert from your bank will ever punish you for taking a few extra minutes to verify.

The Bottom Line: Urgency Is the Weapon

The Bottom Line: Urgency Is the Weapon (Image Credits: Pixabay)
The Bottom Line: Urgency Is the Weapon (Image Credits: Pixabay)
The entire structure of these scams rests on one thing: making you act before you think. Social engineering tactics create a sense of false urgency and prevent consumers from taking time to second-guess the scam. Legitimate companies, including major banks, will never text you asking for account details. That single fact is probably the most useful filter you have. If a message is pushing you to move fast, confirm credentials, or transfer funds to stay safe, stop. The real threat isn’t the transaction on your screen. It’s the pressure you’re feeling to respond to it.

AI Disclaimer: This article was created with the assistance of AI tools and reviewed by a human editor.