How to spot a fake bank text, email or phishing message
Modern phishing messages can copy a bank’s branding, transaction details and tone. The safest test is not whether the message looks professional, but whether you verify it through a channel you opened yourself.
Do not use the link or phone number in an unexpected banking message. Open the bank’s app independently or type the official website yourself. Never disclose your full PIN, password or one-time authentication code to a caller. If you already entered details, contact the bank immediately and secure the affected accounts and email.
A convincing message can still be fake
Spelling mistakes are no longer a reliable scam detector. Criminals can copy logos, sender names and even genuine wording. They may know your name, bank or recent purchase from data breaches or earlier fraud. A message that says “£842 payment blocked — confirm now” is designed to create urgency so that you follow the supplied link before thinking about the communication channel.
Treat the message as an alert, not as an instruction. If it might be genuine, open the banking app from your phone’s home screen or use the website address you already know. If the same security issue exists, you can deal with it there without trusting the message itself.
Know what information a bank should not need from you
A genuine bank may ask identity questions, but it should not need you to reveal a full PIN or give a one-time code to an unsolicited caller so that the caller can “cancel fraud”. One-time codes authorise actions. If someone pressures you to read one aloud, stop. The same applies to requests to install remote-access software or move money to a “safe account”. Those are classic escalation tactics.
Be particularly cautious when a caller tells you not to hang up because doing so will “break the security process”. End the call and reconnect using an independently verified number. If you are worried that a landline call has not disconnected, use another device or wait before calling back.
Protect the email account behind your banking
Bank security does not live only inside the banking app. Your email can be used for password resets, statements and identity recovery, so compromise there can undermine several financial accounts at once. The National Cyber Security Centre recommends strong unique passwords for important accounts and two-step verification. Turn on 2SV for email and other key services where available and keep devices and apps updated.
Do not reuse the banking password anywhere else. A criminal who obtains a reused password from an unrelated website can try it against email and financial services. A password manager can make unique passwords practical without requiring you to memorise dozens of them.
If you clicked the link or entered details
Disconnect from the scam conversation and contact the bank through an official route. Tell it exactly what was entered: card number, online-banking credentials, one-time code or identity information. Check for new payees, device registrations and transactions. Change compromised passwords from a trusted device and secure the associated email account as well.
If you installed an app at the scammer’s request, especially remote-access software, tell the bank that explicitly. Merely changing one password may not be enough while the device remains compromised. Follow trusted device-security guidance and consider professional help if you are unsure whether malicious software remains installed.
Check the request, not just the logo, spelling or sender name
Modern phishing can look polished. Criminals can copy a bank’s branding, use convincing grammar and manipulate the displayed sender name so a message appears in an existing thread. That is why visual quality is a poor test. Concentrate on what the message asks you to do: follow an unexpected link, call a supplied number, move money to a “safe account”, disclose a one-time code, approve a login or install remote-access software. Those requests create the danger.
If a message refers to a transaction you recognise as suspicious, close it and open the bank’s app independently. Use the app’s secure messaging or the number on the back of your card or official website. Do not search for a telephone number from a sponsored result while under pressure, because fraudulent adverts and cloned sites can also appear convincing. A genuine fraud check can wait long enough for you to establish a trusted contact route.
Report suspicious messages using the mechanisms your bank and UK authorities provide, then delete them after preserving anything you may need as evidence. If you clicked a link but did not enter data, change course immediately rather than assuming damage is inevitable. If you disclosed credentials, approved a payment or installed software, tell the bank exactly what happened so it can protect the account appropriately.
Sources and verification
Victoria Hughes — Consumer Rights Specialist
I no longer tell people to “look for bad spelling” as the main phishing test. Good scams can be beautifully written. The stronger habit is channel separation: an unexpected message can tell you that something may need attention, but it should not dictate how you access the bank. Close the message and open the official app yourself. That single habit neutralises many fake links and phone numbers. I also treat one-time codes as the digital equivalent of a signature. If a caller asks you to read a code aloud, the safest assumption is that they are trying to authorise something. Email security matters just as much as the bank login because email often sits behind password recovery. Use a unique password and 2SV there first. If you have already clicked or entered information, do not waste time trying to decide whether the website was definitely fake. Contact the bank, explain exactly what you disclosed and secure the related accounts. The quality of the response depends on the quality of the facts you give them. I no longer use spelling mistakes as my main phishing test. The decisive question is whether the sender is trying to control your next action. A bank alert may be genuine, but you should still reach the bank independently. That single habit breaks many scams because it removes the criminal’s link, phone number and sense of urgency from the conversation.
MyBankAnswers uses official provider and UK regulatory sources wherever practical. Information is general and does not constitute financial advice.