What bank scammers actually do

Bank account scams work by tricking you into giving away access to your account, or by impersonating you to someone who controls your money. The scammer does not need to break into a bank's computer system. They need to convince you, or someone who trusts you, to move money or reveal credentials. Most successful scams exploit a moment when you are rushed, confused, or afraid.

The mechanics vary. Some scams use fake login pages that look identical to your real bank's site. Others use phone calls where someone claims to be your bank's fraud department and asks you to "verify" your password. Still others target business owners by impersonating a vendor or the owner's own accountant. What they all share is a social engineering element—they work because they feel urgent and legitimate in the moment.

Understanding how these scams operate is the first step toward protecting yourself. The rest of this guide walks through the most common methods, what happens after you lose access, and what your bank and law enforcement can actually do to recover money.

Key Takeaways

  • Scammers rarely hack banks directly; they trick you into revealing passwords, clicking malicious links, or authorizing transfers yourself.
  • The most common scams impersonate your bank, a trusted vendor, or someone in your family, and they create artificial urgency to bypass your skepticism.
  • Once a scammer has access to your account, they can drain it in minutes, and recovery depends on how quickly you report it and what type of transfer they used.
  • Your bank is liable for some unauthorized transfers but not all—the rules differ for wire transfers, ACH payments, and debit card fraud.
  • If you suspect you have been scammed, contact your bank when ready, file a report with the Federal Trade Commission, and document everything in writing.

Phishing and fake login pages

Phishing is the most common entry point. A scammer sends you an email or text that looks like it came from your bank, PayPal, or another financial service. The message usually says something urgent: "Unusual activity detected," "Confirm your identity," or "Your account will be closed." It includes a link that takes you to a fake website that mirrors the real one.

When you enter your username and password on that fake page, the scammer captures it. They now have what they need to log in as you. From there, they can change your recovery email, add themselves as an authorized user, or when ready transfer money out. By the time you realize something is wrong, the account may be empty.

The fake pages are often nearly perfect. They use the real bank's logo, colors, and layout. The URL might be slightly off—for example, "bankofamerica-find.com" instead of "bankofamerica.com"—but many people do not notice. The scammer counts on you being in a hurry or on mobile, where you cannot see the full URL clearly.

Phone and text impersonation

A scammer calls you claiming to be your bank's fraud department. They say they noticed suspicious charges and need to verify your information. They ask for your PIN, password, or card number "to confirm it is really you." This is a social engineering attack, and it works because the caller sounds professional and the premise feels legitimate.

Real banks never ask for your password or PIN over the phone. If you receive such a call, hang up and call your bank's official number from the back of your card or their website. Do not use a number the caller provides. Many scammers spoof caller ID so it appears to come from your bank's real number.

Text message scams follow the same pattern. You receive an SMS saying your card has been locked, your account needs verification, or a package failed to deliver. The message includes a link. Clicking it takes you to a fake login page or downloads malware onto your phone. From there, the scammer can intercept two-factor authentication codes or access your banking app directly.

Business account and vendor impersonation

Small business owners are frequent targets because they manage larger sums and often work with multiple vendors. A scammer sends an email that appears to come from a regular supplier, a contractor, or even the owner's own accountant. The email requests a wire transfer or ACH payment for an invoice, often with language suggesting urgency: "Please process this today," or "This is time-sensitive."

The scammer has usually researched the business beforehand. They know the names of real vendors, the owner's email style, and recent projects. The fake email is often sent from an address that is one letter off from the real one, or from a lookalike domain. By the time the business owner realizes the invoice was fraudulent, the money has been wired to an account the scammer controls.

Wire transfers and ACH payments are particularly dangerous because they are difficult to reverse. Unlike a credit card charge, which you can dispute, a wire transfer is generally treated as final once it leaves your bank. Some banks can recall wires if they act within hours, but success is not may provide.

What happens after your account is compromised

Once a scammer has access to your account, the timeline is fast. They may change your password when ready so you cannot log back in. They add a recovery email or phone number they control. They disable notifications or change your contact information so you do not see alerts. Then they transfer money out—either to another account they own, to a money mule's account (someone who has agreed to move stolen funds), or directly to a cryptocurrency exchange.

The speed matters because your bank's fraud detection systems may flag large or unusual transfers. If the scammer moves money slowly or in amounts that match your normal spending, the transfer may clear before anyone notices. If they move it all at once, your bank might block it—but only if their systems catch it in time.

Once money leaves your account via wire transfer, it is extremely difficult to recover. If it was sent to a domestic bank account, your bank can attempt a recall, but the receiving bank is not required to freeze the account or return the funds. If it was sent to a cryptocurrency exchange or an international account, recovery is nearly impossible without law enforcement involvement, and even then success is rare.

Your bank's liability and what you can recover

Your liability depends on the type of fraud and how quickly you report it. Under federal law, if someone uses your debit card without permission, you are liable for up to $50 if you report it within two business days. If you wait longer, your liability can rise to $500. If you wait more than 60 days, you may not be covered at all.

For credit card fraud, your liability is capped at $50 by federal law, and many card issuers waive even that. For unauthorized ACH transfers or wire transfers, the rules are less clear. Your bank may treat them as authorized payments you made yourself, especially if the scammer had your password. Some banks cover these losses under their fraud policies, but others do not.

The key is reporting quickly. Call your bank as soon as you realize something is wrong. Do not wait for a statement to arrive. Ask them to freeze your account, cancel your cards, and begin an investigation. Follow up in writing within 10 days. Keep copies of everything: your written report, the bank's response, and any evidence of the fraud (emails, screenshots, transaction records).

Steps to take if you have been scammed

First, contact your bank when ready by phone using the number on your card or statement. Tell them your account has been compromised and ask them to freeze it. Request that they cancel your debit and credit cards and issue new ones. Ask them to review recent transactions and dispute any you did not make.

Second, change your password on any other accounts that use the same password or email address. If the scammer has your email, they may try to reset passwords on other financial accounts, email, or social media. Enable two-factor authentication on all important accounts if you have not already.

Third, file a report with the Federal Trade Commission at reportfraud.ftc.gov. This creates an official record and helps law enforcement track patterns. The FTC does not investigate individual cases, but the data helps them identify larger fraud rings.

Fourth, consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, TransUnion). A fraud alert tells creditors to verify your identity before opening new accounts in your name. A credit freeze prevents anyone from opening accounts without your explicit permission. Both are free.

Fifth, monitor your credit report for the next year. You can check it free once per year at annualcreditreport.com. Look for accounts you did not open or inquiries from creditors you did not contact. If you see fraudulent accounts, dispute them with the credit bureau and the creditor.

How to reduce your risk

Never click links in unsolicited emails or texts, even if they look legitimate. Instead, go directly to the website by typing the address into your browser or calling the organization's official number. Your bank will never ask for your password, PIN, or full card number via email or phone.

Use a unique, strong password for each financial account. A password manager like Bitwarden or 1Password can generate and store these for you. If a scammer compromises one account, they cannot use the same password to access others.

Enable two-factor authentication on your bank account and email. This means that even if someone has your password, they cannot log in without a code sent to your phone or generated by an authenticator app. Text-based codes are better than nothing, but authenticator apps are more find because scammers cannot intercept them.

Be skeptical of urgency. Real banks do not pressure you to act when ready. If someone is pushing you to transfer money, verify their identity independently before proceeding. Hang up and call the organization back using a number you know is real.

For business accounts, implement approval workflows. Require two people to sign off on wire transfers above a certain amount. Verify vendor payment information by calling the vendor directly using a phone number from a previous invoice, not from the current email. Train employees to spot phishing emails.

Frequently Asked Questions

Can a scammer drain my account if they only have my account number?

An account number alone is not enough to transfer money out. They would also need your routing number, which is public, but more importantly they would need authorization—either your password, your debit card, or a signed check. However, they can use your account number to set up unauthorized ACH transfers if they also have other identifying information. Contact your bank when ready if you think your account number has been compromised.

What if the scammer already transferred the money to another bank?

Your bank can attempt to recall the transfer, but the receiving bank is not required to freeze the account or return the funds. If the money was sent via wire transfer, recovery is unlikely. If it was sent via ACH, your bank has a better chance of reversing it within one to two business days. Report it to your bank when ready—every hour matters.

Will my bank refund me if I was scammed?

It depends on the type of fraud and how quickly you reported it. Debit card fraud is usually covered if you report it within 60 days. Unauthorized ACH or wire transfers may or may not be covered depending on your bank's policy and whether the scammer had your password. Credit card fraud is almost always covered. Ask your bank about their specific fraud policy.

Can I be prosecuted if I unknowingly received stolen money?

Receiving stolen money is not a crime if you did not know it was stolen. However, if you spend it or try to move it after learning it was stolen, you could face charges. If someone sends you money and later claims it was fraudulent, do not spend it. Contact your bank and law enforcement when ready.

How do I know if an email really came from my bank?

Check the sender's email address carefully. Your bank's emails come from an official domain (for example, @bankofamerica.com), not from a Gmail or Yahoo address. Hover over links without clicking to see where they actually go. Call your bank directly using the number on your card to verify whether they sent the email. Real banks never ask for passwords or PINs via email.