An email with the right logo and the right colours. Then a text message that appears in the same conversation as the genuine texts from your bank. Sometimes, last of all, a phone call from a number your phone displays as your bank’s customer service line.
This is bank phishing: an attempt to get you to hand over your sign-in details, card details or confirmation codes by pretending to be your bank. The word phishing is a play on fishing: bait is cast out to a great many people, and someone eventually bites. The techniques change over time, but they have more in common than it might seem.
This post describes the most common techniques, one by one. It is the threat-side companion to the recommendation on emails pretending to be your bank: never use a message as your way into your account, and only reach your bank through channels you have chosen yourself.
One useful clarification: this post describes how these attacks work from the point of view of the person on the receiving end, so that you can recognise them and defend against them. It contains no operational instructions.
The starting point
It is Tuesday evening. An email arrives: “We have detected unusual activity: some features of your account have been restricted. Please verify your details within 24 hours.” There is the logo, a “Verify now” button, even the small print at the bottom.
You do not click, but the thought stays with you. Twenty minutes later a text message arrives, in the same thread where your bank’s texts usually appear: “Unusual sign-in to your account. If this wasn’t you, please wait for a call from one of our advisers.”
The phone rings, and the screen shows a number that looks like your bank’s. The voice is polite, knows your name and offers to help you “secure your account” together.
None of the three messages comes from the bank. They are three different techniques, used one after another.
Why scams in your bank’s name work
All the techniques that follow share one thing: they do not need to break into the bank’s systems, they only need to persuade you to take one step: click, type a password, read out a code. To get there, they rely on three levers:
- trust: the bank is one of the few organisations we genuinely expect important messages from;
- fear: a blocked account or an unusual sign-in touches something we care about;
- haste: a tight deadline leaves little room to stop and check.
None of these levers requires extraordinary skills. The message goes out to a very large number of people, and it only takes a few to reply at the wrong moment.
1. The cloned email with a fake page
In plain terms. An email copied from a real message from your bank, in which the only thing that has changed is the link: it leads to a page imitating your online banking sign-in.
How it works. The design, wording and signatures are taken from genuine messages. The button leads to a site whose address resembles the official one, perhaps with an extra letter. The page asks for your customer number and password, and often for the confirmation code sent to your phone as well.
Why it works. Because we expect an email from the bank to look exactly like that. A logo is easy to copy, and the padlock in the address bar only tells you the connection is encrypted, not that you are on the right site: the recommendation on browsing only over HTTPS explains this well.
Possible impact. Theft of your online banking details; if the confirmation code is handed over too, immediate access to the account.
What should make you suspicious. A link that does not lead to the bank’s domain (the domain is the part of a web address that identifies who owns the site); a request to “verify” details the bank already holds.
How to protect yourself. Never sign in to your account from a link you have received. Use the official app, a bookmark you saved yourself or an address you type in. A password manager (an app that stores your passwords and fills them in for you) also helps: it will not fill them in on a site other than the one it has saved.
2. Sender spoofing
In plain terms. The sender’s name says “your bank”, but the real address is something else. Spoofing means faking the apparent identity of whoever sends a message.
How it works. In email, the display name is a label that can be written freely, like a sender’s name handwritten on an envelope. Sometimes the address itself is imitated with near-identical domains: one letter swapped, or an extra word such as “security” added.
Why it works. On a phone, many email apps show only the name. And when the name looks right, we rarely look any further.
Possible impact. None on its own: it is the calling card that makes the other techniques believable.
What should make you suspicious. A full address that does not match the official domain; a message that arrived at an email address other than the one you gave the bank; a generic greeting instead of your name.
How to protect yourself. Treat the sender’s name as a clue, not as proof. Using an email address reserved for the bank helps, as suggested in the Resources piece on online banking security: if a message “from the bank” turns up anywhere else, you already know it is not from them.
3. The fake account block
In plain terms. A message announces that your account or card has been suspended, and that you must act immediately to reactivate it.
How it works. The text talks about “suspicious activity” or a “mandatory update of your details”. There is always a deadline, and the remedy always goes through a link, an attachment or a number given in the message.
Why it works. Because it plays on the fear of losing access to your own money, and the deadline takes away time to think. Even careful people can act while believing they are protecting themselves.
Possible impact. Handing over sign-in details, card details or codes; sometimes, opening a harmful attachment.
What should make you suspicious. A tight deadline, a threatening tone, vague references to “new regulations”, a solution that is only available through the message itself.
How to protect yourself. Open your bank’s app or website on your own: if there really were a problem with your account, you would see it there, among the notices.
4. The fake refund
In plain terms. This message does not threaten, it promises: a refund, a pending credit, a charge returned to you.
How it works. To “receive” the money, you are asked to confirm your card details, including the security code, or to sign in on a page that imitates your bank’s. The amount is often small and believable.
Why it works. Because it lowers your guard: we are wary of people asking for money, far less so of people who want to give it back.
Possible impact. Theft of your card details and unauthorised payments, often for small amounts so that they go unnoticed.
What should make you suspicious. A refund you were not expecting; a request for your full card details; a form outside your bank’s app. Receiving money never requires your card’s security code.
How to protect yourself. Check in your app whether any money is really on its way. No genuine credit requires your card details on a page reached through a message.
5. Smishing: the same trick by text message
In plain terms. The same deception as the emails, but by text message. The name smishing combines SMS and phishing.
How it works. The sender name on a text, like the one on an email, can be imitated: the fake message can therefore appear in the same thread as your bank’s genuine texts. The text is short and contains a link or a number to call back.
Why it works. Because a text feels more personal than an email, and on a phone screen the address behind a link is hard to read.
Possible impact. The same as the cloned email: sign-in details, card details, codes. Smishing often prepares the ground for a phone call.
What should make you suspicious. A link in a text about your account; an invitation to wait for, or call back, an “adviser”; an alarmed tone in a channel your bank usually uses for simple notifications.
How to protect yourself. Treat a text exactly like an email: no links, no numbers to call back. Check from the official app.
6. Vishing with a fake bank adviser
In plain terms. A phone call from someone presenting themselves as a member of your bank’s staff, often from the “fraud team”. Vishing combines voice and phishing.
How it works. The number on the screen can be faked to look like the bank’s. The caller knows your name, sometimes the last digits of your card: information gathered beforehand or taken from other breaches. The script revolves around an imminent danger and a solution to carry out right away, with their help.
Why it works. Because a polite, competent voice inspires more trust than an email, and the caller does not leave you time to check.
Possible impact. Confirmation codes handed over, “safety” transfers to accounts that are not yours, installation of remote access apps, meaning programs that let another person see and control your phone.
What should make you suspicious. Requests for codes, passwords or PINs; an invitation to move money to a “safe account”; pressure not to hang up; a request to install an app. Your bank does not ask you to move your money in order to protect it.
How to protect yourself. Calmly hang up and call your bank yourself, using the number on your card, in the app or on the official website. A number on the screen that looks right is not a guarantee.
7. The combined attack: email, phone call and confirmation code
In plain terms. The previous techniques are used together, each one making the next more believable, until the attacker obtains the last missing piece: the confirmation code.
How it works. The email or text is used to obtain your password, or at least to raise the alarm. Then the “fake adviser” calls, meanwhile using that password to set up a transaction, and asks you to read out the code that has just arrived or to approve a notification in the app, supposedly to “block” the attack. The code is an OTP (one-time password): a single-use code, valid for a few minutes, that your bank sends to confirm a sign-in or a payment. Reading it out to someone is like signing on their behalf.
Why it works. Because each piece confirms the others, and the second factor of authentication, designed to protect you, is handed over by you. This is why the recommendation on protecting accounts with a second factor insists so firmly on never sharing codes.
Possible impact. Transfers authorised with your codes, a new device added to your online banking, contact details changed.
What should make you suspicious. A code arriving when you have not started anything; a text describing a transaction different from the one explained on the phone; someone asking you to approve something “to cancel it”.
How to protect yourself. Always read the whole message that comes with a code: it usually says what the code is for. A code is never read out to anyone, not even to someone who says they are calling from the bank. If you find a transaction you do not recognise, the guide on what to do after a bank phishing email sets out the steps in the right order.
Summary table
| Technique | Main risk | What should make you suspicious | Effective defences |
|---|---|---|---|
| Cloned email with a fake page | Sign-in details typed into an imitation site | Link to a different domain, request to “verify” | Signing in only from the app, a bookmark or a typed address |
| Sender spoofing | A fake message that looks genuine | Different full address, generic greeting | Sender name as a clue, an email address reserved for the bank |
| Fake account block | Acting on impulse out of fear | Tight deadline, threatening tone | Checking notices inside the app |
| Fake refund | Card details handed over | Unexpected refund, request for the security code | Checking transactions in the app |
| Smishing | A link opened on your phone | Link in a text about your account, invitation to wait for a call | No links from texts, checking in the app |
| Vishing with a fake adviser | Codes or transfers granted over the phone | Requests for codes, “safe account”, pressure | Hanging up and calling back on the official number |
| Combined attack with an OTP | Transactions signed with your codes | Unrequested code, text that does not add up | Reading the code’s message, never reading the code out |
What they have in common
Seven different techniques, three defences that cut across almost all of them:
- Reaching your bank only through your own channels — the official app, a bookmark, a typed address, the number printed on your card.
- Never handing over codes or passwords — they are for you alone, and only when you are the one starting a transaction.
- Stopping when someone is rushing you — the deadline is part of the deception; a few minutes spent checking costs a genuine bank nothing.
These are not advanced measures, and they cover most real-world cases. To learn the details that give a fake message away, the guide to the signs of a fake bank email goes through them one by one.
Protection checklist
- ☐ I sign in to online banking only from the official app, a bookmark or a typed address
- ☐ I do not open links or attachments in emails or texts about my account
- ☐ I look at the sender’s full address, not just the display name
- ☐ I look for notices and messages inside my bank’s app or secure area
- ☐ I never read out confirmation codes, passwords or PINs to anyone
- ☐ I read the whole text that comes with a confirmation code
- ☐ If I get a call “from the bank”, I hang up and call back on the official number
- ☐ I have turned on app notifications for sign-ins and payments
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Understanding that bank phishing does not attack the bank’s systems but the trust, fear and haste of the person receiving the message |
| Skills | Recognising the mechanism of each technique from its signals, including numbers and senders that look genuine |
| Secure Behaviour | Stepping out of the message and checking through the official channel before clicking, replying or reading out a code |
Reference level: FL2 — Beginner, with elements of FL3 — Autonomous in the section on the combined attack with a confirmation code.
Conclusion
The techniques described here are rarely aimed at you in particular. They start from lists of addresses and numbers, and they succeed when a message reaches someone who is in a hurry.
That is why the most effective defence is a habit rather than a tool: you reach your bank only through the channels you have chosen, and codes are never given to anyone. Genuine messages stay in the app, and they will still be there tomorrow.
To work out where to start, the digital resilience self-assessment helps you take stock. For the tools that filter these messages out, there is an overview of anti-phishing technologies.
Something to think about. If tomorrow you received a call from a number identical to your bank’s, would you already know which number to call back to check?
Related resources
Short pieces from the Resources section, for anyone who wants to focus on a single aspect:
- How to recognise phishing when it is built to be convincing — messages crafted down to the last detail
- Online Banking Security: A Separate Address for the Bank — an email address reserved for your bank
- Two-Factor Authentication for Online Banking: The Access Points — how confirmation codes work
Related content
- Emails pretending to be your bank — the recommendation this belongs to
- Signs of a fake bank email — the indicators these techniques leave behind
- What to do after a bank phishing email — the steps to fix and prevent
- Anti-phishing technologies — the tools that make them less effective
- What happens after bank phishing — what they lead to when they succeed
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



