CYBER WELFARE

Protect your Digital Privacy

The impact of bank phishing: what gets hit when an email looks like your bank

When an email arrives carrying your bank’s logo, the most common reaction is “I’d never fall for that”, or “there isn’t much in my account anyway”. Both are understandable, but they start from the wrong idea: that the damage is measured only by your balance. Phishing — a message built to look as if it comes from a trusted sender and to persuade you to hand over information or take an action — isn’t prepared for you in particular. It is sent out in huge numbers, to anyone, counting on someone replying at the wrong moment.

The more useful question is a different one: if that message worked, what would be touched?

This post answers it by looking at the impact of bank phishing through the three aspects by which the security of any information is measured: that it stays private, that it stays correct, and that it stays available. They are the practical translation of three technical words — confidentiality, integrity, availability — and they help you see that the damage from a fake email is never of just one kind.

It expands on the recommendation about emails pretending to be your bank: don’t follow the links, don’t reply, and reach your bank only through the channels you have chosen yourself.

Three questions to measure an impact

Before getting into the details, it’s worth having the right questions at hand. For your relationship with any bank — and not only when a suspicious message turns up — they are these:

  1. What could whoever built the fake page read or collect? — this is the confidentiality question.
  2. What could they change or authorise in my name? — this is the integrity question.
  3. What would I no longer be able to do if my account or cards were blocked? — this is the availability question.

Applied to the account your salary is paid into, these three questions almost always produce the same answer: a lot. Applied to a prepaid card you rarely use, the answer seems modest — until you discover that the phone number and the app login are the same as for your main account. That is where the maths changes: the impact isn’t measured by the email you received, but by what that email manages to get you to hand over.

1. Confidentiality: your login details, card details and codes stay yours

Confidentiality is the guarantee that information can be read only by those who are authorised to read it. An email pretending to be your bank hits it directly, because its whole purpose is to get you to type, on a page that isn’t your bank’s, what should stay between you and your account.

A practical example

You receive a message about a “security details update” that needs completing. The link leads to a page identical to the sign-in page you know. You enter your customer number and password; straight away the page asks for the code that has just arrived by text message. That code is a one-time passcode, or OTP: a temporary code, valid only once, that the bank uses to confirm a sign-in or a transaction.

What the incident looks like

In just a few steps, a fake page can collect everything it needs: your online banking login details, your card number with its expiry date and CVV (the three-digit security code printed on the back), and the one-time code you have just received. Then there’s what can be seen once inside the account: your transactions reveal where you work, how much rent you pay, which medical appointments you have, which subscriptions you keep. No money has to move for simply reading to be a harm already.

What to watch for

  • a page that asks, all at once, for details your bank never asks for together, such as your full password, a one-time code and your card details;
  • after you submit, a vague error message or a sudden redirect to the real site;
  • a text message with a code you didn’t request at that moment;
  • a sign-in notification from a device or a place you don’t recognise.

What to do

Never enter your login details starting from a link you received: open your bank from a bookmark, from the official app, or by typing the address yourself. If you’ve already entered something, contact your bank on the official number printed on the back of your card or in your contract, change your login details through the genuine channel and, if you gave away your card details, ask for the card to be blocked. Turning on account login alerts helps you notice sooner when someone who isn’t you has signed in.

2. Integrity: payments, payees and contact details stay correct

Integrity is the guarantee that data isn’t altered by anyone without the right to do so. Here, bank phishing weighs in a different way: it’s no longer about what someone can see, but about what they can change or authorise in your name.

A practical example

With your login details and a one-time code, someone adds a new payee — the person or business you send money to — and makes a transfer. The bank isn’t being attacked: it is carrying out an instruction that, from the way it arrives, looks like yours. There is also a quieter variant: an email pretending to be your bank, or a supplier, announcing “new bank details” for a regular payment. Nobody gets into your account, but you end up paying into the wrong one yourself.

What the incident looks like

The most treacherous changes involve exactly the details you need to spot the problem and regain control: the mobile number your codes go to, the email address for notifications, the devices allowed to use the app. Once those are changed, the alerts stop reaching you. At the same time, your card’s spending limits may change, or payments may appear that look ordinary on a quick glance at your statement.

What to watch for

  • a confirmation message for a new payee, a new device or a change of phone number that you didn’t request;
  • notifications from your bank that suddenly stop arriving;
  • names in your list of saved payees that you don’t recognise;
  • a request to pay a familiar amount into account details different from the usual ones.

What to do

Always read the whole text of the message containing the code: it usually says what you are authorising, and a “new device” or “new payee” you didn’t ask for is reason enough to stop. From time to time, check your saved payees, contact details and linked devices — from the app, or from the website you reached yourself. If someone tells you their bank details have changed, check with a phone call to a number you already had, not the one written in the message.

3. Availability: your account and cards work when you need them

Availability is the guarantee of being able to use your services at the moment you need them. It’s the easiest impact to recognise, because it shows up as a locked door — and it often happens precisely when the bank is doing its job.

A practical example

In the morning you try to pay by card and the payment is declined. You open the app and it asks you to activate it again. The bank has spotted unusual activity and has frozen your account and cards to protect them.

What the incident looks like

The block is a protection, not a punishment, but it comes at a practical cost. A replacement card takes a few days to arrive, and in the meantime the regular payments linked to the old card don’t go through: bills, subscriptions, the card saved on your phone. Access to online banking may stay suspended until you prove who you are again, over the phone or in a branch. And if whoever got in changed your password, the locked door wasn’t put there by the bank: you are the one left outside.

What to watch for

  • your correct login details are rejected on an app you used normally;
  • your card is declined for no obvious reason;
  • the app asks to be set up from scratch, even though you haven’t changed phone;
  • emails and text messages from your bank stop arriving, or arrive through channels you don’t know.

What to do

Keep your bank’s official number saved in your contacts, taken from the back of your card or from your contract, so you never have to look for it inside a message. Having a second way to pay and a short list of the regular payments linked to your card makes a few days of blocked access far easier to manage. And if you lose access, always start from your bank’s official channel: it’s the root you rebuild from.

AspectWhat whoever built the message can doWhy it matters
ConfidentialityCollects login details, card details and one-time codes, and reads your transactionsThe harm happens even without any money moving, and often goes unnoticed
IntegrityAdds payees and devices, changes contact details and limits, makes paymentsNotifications stop reaching you and recovery takes longer
AvailabilityTriggers a frozen account, replacement cards, or locks you outStops everyday and regular payments, sometimes for days

One scenario that brings them together

Helen receives an email one evening, after dinner. The logo is her bank’s, the tone polite: “To keep using the service, please complete your security details update.” She clicks, enters her customer number and password, then the code that arrives by text. The text said “code to authorise a new device”, but she copied it without reading it. The page thanks her: “Verification complete.”

From there, in sequence: her login details and the code are collected, and her transaction history is read (confidentiality); a new device is authorised, the phone number for notifications is changed and a new payee is added (integrity); the next morning the bank, spotting an unusual transaction, freezes her account and cards, and Helen can pay neither for her shopping nor sign in to the app (availability). Three different impacts, a single cause: a link followed instead of a bookmark.

The impacts that show up later

Not every effect appears right away. Some develop over time, which is why “nothing has left my account” isn’t a reliable check.

  • Data used to make another request believable. Your name, bank details, recent transactions or branch name help build later calls and messages that are far more convincing — such as a fake bank adviser “calling to stop a suspicious payment”.
  • Card details used later on. The card number, expiry date and CVV can be used weeks afterwards, perhaps for small online purchases that blend in with your usual spending.
  • Access that stays open. A device authorised on the app, or an active session (the “stay signed in” state on a browser), can keep working even after a password change, unless it is explicitly revoked.
  • An address marked as active. Anyone who has clicked or replied once tends to receive more attempts, because their address shows up as reachable and responsive.

This isn’t a reason to live on high alert. It’s the reason protection has to be preventive: reaching your bank only from a bookmark, the official app or an address you type, together with a second sign-in factor, reduces all four of these effects — including the ones you’ll never see. For a full guide to the second factor, see the recommendation on protecting accounts with a second factor.

Not all banking details weigh the same

The impact depends on what you hand over and on what that detail lets someone reach.

Detail handed overMain impactWhy
Online banking customer number and passwordAll threeThey open the door to the account and everything in it
One-time code or in-app confirmationIntegrityIt authorises one specific transaction or device: it’s as good as a signature
Card number, expiry date and CVVConfidentiality and integrityThey allow online payments in your name
Mobile number and contact emailIntegrity and availabilityNotifications, codes and access recovery all go through them
Personal details and bank account detailsConfidentiality, with delayed effectsThey make later scams believable
A written reply to the emailConfidentialityIt confirms the address is active and may reveal personal details
A click on the link, without entering anythingLow on its ownIt usually stops there, but flags an address as responsive

The second row is the one that counts most: the most sensitive detail isn’t always the password, but the code that confirms a transaction you never saw.

Why an almost perfect email matters too

A polished message doesn’t reduce the impact, because no visual detail proves where it really comes from.

Element of the emailWhy it doesn’t prove it’s from your bank
The right logo, colours and layoutThey can be copied from any genuine message
Your first name and surnameThey circulate in many lists, including from breaches of other services
The last digits of your cardThey may come from another data leak or from a receipt
The bank’s name as the senderThe display name can be written freely
A link starting with “https” and a padlockThey show an encrypted connection, not an honest site

The padlock deserves one more line: it guarantees that the connection travels protected, as the recommendation on browsing only over HTTPS explains, but it doesn’t tell you who is on the other end. If a detail can be copied, it proves nothing: the proof lies in the channel you choose.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessRecognising that a single fake message produces impacts on different levels, even without any immediate loss
SkillsBeing able to read confidentiality, integrity and availability as three concrete questions about your own banking
Secure BehaviourReaching your bank only through the channels you’ve chosen, and regularly checking payees, contact details and linked devices

Reference level: FL2 — Beginner. This is the level at which you move from “I know I shouldn’t click on links from the bank” to “I understand what happens if I do.” Awareness of the impacts is what keeps the behaviour steady over time. If you’d like to see where to start on your own path, the digital resilience self-assessment takes only a few minutes.

Summary

  • Confidentiality is about what gets collected or read: login details, card details, one-time codes, transactions.
  • Integrity is about what gets changed or authorised: transfers, payees, contact details, authorised devices.
  • Availability is about what you can no longer use: a frozen account, replacement cards, regular payments interrupted.

An email pretending to be your bank doesn’t produce just one impact: it opens the door to all three, on your account and on everything linked to it.

One thing to do today. Bookmark your bank’s official address, or make sure you are using its official app. Then, signing in from there, check three things: the authorised devices, your list of saved payees, and the phone number and email used for notifications. It takes about ten minutes, and it covers all three impacts at once.

Related resources

Short pieces from the Resources section, for anyone who wants to focus on a single aspect:

Related content

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.