“We have detected unusual activity on your account. To avoid suspension, please confirm your details within 24 hours.” A message like this tends to arrive in the evening, while you are busy with something else. The logo is right, the colours are right, perhaps even your name is there. And there is a handy button that promises to sort everything out in a minute.
That convenience is exactly the delicate point. Emails pretending to be your bank are among the most common forms of phishing — attempts to get you to hand over passwords, codes or card details by posing as someone you trust. They do not work because the people who receive them are naive: they work because they imitate well and ask you to hurry. You are not a target because you are important, but because you have a bank account and an inbox, like almost everyone else.
This recommendation — R16 of the Cyber Welfare Framework — offers a simple habit that works even when the fake is flawless: an email that claims to be your bank is never used as a way in. You reach your bank on your own terms: from a bookmark, from the official app, or from an address you type yourself. No technical skills are needed, just a clear rule and the calm to follow it.
What this recommendation says
Recommendation R16 states that every email claiming to come from your bank should be treated as a notice to check, never as a tool to use.
In practice, that means four things:
- do not follow the links or press the buttons in the message;
- do not reply to the email, not even to ask whether it is genuine;
- do not open attachments you were not expecting, and do not call phone numbers given in the text;
- check through the official channel: sign in to your bank from your saved bookmark, from the app installed from the official app store, or by typing the website address yourself, and look for messages and notifications there.
At the heart of the rule is a change of perspective: you do not need to tell a real email from a fake one at a glance, you simply need to avoid being taken anywhere. If the message is genuine, you will find it again in your secure online banking area or in the app.
What it is not. It is not an invitation to ignore everything your bank sends you, or to treat every message with suspicion. Banks do send genuine and useful emails too. The recommendation does not ask you to delete them, but to read them the way you would read a leaflet: a piece of information that, if it matters to you, you go and check at the source. Nor is it a contest to spot spelling mistakes: many fake messages are written flawlessly.
Where it applies. To emails that mention your bank, your card or online payment services. The same logic applies to text messages and chat messages that pretend to come from your bank: in that case it is called smishing, which is simply phishing by SMS. It covers personal accounts, joint accounts shared with a family member, and business accounts.
Why it matters
A well-made fake email can be almost impossible to tell apart from a real one. A logo can be copied in seconds, the sender’s name can be anything the sender chooses and, in some cases, even the displayed address can be disguised: this is spoofing, forging the sender’s details so that a message looks legitimate. The page the link leads to can also reproduce the bank’s website faithfully.
The harm does not come from the email itself, but from what it asks you to do. The link leads to a page that collects whatever you type: your customer ID, your password, your card details and, increasingly, the temporary codes used to confirm a transaction. These are called OTPs (One-Time Passwords): codes valid for a few minutes that your bank sends you to authorise a sign-in or a payment. If you hand them over yourself, even that extra layer of protection can be bypassed.
Sometimes the email is only the first step: it may be followed by a call from a fake bank adviser who already knows your name and customer ID, and who asks you to “confirm” a transaction in order to stop it.
The concrete consequences show up on four fronts:
- access to your account — someone signs in to your online banking in your place and sees your balance, transactions and personal details;
- transactions you did not make — transfers, top-ups or payments authorised with the codes you handed over;
- disruption — cards to replace, an account temporarily frozen, forms and phone calls to put things right;
- stress and loss of trust — the feeling that you can no longer rely on your inbox, and sometimes the embarrassment of telling others what happened.
The strength of this recommendation is that it does not depend on the quality of the fake. A trained eye can still be fooled, especially on a phone; a rule of behaviour works the same way every time: if you never go in through the door the email offers, the fake door stays shut.
| Benefit of the “I reach my bank on my own” rule | Why it counts |
|---|---|
| Works even against flawless fakes | You do not have to recognise the message: you just do not use it as a way in |
| Protects credentials and codes | Passwords and OTPs are typed only on the site or app you reached yourself |
| Takes the power out of urgency | Checking in the app takes a minute and lifts you out of the message’s rush |
| Makes scam calls less convincing | Without your details, a fraudster has far less material to sound credible |
| Keeps you informed | Genuine messages are still waiting for you in your secure banking area |
A concrete example
Helen has used online banking for years, mostly through the app on her phone. One Tuesday evening, while she is cooking dinner, an email arrives: “Mandatory security update. Your access has been restricted. Click here to restore it.” The logo is her bank’s and the tone is polite.
Her thumb is already on the button. Then Helen remembers a rule she set herself a few months earlier: with the bank, never through emails. She closes her inbox, opens the bank’s app she installed from the official app store and signs in as usual. No warning, no restriction, no message in the notifications area.
To be thorough, the next day she calls the number printed on the back of her card. The adviser confirms that the bank has sent no message of that kind. Helen reports the email as phishing in her email program and deletes it.
Had she pressed the button, she would have landed on a page identical to her bank’s, which would have asked for her customer ID, her password and then the code sent to her by text.
What made the difference was the very first move: if you always reach your bank on your own, a fake email has no door to open. Helen did not have to work out whether the message was fake. She simply took her usual route.
When to apply it
The rule always applies, but there are moments when it makes an obvious difference.
- When the message puts you under pressure. “Within 24 hours”, “final notice”, “account suspended”: urgency is the most common lever, because it takes away the time to think.
- When it asks you to confirm or update details. Codes, passwords, card numbers, PINs: your bank has no reason to ask for these by email.
- When it announces money coming in or going out. A refund to claim, a payment on hold, a transfer to approve: the news may be true or false, but you check it in the app.
- When it contains an unexpected attachment. A “statement” or a “form to fill in” that you never asked for.
- When you are on your phone or in a hurry. A small screen hides the full sender address and the full link, and distraction does the rest.
- When the email looks completely genuine. This is when the rule helps most: the quality of a message says nothing about where it came from.
- When the same kind of message arrives by text or in a chat app. The channel changes, the rule does not.
How to apply it
You do not need to change everything in a day. You need to prepare the route once, and then use it every time.
- Save a bookmark for the official website. Type your bank’s address yourself, taking it from your account agreement, from paperwork you received at the branch or from the back of your card, and save it to your browser’s bookmarks. From then on, use only that bookmark for online banking.
- Install the app only from the official app store. Search for your bank’s app in the app store of your phone’s operating system and check that the publisher is the bank itself, or follow the link on the official website you reached from your bookmark.
- Set yourself a fixed rule for bank emails. No links, no buttons, no attachments, no replies — even when the message looks genuine. A rule with no exceptions is easier to follow than a judgement made case by case.
- Check through the official channel. Go in from your bookmark or the app and look at the messages area, notifications and recent transactions. If the message is real, you will find it there.
- If you want to speak to someone, use a number you already know. The one on the back of your card, on the official website or on your agreement. Never the one written in the email or the text, even if it looks like a freephone number.
- Report it, then delete it. Use the “report phishing” or “report spam” option in your email program. Many banks also list on their website an address where you can forward suspicious messages: look for it there, not in the email you received.
- Strengthen access to your bank. Turn on in-app confirmation for transactions and a second authentication factor, as explained in the recommendation on protecting accounts with a second factor. And switch on notifications for sign-ins and transactions, as suggested in the recommendation on account login alerts: if something happens, you know straight away.
A password manager — a tool that stores your credentials and fills them in for you — gives you extra help here: it normally stays silent on a fake page, however identical it looks. This is covered in the recommendation on storing passwords safely.
Common mistakes to avoid
- Trusting the logo and the design. Colours, layout and signatures are easy to copy. The look of a message says nothing about who actually sent it.
- Trusting the padlock. The padlock and HTTPS show that the connection is encrypted, not that the site belongs to your bank: a fake page can have one too. The recommendation on browsing only over HTTPS explains why.
- Replying to ask for confirmation. Your reply goes to whoever wrote the email — exactly the person you want to avoid — and confirms that your address is active.
- Calling the number given in the message. The person on the other end may be the one behind the scam, ready to talk you through it step by step.
- Searching for your bank online and clicking the first result. Adverts imitating the official site can appear among the top results. A bookmark avoids the problem altogether.
- Keeping quiet after a click. If you have already entered your details, this is not the moment for guilt but for action: contact your bank on its official number and follow the steps on what to do after a bank phishing email.
How this connects to the Cyber Welfare Framework
R16 brings security into one of the most everyday gestures there is: opening your inbox. It turns a reflex — clicking — into a conscious choice: checking for yourself.
| Pillar | How this contributes |
|---|---|
| Skills | Knowing how to set up a safe route to your bank: bookmark, official app, verified phone number |
| Awareness | Understanding that urgency, fear and convenience are the levers emails pretending to be your bank rely on |
| Secure Behaviour | Never using an email as a way into your bank, even when it looks genuine |
Digital maturity levels.
- FL1 — Basic. When an email looks like it is from your bank, you follow the link if the message convinces you. It is the most common starting point, not a fault.
- FL2 — Beginner. You no longer use links in bank emails: you always sign in from the app or your bookmark and check there.
- FL3 — Autonomous. You apply the same rule to texts and chat messages, you have turned on notifications and in-app confirmation, and you report suspicious messages.
- FL4 — Skilled. You also recognise the more elaborate variations, such as the phone call that follows the email, and you periodically review your bank’s official channels.
- FL5 — Expert-Guide. You help other people — parents, colleagues, friends — save the right bookmark and adopt the same rule.
R16 is the key step from FL1 to FL2, and it remains an active requirement at every level after that. It sits alongside R17, on handling all your email safely, which is coming soon.
How to check you are applying it properly
Three questions, to be answered honestly.
- The last time I received an email from my bank, did I use the link in the message or open the app on my own?
- Do I know where to find my bank’s phone number without looking for it in an email?
- If a flawless message arrived tomorrow, with my name and the right logo, would I know exactly what to do?
Quick checklist
- ☐ I have a bookmark for my bank’s official website, created by typing the address
- ☐ My bank’s app is installed from the official app store
- ☐ I do not click links, open attachments or reply to emails that mention my bank
- ☐ I check messages in my secure banking area or in the app’s notifications
- ☐ I know my bank’s official phone number and where to find it
- ☐ I have turned on notifications for sign-ins and transactions, and in-app confirmation
If a box stays empty, you already have your next step. If you would like a more structured measure of where you stand, you can take the digital resilience self-assessment.
In short
Emails pretending to be your bank can be very convincing, and you do not have to be careless to fall for one. That is why the strongest protection is not becoming an expert at spotting them, but changing the way you reach your bank.
The rule is simple: no links, no replies, no attachments. You reach your bank from a saved bookmark, the official app or an address you type yourself, and that is where you check whether the message really exists. If you need to speak to someone, you use a number you already know.
It is a small habit that costs one extra minute and gives you back control: you decide which door to use, not the person who wrote to you.
Something to think about. If an email identical to your bank’s arrived this evening, which door would you choose to go in through?
Explore this recommendation
This recommendation is the pivot of a content unit. Each post looks at a different aspect.
- Impact of bank phishing — what gets hit, in terms of the confidentiality, accuracy and availability of your account and data
- What happens after bank phishing — the concrete effects on the operational, financial, legal, reputational and personal levels
- What to do after a bank phishing email — the mitigations, from the first call to your bank through to recovery
- Signs of a fake bank email — the indicators to look for and what they really mean
- Anti-phishing technologies — the tools available, their advantages and limits
- Bank phishing techniques — how attacks that imitate your bank are put together
Related resources
Short reads from the Resources section, for anyone who wants to focus on a single aspect:
- How to Recognise Phishing When It Is Built to Be Convincing
- Online Banking Security: A Separate Address for the Bank
- Two-Factor Authentication for Online Banking: The Access Points
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



