An email with your bank’s logo, a warning about “unusual activity”, a button to verify your details. You clicked, perhaps you even typed in your username and password, and only afterwards did something feel wrong. The question that follows is a simple one: what do I do now?
Phishing is a fake message built to look genuine, designed to get you to hand over your sign-in details, card details or confirmation codes. When it imitates your bank, it is natural to feel embarrassed or anxious. There is no need: it happens to careful, well-informed people, because these messages are made precisely to arrive at the wrong moment. What matters now is acting early and in the right order. Early, though, does not mean in a rush.
This post organises the countermeasures into four moments: prevent it from happening again, detect signs that your account is being misused, respond in the first few hours, and recover a stable situation. It is the practical, hands-on side of the recommendation on emails pretending to be your bank: you reach your bank only through its official channels, never through a link you have received. If it has just happened, you can go straight to section 3.
Before you start: why the order matters
After a bank phishing email there are many things to do, but they do not all carry the same weight. Some stop the damage, others help you document it, and others help you avoid falling for it again.
The order of priority that works in most cases is this one:
- call your bank on its official number — it is the only party that can block sign-ins and transactions;
- block the cards whose details you entered, or that are linked to the account;
- change your credentials for online banking, meaning your online access to the account, and anywhere else you used the same password;
- check transactions and payees, meaning the people or accounts that transfers can be sent to;
- report the message to your bank and to your email provider;
- keep the evidence: emails, screenshots, times;
- report it to the police or the relevant authority.
Not every case is the same, and it helps to work out straight away which one you are in:
- you only opened the email without clicking anything: report it and delete it after keeping a copy; usually nothing else is needed;
- you clicked but did not enter any details: close the page, report the message and keep an eye on your transactions over the following days;
- you entered sign-in details, card details or codes: follow every step, in the order given.
1. Prevention: reducing the risk before anything happens
This part is for next time. If you are dealing with something that has already happened, come back to it calmly, once the situation is settled.
Reach your bank only through your own channels
What to do. Save your bank’s address as a bookmark in your browser (a quick link to a site you use often), or use the official app downloaded from your phone’s official app store. If an email tells you there is a problem with your account, do not use its links: open the bookmark or the app and check from there, in the messages section of your secure area.
Turn on transaction notifications
What to do. Many banks can alert you with an in-app notification or a text message for every sign-in, payment or transfer. Turn them all on, even the ones that seem unnecessary: they are the quickest way to notice a transaction you did not make.
Strengthen access to your account
What to do. Use a unique password for online banking, one that appears nowhere else, and keep strong authentication switched on: confirming sign-ins and transactions with a second element, such as a code or an approval in the app. Where your bank allows it, prefer confirmation in the app over a code sent by text message.
Why it counts. A stolen password on its own is no longer enough to move money. It is the same logic explained in the recommendation on protecting accounts with a second factor.
Keep a separate email address for your bank
What to do. Consider an email address used only for your bank and nothing else. A message “from the bank” that arrives at any other address is, in all likelihood, fake.
2. Detection: noticing early
Read your notifications, even the small ones
What to do. Do not archive sign-in or payment notifications without reading them. A sign-in from a new device, a small payment to a merchant you do not know, a change to the phone number on your account: these are often the first signs, and they arrive before the bigger damage.
Check your transactions regularly
What to do. Open your list of transactions in the app or on the website at least once a week, not only when your statement arrives. Look at pending transactions too: that is sometimes where a suspicious one shows up first.
Be wary of phone calls that follow an email
What to do. If, after a suspicious email, someone calls claiming to be from your bank and asks you for a code, an approval in the app or to move your money “to a safe account”, hang up. Then call your bank yourself on its official number. The most successful scams often combine an email with a phone call: the first prepares the ground, the second asks for the code.
The full list of the signs of a fake bank email is in the dedicated post.
3. Response: what to do in the first few hours
Here, more than anywhere else, the order matters. Each step takes only a few minutes.
Call your bank on its official number
What to do. Use the number printed on the back of your card, the one in your contract or in the official app you already have installed, or the one you find on the website after typing the address in yourself. Never the number written in the email, in a text message or in the first result of a search engine. Explain what happened: what you entered, on which page, and at what time.
Why it counts. Your bank can suspend online access, stop transactions that are still in progress and flag the account as at risk. Some transfers go through in seconds, others do not: the sooner you call, the more room there is to act.
Block your cards
What to do. If you entered the details of a card, ask for it to be blocked during the same call or in the app, where that feature exists. Your bank will issue a new card with a different number and codes. If you are unsure which cards are involved, block them all: replacing them is a nuisance, not a loss.
Change your credentials
What to do. Change your online banking password from the app or your bookmark, never from the link in the email. If you gave away your PIN or the answers to your security questions, ask your bank how to replace them. If you used the same password anywhere else, starting with your email, change it there too: that is the principle of a unique password for every account.
Don’t forget. Do not delete the phishing email: you will need it for your report to the bank and to the police.
Check transactions, payees and devices
What to check. Transfers and payments from the last few days, pending transactions, recently saved payees, changed spending limits, the phone number and email address linked to the account, and the devices authorised to use the app. Someone who gains access often tries to add a payee or a device so that they can come back later. Report anything you do not recognise to your bank.
4. Recovery: getting back to a stable state
Report the message
What to do. Many banks list on their website an address or a feature for reporting fraudulent messages: look for it through the official channel and forward the email there. Use your email provider’s “report phishing” feature too. Every report helps block the same message for other people.
Keep the evidence
What to keep. The original email, the sender’s address, the address of the fake page if you remember it, screenshots, any text messages you received, the list of disputed transactions, and the date and time of your call to the bank along with the name or reference number you were given. Put it all in one folder: it saves you from piecing everything together again later.
Report it to the police
What to do. If money has left your account or you gave away sensitive details, report it to the police or to your country’s official reporting service for online fraud, which is often available online. Your bank may ask for a copy to assess your dispute of the transactions. Timescales and conditions for any refund depend on your contract and on the rules in your country: ask your bank about them, ideally in writing.
A word of caution. There are no legitimate services that reach out to you first and offer to “recover lost money” for a fee. Offers of this kind are themselves a scam.
What to do. If the account is a joint account, or someone in your family uses the same cards, let them know with a direct message. They may receive the same email, or a phone call that seems to follow on from it.
Build on your good habits
What to do. Close the loop: a bookmark or the app as your only way in, notifications switched on, a unique password, strong authentication and a weekly look at your transactions as a habit.
A plan in three sessions
If the list feels long, here is how to spread it out without missing anything.
Session 1 — Straight away (15 minutes)
- Call your bank on its official number and explain what happened.
- Block the cards involved.
- Change your online banking password from the app or your bookmark.
- If you used the same password elsewhere, change your email password first.
With this one session alone, you have closed the main routes to your money.
Session 2 — The same day (20 minutes)
- Check transactions, pending payments and payees.
- Check the phone number, email address and devices linked to the account.
- Save emails, screenshots and times in a single folder.
- Report the message to your bank and to your email provider.
Session 3 — Over the following days (20 minutes)
- Report it to the police and give a copy to your bank.
- Turn on all transaction notifications.
- Save your bank’s bookmark and use only that, or the official app.
- Check your transactions again after a few days.
In less than an hour in total, split into three moments, the situation is under control and documented.
Frequent mistakes when fixing things
Even people who react straight away often stumble at the same points.
- Calling the number given in the email. The person who answers is whoever wrote it, not your bank.
- Replying to the email to ask for an explanation. It confirms that your address is active and opens a conversation with someone who wants to deceive you.
- Changing your password through the link you received. You end up back on the fake page.
- Trusting someone who calls “from the fraud team”. No bank asks you over the phone for codes, your PIN or to move money to another account to protect it.
- Deleting the email to put it behind you. It is the main piece of evidence, both for your bank and for the police.
- Waiting out of embarrassment. The time lost in doubt is the time you need to stop a transaction.
- Stopping at the bank. If the password was the same as your email password, your inbox needs securing too.
Operational checklist
Stage 1 — Stop the damage
- ☐ Bank contacted on its official number
- ☐ Cards involved blocked
- ☐ Online banking password changed through the official channel
Stage 2 — Look for warning signs
- ☐ Transactions and pending payments checked
- ☐ Recently saved payees verified
- ☐ Phone number, email and devices linked to the account verified
Stage 3 — Document and report
- ☐ Emails, screenshots and times saved in a single folder
- ☐ Message reported to the bank and to the email provider
- ☐ Police report filed and a copy given to the bank
Stage 4 — Consolidate
- ☐ Access only through a bookmark or the official app
- ☐ Transaction notifications switched on
- ☐ Strong authentication on and a unique password for the bank
A short scenario
John receives an email: “Unusual sign-in detected, verify your details today”. He clicks and enters his username and password. When the page also asks for the code he has just received by text message, he stops: his bank does not usually ask for it like this.
He does not reply to the email and does not call the number written in it. He takes out his card, calls the number printed on the back and explains what he did. The bank suspends his online access and finds a payee added a few minutes earlier: it removes it. John changes his password in the app, saves the email and the screenshots, and that evening files a report online.
The next day a “fraud officer” calls and, to “cancel the case”, asks him to approve a transaction in the app. John hangs up and calls his bank back on the official number: nobody there had tried to reach him. Ten minutes, in the right order, and one phone call he did not believe.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Skills | Knowing how to carry out a containment sequence in the right order, starting with the bank |
| Awareness | Understanding why contact should always be started by you, through the official channel |
| Secure Behaviour | Turning bookmarks, notifications and checking transactions into habits |
Reference level: FL2 — Beginner. This is the level at which you know the main risks and confidently follow a few clear rules, even under pressure, without needing technical skills.
Conclusion
Falling for a bank phishing email is not a personal failing, and there is almost always room to limit the damage. That room depends on two things: how quickly you contact your bank, and whether you contact it through the right channel.
What to do right now. Today, while you are calm, save your bank’s official number in your contacts, copying it from the back of your card, and its website as a bookmark. If you ever need them, you will not have to look for them in a moment of stress.
To choose the tools that help you avoid falling for it again, the post on anti-phishing technologies compares them. To see where you stand, the digital resilience self-assessment gives you a reference point.
Related content
- Emails pretending to be your bank — the recommendation this belongs to
- Anti-phishing technologies — the tools that make these fixes sustainable
- Signs of a fake bank email — what to watch in order to notice in time
- What happens after bank phishing — what you avoid by acting early
- Bank phishing techniques — what you are protecting yourself against
Related resources
Short explainers from the Resources section, for anyone who wants to focus on a single aspect:
- Online Banking Security: A Separate Address for the Bank
- How to Recognise Phishing When It Is Built to Be Convincing
- Two-Factor Authentication for Online Banking: The Access Points
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



