The fake bank text is only act one
Most guides stop at "do not tap the link", which leaves out the part that actually empties accounts. In Britain the fake bank text is rarely the whole con. It is the knock at the door. What follows is a phone call, and the phone call is where the money goes. So this guide runs in two acts, and the second is the dangerous one.
Act one: the text that gets you nervous
The bank on the label is whatever most people bank with, so you will see Barclays, Monzo, HSBC, NatWest, Lloyds, Halifax and Starling. The job of act one is not to rob you. It is to get your heart rate up, so that when the phone rings you are already half convinced your money is under attack.
Read the real thing next to the fake
Hold a genuine Lloyds or HSBC alert up against the scam and the gap is obvious. A real bank text tells you something that already happened. A payment left your account, a card was used abroad, someone logged in. When a real fraud team does check with you, it asks a plain yes or no, the sort of "Did you try to pay £60 at Tesco? Reply Y or N" that needs no link at all. What a genuine message never does is send you to a web page to key in your card number, PIN or full banking password. Your bank already knows who you are, so it has nothing to verify by making you type it again.
The web address gives it away every time. Your bank lives on its own name and nothing bolted onto it, barclays.co.uk and no more. The scam lives on a lookalike, barclays-secure.xyz or monzo-verify.info or hsbc-alert.online. A word stuck before or after the bank name, an odd ending like .xyz or .info, any of those and it is fake. And a text can wear the bank's name at the top and drop into the same thread as your real alerts, so the sender label proves nothing.
Act two: the call and the "safe account"
This is the payload. A while after the text, sometimes minutes, sometimes the next day, the phone rings. The caller is calm, knows your name, maybe the last four digits of a card, and says they are from the fraud team about that suspicious payment. Your account is compromised, they say, and the only way to protect your balance is to move it now into a new "safe account" they have opened in your name. They stay on the line while you do it, and may tell you not to mention it to the cashier, because "the fraudster may be watching".
Every word of that is the scam. This is authorised push payment fraud, APP for short, and it is the biggest way people lose real money to texts in the UK. Your bank will never ask you to move money to keep it safe, never set up a "safe account" for you, never ask for a one time passcode read back to it, and never tell you to hide a transfer from staff. The instant a caller wants you to move money to protect it, that caller is the thief. Hang up, wait a couple of minutes so the line clears and ring your bank on the number on your card.
When it comes dressed as the taxman
The same machine wears a government coat too. One version dangles a treat, "HMRC: you are due a tax refund of £274.50, claim it here". The other tightens your chest, "HMRC: unpaid tax detected, settle today to avoid legal action". Both push you to a page like hmrc-rebate.xyz for your card, address and Government Gateway login. HMRC never texts a link to pay a bill or claim a rebate. Real tax sits in your account at gov.uk or lands on the doormat by post. There is a fuller walk through in the DVLA and tax refund scam.
If the text just arrived and you have done nothing
- Leave the link alone. Not even a quick look. The page is built to be convincing.
- Do not ring any number in the message. To check, ring the number on the back of your card or the one inside your official app.
- Look the normal way. Open your banking app or type the bank's address yourself. Anything genuinely wrong shows up there.
- Report it. Forward the text to 7726, free, which spells SPAM on the keypad. On iPhone you can also report it as junk.
If you tapped, typed or moved money
- Ring your bank now on the number on the back of your card and ask them to freeze the card and watch the account. If you moved money to a "safe account", say so plainly. The faster you call, the better the chance of stopping it.
- Change your online banking password and app passcode from the official app and never from a link, then change it anywhere else you reused it.
- Report to Action Fraud at actionfraud.police.uk or 0300 123 2040. In Scotland, report to Police Scotland on 101. Call 999 only if someone is in immediate danger.
- Under UK rules banks must reimburse most victims of authorised push payment fraud. Ask about a reimbursement claim, and do not let embarrassment talk you out of it.
Speed matters more than feeling foolish. These scripts are written by professionals to catch sharp people on a busy day. For the calm version of these steps, read you already tapped a scam link.
The one most likely to catch your mum
The people this hits hardest are not the ones reading a guide at lunchtime. They are the ones who pick up a call that already knows their name and freeze. The very same two act script runs in the States as the fake bank text about a locked account, only the bank names change. To see the operation behind the call, read how SMS scam gangs actually operate, and if a parcel fee text turned up the same week, that is the same gang with a different mask.
This is where the Escudo app helps. It filters known scam patterns on the iPhone and sets act one aside in a junk folder before it is read, so the text that would have got the heart racing never lands in front of your mum. It cannot tell you whether one specific message is really from your bank, and it does not pretend to. Nothing is deleted, it is only set aside, and your messages never leave the phone.
Fewer scam texts reaching the people you love
The Escudo app is coming soon to iPhone in the UK. Download it free on your iPhone.
Download on the App Store