Bank Impersonation Scam Calls: Why Caller ID Lies

It’s Tuesday, 5:40 in the evening. Your phone rings and the screen shows the name of your bank, the same name that appears when the real bank texts you a login code. A calm voice introduces himself as Daniel from the fraud department. He’s sorry to disturb you, but there are two pending payments on your account, one to a crypto exchange, one to an electronics shop in another country. Did you authorise these? No? Good, that’s why he’s calling. He reads out the last four digits of your card to “confirm he has the right customer.” They match. Your pulse goes up. He stays calm. That calm is the product; it’s what you’re supposed to trust.

Everything about this call can be fake. The number, the name on the screen, the card digits, the department, Daniel. This article explains how a bank impersonation scam call works from the inside, and gives you a verification protocol that holds even when every visible signal is forged.

A spoofed bank phone number is trivial to produce

Caller ID feels like identification. It isn’t. It’s closer to the sender line on a postcard: a field the sender fills in, which nobody along the route is obliged to check.

When a call is set up, the originating side declares a number, and that declared number is what your phone displays. On old fixed networks, declaring a false number took some effort. On internet telephony it takes a configuration field. Fraud groups route calls through services that let them present any number they like, so they present your bank’s published customer service line. Your phone, trying to be helpful, matches that number against its contacts and shows the bank’s name. Some networks now cryptographically attest calls (the US STIR/SHAKEN system is the best-known attempt), but coverage is partial and international calls slip through the gaps.

The consequence is blunt: an incoming call can never prove who is calling. The FTC’s guidance on phone scams says it plainly: caller ID can be faked, so don’t trust it.

The card digits don’t prove anything either. Partial card numbers, your address, even your account balance can come from earlier phishing, a data breach, or malware. Scammers open with accurate details precisely because you assume only your bank could know them.

The script of the fake fraud department

These calls follow a script honed over thousands of attempts, and it’s worth knowing the beats before you hear them live.

First, the alarm: suspicious payments, a compromised card, someone at a branch trying to withdraw from your account. The threat is always active right now. Urgency is load-bearing; a victim who has time to think is a lost victim.

Second, the rescue. This is where the variants split. In the classic safe account scam, Daniel explains that your money must be moved immediately to a “safe account” or “holding account” the bank has opened for you, because your current account is compromised. He’ll help you do the transfer yourself, which neatly defeats the bank’s own fraud detection, since you are the authenticated customer making a deliberate payment. Other variants ask you to read out a one-time code “to cancel the fraudulent payment” (the code actually approves it), or to install remote access software so the “technician” can secure your device, or, in courier fraud, to hand your card to a colleague who will collect it from your home. Take Five, the UK banking industry’s fraud campaign, documents that last one in depressing detail.

Third, the leash: stay on the line. Don’t call anyone, don’t visit a branch, and above all don’t tell your family, because “the fraudster might be someone close to you” or “staff at your branch are under investigation.” Isolation is not a side effect of the script. It is the script.

What your bank will never ask

Banks and regulators publish the same short list, and it’s worth memorising because it turns a sophisticated con into a checklist failure. Your bank will never:

  • ask you to move money to a “safe account” — that account does not exist, in any bank, anywhere
  • ask for your full PIN, full password, or a one-time code over the phone
  • send a courier to collect your card, or ask you to hand it to anyone
  • ask you to install remote access software such as AnyDesk or TeamViewer
  • pressure you to act before you’ve had time to hang up and check

One item on that list ends the call on its own. The moment anyone mentions moving money to keep it safe, you are talking to a criminal. There is no polite ambiguity left at that point.

Hang up and call back, and where that protocol leaks

The standard advice is good: hang up, then call your bank yourself on a number you sourced independently, from the back of your card or the bank’s website that you typed in yourself. In the UK you can dial 159, a short code that routes you to your own bank. Never call a number the person on the phone gave you; that just reconnects you to the scam with extra confidence.

But be honest about the weak points, because scammers know them better than you do.

The famous one is the held line. On older analogue landline exchanges, a call was only fully torn down when the caller hung up; if the victim hung up and immediately redialled on the same landline, some networks kept the old connection alive for two or three minutes. Fraudsters stayed on the line, played a fake dial tone, and had an accomplice “answer” as the bank. This was real and heavily exploited, mostly against landline users in the UK, until the BBC reported in 2014 that BT, Sky and Virgin Media were cutting those clearing delays to around two seconds. On mobile phones the trick never worked, because hanging up ends the call, full stop. So today the held line is mostly a historical threat, but “mostly” is doing some work in that sentence: exchanges and VoIP setups vary. The robust habit costs you nothing. Call back from a different phone if one is nearby, or wait a couple of minutes and check you hear a normal dial tone first.

The modern successor is the call merging scam: the caller persuades you to merge in a “colleague,” and the merged call is actually an automated call from your bank reading out a one-time code, which the fraudster now hears. Never merge or forward calls at a stranger’s request.

And the leak nobody patches: the callback only verifies the bank. It does not calm you down. If the script has already convinced you the bank itself is compromised, you’ll call the real bank and disbelieve them. That’s why the pause matters as much as the number.

If the money already moved

Speed genuinely matters here. Call your bank’s fraud line immediately and ask them to attempt recall of the payment; the first hours are when funds are still traceable. In Belgium, block your cards through Card Stop on 078 170 170 (from abroad +32 78 170 170); verify that number yourself on the official cardstop.be site before you need it. Then report to the police. In the UK that’s Action Fraud (0300 123 2040); in the US, ReportFraud.ftc.gov. File a formal dispute with your bank in writing. And tell someone. Shame is the scammer’s after-sales service; it keeps victims silent and repeatable.

The asymmetry underneath all of this

Here’s what I keep coming back to as a founder. When your bank calls you, it can verify you in seconds: codes, apps, security questions. You cannot verify it at all. The channel only authenticates in one direction, and every scam in this article lives inside that asymmetry.

We’re building Hongi to close it. The app gives two paired people rotating codewords, refreshed every 30 seconds and computed offline, so an impersonator can never know both sides. Today that already gives you something concrete for the worst moment of the call: before you move a cent under pressure, call a person you’ve paired with, your partner, your daughter, a friend, and verify them by codeword before you trust their advice. A genuine “wait, this is a scam” from a verified voice beats any script. The same mechanism is where our work with organizations is headed, so that one day “this is your bank calling” is something a caller can actually prove. Until then, the protocol above is your best defence, and there’s more on how verification works in our FAQ.

Hang up first. Verify second. Move money never.