Impersonation attack field guide
Bank and Business Impersonation Texts: Verify the Alert Before You Act
The logo is familiar. The panic is deliberate. The safe route back to the institution begins somewhere the message did not provide.
Map the attack, not just the opening text
The first message is often only the doorbell. It creates a believable account problem and directs the recipient to a controlled phone number or website. A convincing ‘fraud specialist’ can then convert fear into credentials, codes, transfers, or device access.
Record the entire sequence: alert, link, callback, person or department claimed, questions asked, codes requested, payment instructions, and any follow-up. The handoffs are evidence of how the operation works.
Re-enter through a trusted door
Open the official institution app, use a bookmark, type the known domain, or call the number printed on a card or statement. Explain that an unsolicited message alleged account activity and ask whether the alert exists in the institution’s own system.
Do not merely search the brand name and call the first advertisement or directory result. Impersonators buy ads and manipulate listings too. Use a channel with an existing trust relationship.
- Exact sender and callback number
- Displayed and final link destination
- Transaction, login, refund, or suspension claimed
- Credential, code, transfer, gift card, crypto, or remote-access request
- Department and employee identity claimed
- What the real institution confirms independently
Let the requested action classify the risk
A request to confirm whether a transaction is yours is different from a request to reveal a password, PIN, one-time code, full card number, seed phrase, or screen-sharing access. The latter group can directly enable account compromise.
A demand to ‘move money somewhere safe’ is especially dangerous. Real fraud departments do not protect funds by directing customers to an unknown account, cryptocurrency wallet, gift card, or cash courier.
Preserve the technical trail
Keep screenshots, voicemail, caller ID, callback numbers, URLs, email headers when applicable, transaction IDs, code notifications, and the exact words used to explain the requested action. Correct OCR errors before comparing identifiers.
When multiple numbers, domains, or scripts repeat, the shared infrastructure may be more informative than the branded identity displayed to the victim. Label the connection as a lead unless evidence supports more.
Recover in the right order
Contact the institution immediately through a trusted channel. Lock accounts or cards, change credentials from a known-clean device, revoke unfamiliar sessions, dispute unauthorized transactions, and preserve every case number.
Then secure the email and phone accounts used for recovery, review forwarding rules and multifactor settings, and report the impersonation to the FTC and the impersonated organization.
How this guide was built
Reporting and review note
This guide combines FTC and FCC guidance with CallSlayer’s sequence-based analysis of numbers, messages, links, requested actions, and identity clues. The attack sequence is illustrative and does not describe a private user case.
Sources
Trace the whole impersonation sequence
Analyze the number, exact message, callback, link, and requested action together instead of letting the brand name carry the case.