8 min read

Bank Impersonation Scams: How They Work and How to Prevent Them

Bank Impersonation Scams: How They Work and How to Prevent Them
What Are Bank Impersonation Scams? [Full Guide]
11:27

What are Bank Impersonation Scams?

A bank impersonation scam is a type of financial institution impersonation scam in which fraudsters pose as a legitimate bank to trick customers into taking actions that benefit the attacker. This scam is also widely known as a safe account scam (where victims are told to move funds to a fraudster-controlled 'safe account') or, more narrowly, bank spoofing when it relies on caller-ID or domain spoofing specifically.

Impersonation fraud, the "safe account scam" where criminals pose as a bank, the police, or another trusted organisation to move funds, is actually one of the few APP fraud categories moving in the right direction.

UK Finance's Annual Fraud Report 2026 shows losses from impersonation and related "malicious redirection" scams fell 12% in 2025, continuing a multi-year decline from over half of all UK APP fraud losses in 2020 to under a quarter today. That's a genuine sign that layered controls, payee verification, callback checks, and in-app warnings are working. It isn't a sign the threat has gone away: fraudsters are simply having to work harder, which is exactly why the tactics in this article (AI voice cloning, reverse-proxy MFA relay, rapid mule routing) keep evolving.

Key Takeaways

  • Bank impersonation scams are a form of financial institution impersonation in which fraudsters pose as legitimate banks to trick customers into authorising payments, sharing sensitive information, or compromising their accounts.
  • UK impersonation ("safe account") scam losses fell 12% in 2025 even as overall APP fraud rose 19%, evidence that targeted controls work, not that the threat has disappeared.
  • Modern bank impersonation scams combine bank spoofing, phishing, fake websites, and multi-channel social engineering to create convincing and highly coordinated attacks.
  • Most bank impersonation scams follow a structured attack lifecycle, from target selection and data capture to impersonation, payment authorisation, and money mule routing.
  • Banks can reduce the risk of bank impersonation scams by combining customer awareness, trusted verification channels, targeted payment controls, and layered fraud prevention strategies.

 

How a Typical Bank Impersonation Scam Works: 4 Stages

Although bank impersonation scams vary depending on the fraudster's pretext, most follow the same four-stage attack lifecycle.

impersonation-bank-scam-12

1. Target selection & content preparation

Fraud groups assemble target lists from breached datasets, lead brokers, and recycling of older phishing logs, then enrich with phone numbers, email addresses, and bank brands. In parallel, they build the pretext and infrastructure: a short SMS script, a look-alike website (often with valid TLS and cloned UI), and local VoIP numbers that match the victim’s region.

Pretexts aren’t only “bank” pages. Parcel delivery, retailer refunds, investment portals, and tax notices are common on-ramps designed to harvest credentials, one-time codes, device info, and personal details that will stand up in later “verification” steps.

 

2. Initial contact & data capture

The initial contact is usually an SMS or email containing a link to a lure site. Texts often use sender-ID spoofing so messages appear in the existing thread titled with the bank’s name on the handset. The fake website requests logins, DOB/postcode, card fragments, or prompts for codes under the guise of “cancelling a suspicious payment.”

 

3. Impersonation call

A live caller phones from a number that appears to be the bank (cheap to do with VoIP caller-ID spoofing, especially when calls originate outside jurisdictions enforcing strict attestation). Increasingly, fraudsters also use AI voice cloning to make these calls sound even more convincing. Using data already collected, the caller “verifies” the account, then steers the victim through actions the attacker needs: reading back a code, approving a login/push, enrolling a “secure device,” installing a “security tool,” or moving funds to a “safe account.”

 

4. Transaction & money movement

With control of the session (and the narrative), attackers usually finish by executing authorised push payments. They get victims to add a new payee, raise limits, and send funds. Payments are split to stay below review thresholds and routed through money mule networks, then cashed out, forwarded across banks, or converted via crypto on-ramps.

 

What’s in it for the scammer? 

  Category Score (/10) Key Insights
1 Initial Investment Scammer Setup Cost

mediumModerate · 5/10

Bank-impersonation runs on readily available parts: leaked data, cheap domains with passable branding, SMS routes, and VoIP numbers. Kits for fake banking pages and scripted lures are widely sold and reused, so setup is mostly integration and rehearsal, not R&D. Costs rise when you add highly accurate voice cloning, better hosting hygiene, or mule onboarding. Still, it’s a mid-cost campaign to run, not something requiring high investment. 

2 Exposure Risk Likelihood of Getting Caught

mediumModerate · 6/10

Phone and SMS leave traces like caller records, message routes, takedown trails, and contact-center recordings. Money mules add another point of failure if they’re identified. That said, VoIP churn, cross-border routing, and quick cash-out keep personal exposure manageable.

3 Success Rate Likelihood of Scamming a Victim medium
Moderate · 6
/10

The scam hinges on timing and persuasion: catching customers during real activity, sounding credible, and driving a few critical steps (new payee, limit change, high-value transfer). Education, name-check warnings, and in-app approvals blunt many attempts, yet multi-stage pretexts still convert often enough, especially off-hours, with first-time payees, or when a live caller manages the script. 

4 Return on Investment ROI high
Moderate to High · 9/10

When a bank impersonation scam lands, payout is strong. Authorized push payments clear quickly, and reversals are hard. Infrastructure is reusable across brands and regions, and harvested data fuels further fraud long after the first hit. With instant rails, funds move before scrutiny catches up.

 

protecting-agianst-scam-01

Protecting Against Bank Impersonation Scams

1. Provide Specific, Timely Customer Education

Rather than educating customers with notices on the bank’s website, move the awareness closer to the point of highest risk. Include short plain-language messages in the mobile app during risky actions (adding a payee, raising limits, like “We will never ask for your OTP or to move funds to a ‘safe account’.”

2. Add targeted friction to the flows scammers use most

Even when a scam is months in the making, the payoff hinges on a few actions that must succeed in a short window. Brief holds and extra checks at those moments make the attack less reliable and more visible. This can include things like short waiting periods for the first payment to a new payee (show a countdown and status), lower daily caps for first-time payees and recently changed limits, name-mismatch warnings on payees that require an explicit “proceed anyway, or second approver or scheduled callback for large or overseas transfers.

3. Verify sensitive actions in a channel that impostors don’t control

Caller ID, texts, and emails are easy to spoof. If the impostor controls the conversation there, they can walk a customer through any “security step.” Pulling the decision back into a trusted channel breaks that control. In-app messaging and bank-initiated callbacks (requested inside the app) for certain actions can work here.

4. Connect Fraud Signals Across Channels

These scams unfold across multiple stages. A text today, a fake website tomorrow, a call next week, followed by a new payee and a transfer. Each step can look routine in isolation, but together they signify a scam in motion. Acoru’s fraud detection solution identifies risk using pre-fraud signals across all channels, before a fraudulent transaction takes place.

 

what-does-finantial-institutions

What does this mean for Financial Institutions?

Financial institutions should treat bank impersonation scams as a multi-stage attack and move detection upstream to the pre-fraud stages.

This is also one of the clearest cases where regulation and detection point the same direction. The UK's Confirmation of Payee scheme and the EU's Verification of Payee mandate (in force for euro-area sending institutions since October 2025) both exist specifically to catch the moment a customer is directed to a name-mismatched "safe account." A payee-name mismatch is a strong signal in isolation; correlated with the SMS, spoofed call, and OTP-relay activity that typically precede it, it's close to a confirmed attack in progress.

That means watching for pre-fraud signals: indicators that something nefarious is underway. These signals can include look-alike domains tied to the bank's brand, proxy fingerprints, OTP relay behaviour, customer credential exposure, confirmation-of-payee mismatches, and sudden contact-detail changes.

None of these signals alone proves fraud. Together, they reveal an attack as it develops. Financial institutions ultimately need pre-fraud signal intelligence to be able to take action early enough to interrupt bank impersonation scams before a transaction is initiated.

Also, checks like caller ID, SMS OTP, and knowledge-based prompts no longer signal safety when fraudsters can easily control the conversation and the context. The anchor of trust may need to shift away from customers’ phone networks and toward bank-controlled channels.

 

 

Bank Impersonation Scams Examples

Bank impersonation scams affect financial institutions and customers worldwide. The following real-world examples from across Europe illustrate how these attacks are carried out and the financial impact they can have.

impersonation-scam-05
Spain

In March 2025, elEconomista reported on the arrest of a 24-year-old who defrauded victims out of more than €200,000 by posing as a bank security employee. The report describes how the fraudster used prior info obtained about the victims to make the later stages of the scam easier to fall for. These later stages involved phone calls and text messages posing as a bank employee and requesting the victims take certain actions that transferred money to accounts under his control. 

impersonation-scam-04
UK

A South London man received a jail sentence of five years after defrauding bank customers of £988,719 (over €1 million) through bank impersonation. In a classic case of the multi-channel nature of these scams, the perpetrator first called victims, pretending to be investigating fraudulent activity. Then, victims would get directed to a fake website, where they’d unknowingly disclose their important account details. The fraudster then used those details to transfer funds to mule accounts under his control. 

impersonation-scam-03
France

In 2025, a French court ordered BNP Paribas to reimburse a customer who had previously fallen victim to a bank impersonation scam. This particular scam exploited the trust relationship between the customer and his bank advisor at BNP Paribas. The fraudster was able to spoof his telephone number to appear as the customer’s usual bank advisor. The fake advisor directed the customer to transfer funds totalling €54,000.

impersonation-scam-02
Germany

In July 2025, the Bavarian Police in Germany issued a press release that described bank impersonation scams conning customers out of €100,000. The tactics rested on fraudulent phone calls posing as bank employees. In an interesting exploitation of real time payments using push-based approval, the fraudsters told victims they were hacked and that to confirm the return of funds to their accounts, they needed to approve push notifications on their banking apps. In fact, these push notifications ended up approving real-time transfers to the fraudsters’ accounts. 

impersonation-scam-01
Netherlands

In a demonstration of the scale of these scams, Dutch police swooped in to arrest 8 people suspected of running a bank impersonation operation in September 2025. The eight scammers posed as bank helpdesk employees. Typically, they’d spoof their phone numbers to appear as the customers’ banks, inform customers of an account hack, and advise transfer to supposedly safe accounts. These accounts were in fact under the control of fraudsters. Up to 150 people lost a total of €1.6 million from this gang’s activities. 

what-means-01

What does this mean going forward?

Generative AI will continue to strengthen fraudsters' capabilities by enabling natural-language scripts in any dialect, cloned voices that mimic trusted bank employees, and low-cost automation that coordinates SMS, phone calls, and fraudulent websites at scale.

The operating model needs to shift from “prove the loss after” to “see the setup before.” That means continuous account classification across the lifecycle (onboarding, device changes, contact-detail edits, beneficiary creation, outbound transfers). Also, those companies that best prevent these scams will need a pre-fraud signal intelligence fabric that links what’s happening across channels. This needs to be done through omnichannel orchestration that connects the dots across all channels. 

 

See how Acoru helps financial institutions detect bank impersonation scams before fraudulent payments take place. Request a demo.

 

Frequently Asked Questions

What is a bank impersonation scam?

A bank impersonation scam is a type of authorised fraud in which criminals pose as a legitimate bank, by phone, text, email, or fake website, to trick customers into sharing credentials, approving a fraudulent transaction, or moving money to an account the fraudster controls.

What is a "safe account scam"?

A safe account scam is the most common form of bank impersonation: the fraudster tells the victim their account has been compromised and that funds must be urgently moved to a "safe account" for protection. The account is entirely controlled by the fraudster.

How do fraudsters spoof a bank's phone number or text messages?

Using caller-ID spoofing and SMS sender-ID spoofing, criminals can make a call or text appear to come from a legitimate bank number, sometimes appearing in the same message thread as genuine bank alerts, making the contact look authentic even to cautious customers.

Is bank impersonation fraud getting worse?

It's mixed. UK Finance's 2026 data shows losses from impersonation-style scams actually fell 12% in 2025, as banks have layered in stronger controls. But the underlying tactics, AI voice cloning, reverse-proxy MFA relay, rapid mule routing, continue to evolve, so the decline reflects better defences, not a disappearing threat.

Will my bank ever ask me to move money to a "safe account"?

No. Legitimate banks will never ask a customer to transfer funds to a different account, whether described as "safe," "protected," or otherwise, to resolve a security concern.

How can financial institutions detect bank impersonation scams before money is lost?

By correlating signals across channels rather than relying on any single check, look-alike domains, OTP-relay behaviour, sudden contact-detail changes, and payee-name mismatches individually look routine, but together they reveal an attack in progress well before the final transaction.

Double Your Coins Today: Don’t Fall for a Crypto Scam

1 min read

Double Your Coins Today: Don’t Fall for a Crypto Scam

What are Crypto Scams? Crypto scams are a type of investment fraud where criminals use the mechanics and mystique of cryptocurrency to deceive...

Read More

1 min read

"Dad, I'm Using This New Number Now": What To Do? [A Complete Guide]

How Emotional Manipulation Drives Mobile Scams "Hi Dad” scams, also known as “Hi Mum” scams, are a type of authorized fraud (scam). These scams...

Read More
3 Best Practices for Detecting APP Fraud in Banking

1 min read

3 Best Practices for Detecting APP Fraud in Banking

Authorized push payment (APP) fraud is a type of scam in which criminals manipulate victims over days or even weeks before convincing them to...

Read More