Banking phishing: recognise the traps and act before it is too late
A fake adviser, an urgent text, a QR code or a copied website: banking phishing mainly exploits trust and haste. Learn to recognise the scenario and respond according to what you have already done.
Banking phishing is no longer always a badly written email promising an unlikely windfall. A modern attack can copy a bank's logo, tone and apparent phone number, involve a fake adviser on the phone and direct you to a convincing copy of the official app or website.
Technology is used to create credibility, but the real lever remains human. The fraudster manufactures an emergency, prevents the victim from thinking and then gets them to carry out the action themselves that will grant access to the account or authorise the payment.
Knowing how to recognise this scenario is more effective than memorising the appearance of a few fake messages. Logos change; the mechanics of manipulation remain remarkably stable.
Phishing, smishing, vishing and quishing
The word phishing describes an attempt to obtain information or prompt an action by impersonating a trusted identity.
- Traditional phishing arrives by email.
- Smishing uses a text message or a messaging service such as WhatsApp.
- Vishing takes place over the phone with a fake adviser, a fake anti-fraud service or sometimes a fake police officer.
- Quishing hides the link in a QR code placed in a message, letter or poster.
- Technical support fraud pressures you to install a remote access app.
These techniques can be combined. A text announces a suspicious transaction, a call follows a few minutes later and the fake adviser guides the victim to a phishing site. The succession of channels creates the impression of an official procedure.
The anatomy of a banking attack
1. A contact that seems credible
The message uses the name of a bank, a payment service, Card Stop, a public authority or a well-known retailer. The displayed number can be spoofed. A message that appears in the same thread as a genuine banking text is therefore not automatically authentic.
2. A story that justifies the urgency
The account is supposedly blocked, a new card needs to be activated, a refund is awaiting confirmation or an unusual transaction needs to be cancelled. The scenario is chosen to trigger fear of losing money or the desire to solve the problem immediately.
3. An action presented as protective
The fraudster asks you to click, scan a QR code, share a response generated by the card reader, approve a notification, install an app or transfer money to a supposed “secure account”.
The victim believes they are cancelling a fraud while they are actually authorising a login, adding a payee or confirming a payment.
4. Pressure that prevents verification
The fake adviser stays on the phone, asks you not to speak to anyone or claims that every second counts. This pressure is not incidental: it is used to prevent a call to the bank's real number.
Signs that should make you end the exchange
- A request for a PIN, password, card reader code or code received by text.
- A login link sent by email, text or messaging service.
- A request to return or hand over your bank card.
- An invitation to install a remote control tool.
- A transfer to a “safe account”, “protection account” or “technical account”.
- Approval of a transaction you have not prepared yourself.
- A threat of immediate blocking or a request to keep the call secret.
- A web address that adds a word, replaces a letter or places the bank's name before another domain.
- A caller who refuses to let you hang up and call the bank back.
A message with no spelling mistakes can be fraudulent. A correct logo, the HTTPS padlock and the display of the real phone number are not sufficient proof of the sender's identity either.
What a bank will not ask you to do
A bank will not ask you to reveal your PIN, your full password or your card reader's response codes by email, text or phone. Nor will it ask you to send your card by post following an unexpected message.
A genuine employee may contact you about a transaction, but you must always be able to end the exchange and call back through an official channel. Never consider the incoming number to be sufficient proof.
The safest rule is simple: only confirm a banking transaction if you initiated it yourself and the confirmation screen shows exactly the amount and payee you expect.
Eight habits that block most attempts
Open the app yourself
Do not log in through a link you have received. Close the message, open the installed banking app or enter the official address saved in your bookmarks yourself.
Hang up and call back
Use the number on the back of the card, in the app or on the official website you have opened yourself. Do not call back a number provided in the suspicious message.
Read the confirmation screen
Strong authentication does not protect you if you approve a fraudulent transaction yourself. Check the amount, the payee and the type of action before every confirmation.
Do not share any secrets
A one-time code, a card reader code, a password and a PIN are personal. A legitimate service does not need you to read them out.
Refuse remote access
Do not install software requested during an unexpected call. With remote access, the fraudster can see the screen, guide payments and hide certain actions.
Reduce the possible impact
Enable payment alerts, set appropriate transfer limits and use a unique password for the email account associated with your bank. Protect this email account with multi-factor authentication.
Check the real domain
In a web address, the decisive element is just before the extension such as .be, .com or .eu. A bank's name placed earlier in a long address may be nothing more than a deceptive subdomain.
Report without resharing
In Belgium, a suspicious message can be forwarded to suspect@safeonweb.be. Send the message or a screenshot of the text, then delete it. Avoid reposting an active link on social media.
You clicked: what should you do now?
The response depends on what actually happened. Acting quickly helps, but avoid actions that erase evidence.
You opened the link without entering anything
Close the page. Do not download anything or accept any notifications. If a file or app has been installed, disconnect the device from the network if necessary and have it checked with an up-to-date security tool or by a competent person.
Keep the message and website address for reporting.
You shared a password
From a trusted device, change that password immediately. If you reused it, change it on every other affected service. Enable multi-factor authentication and sign out unknown sessions.
Start with your main email account, because it is often used to reset other accounts.
You gave banking details or approved a transaction
Contact your bank immediately through its official channel. Ask for the affected access or transactions to be blocked and follow its instructions.
In Belgium, also contact Card Stop on 078 170 170, or +32 78 170 170 from abroad, when card details have been shared, a card is compromised or the situation requires it. Do not wait to see money disappear.
Money has been transferred
Notify the bank without delay: a quick response can sometimes help block or recall a transaction, with no guarantee of recovery. Keep statements, messages, numbers, screenshots, web addresses and the times of contacts.
File a complaint with the police. Do not pay any more money, even if someone promises to recover the funds for a fee. Victims are frequently targeted a second time by fake recovery services.
Institutions and businesses must also reduce the risk
Prevention is not solely the responsibility of customers. A financial institution or a business that handles payments must maintain consistent channels, explain precisely what it will never ask for and offer an easy-to-find way to report a problem.
Internally, sensitive transfers and changes to bank details should be verified through a second, known channel. Payment permissions must be limited, important approvals separated and staff regularly trained using realistic scenarios, including phone calls and QR codes.
Clear public communication after a fraud campaign also helps customers recognise the scenario without revealing information that would make new attacks easier.
The thirty-second test
Before any banking action prompted by a message, ask yourself five questions.
- Did I start this transaction myself?
- Does the message create urgency or ask for secrecy?
- Am I being asked to reveal a code or approve an action?
- Can I check in the app that I opened independently?
- Have I called the official number rather than the one in the message?
One worrying answer is enough to end the exchange.
Conclusion
Banking phishing works when a credible appearance meets a moment of haste. The best defence is not recognising every fake logo, but refusing to follow the imposed scenario.
Do not follow the link, do not share any code, never approve an unexpected transaction and call the bank back through an official channel. If information or money has already been sent, contact the bank and Card Stop immediately. Shame wastes time; a quick response offers greater protection.