How to Report Bank Scam Text Messages: What to Do, Who to Contact, and How to Protect Yourself

Written by: Abigail Ivy
Published on:

What a bank scam text looks like

Bank scam texts are phishing messages that pretend to come from a legitimate financial institution, credit card issuer, or payment service.

They often claim there is suspicious activity, a locked account, or an urgent security issue, then push you to tap a link, call a fake number, or share one-time passcodes.

These messages are designed to create urgency and bypass careful review.

The more you understand their patterns, the faster you can identify and report them before the scam spreads to others.

How to report bank scam text

If you receive a suspicious message, report it through the channel that best reaches both your bank and the relevant fraud authorities.

The key is to preserve the message, avoid interacting with it, and submit it to the proper reporting systems as quickly as possible.

1. Report it to your bank or card issuer

Contact the bank or financial institution that the text claims to represent.

Use the phone number on the back of your card, the official website, or the mobile app rather than any number included in the message.

  • Ask for the fraud or security department.
  • Tell them you received a phishing or spoofed SMS message.
  • Share the sender number, exact text, and any linked website.
  • Request instructions if the message referenced your real account or recent activity.

Some banks maintain dedicated reporting inboxes or in-app fraud reporting tools.

Even if the message is fake, banks use these reports to block abusive numbers and warn other customers.

2. Forward the text to your mobile carrier’s spam reporting service

In the United States, many carriers support forwarding spam texts to 7726, which spells SPAM on a phone keypad.

This helps carriers identify fraudulent sender IDs and block repeated campaigns.

  • Forward the suspicious message exactly as received.
  • Follow any carrier prompts for additional details.
  • Block the number after you report it.

If your carrier uses a different reporting system, check its official support page for the current SMS spam process.

3. File a report with the FTC

The Federal Trade Commission accepts reports of phishing and impersonation scams at ReportFraud.ftc.gov.

FTC reports help identify trends, build enforcement cases, and improve public warnings.

Include the phone number, message content, linked URL, and the name of the institution the scammer was impersonating.

If you clicked a link or entered information, note that as well.

4. Report it to the FBI if money or identity theft is involved

If the message led to a loss, account takeover, or theft of personal information, file a complaint with the FBI’s Internet Crime Complaint Center, known as IC3.

This is especially important if you sent money, shared banking credentials, or provided a Social Security number.

Use IC3 to document:

  • The date and time of the message
  • The phone number or short code used
  • The website or app involved
  • Any transfers, login attempts, or unauthorized transactions

What evidence should you save?

Before deleting anything, capture enough detail to support a report.

Evidence makes it easier for investigators, banks, and carriers to recognize the scam pattern.

  • Screenshots of the full text thread
  • The sender’s number or alphanumeric ID
  • The exact wording of the message
  • Any link preview or URL
  • Voicemail or call logs if the scam moved to a phone call
  • Transaction records if you entered information or sent money

If possible, keep the original message in your phone’s messaging app.

Avoid replying, even to say “stop,” because that can confirm your number is active.

What should you do if you clicked the link?

Clicking a scam link does not always mean your accounts are compromised, but it does raise the risk of credential theft, malware, or fraudulent login prompts.

Act quickly and treat the event as a possible security incident.

  • Close the browser tab immediately.
  • Do not enter passwords, card numbers, or one-time codes.
  • Change your bank password if you typed it into the fake site.
  • Contact the bank and ask them to monitor for unusual activity.
  • Review recent transactions and card charges.

If you downloaded an attachment or installed an app, remove it and run a trusted mobile security scan if available.

On Android and iPhone, review app permissions and delete anything suspicious.

What if you shared personal or banking information?

If you provided sensitive information, escalate immediately.

A bank scam text can be the first step in account takeover, card-not-present fraud, or identity theft.

  • Call your bank using a verified number.
  • Freeze or replace affected cards if needed.
  • Change passwords on banking, email, and payment accounts.
  • Enable multifactor authentication with an authenticator app or hardware key where supported.
  • Place a fraud alert or credit freeze with the major credit bureaus if identity theft is suspected.

Monitor credit reports and account notifications for new loans, address changes, or login alerts you do not recognize.

How to recognize common bank scam tactics

Fraudsters often use the same psychological patterns across different campaigns.

Recognizing them helps you spot scams before they become a problem.

Urgency and fear

Messages may warn that your account will be frozen, your card was declined, or a large transfer was blocked.

The goal is to make you act before verifying the claim.

Impersonation of real brands

Scammers copy bank names, logos, and official-sounding language.

They may spoof sender IDs to look like a genuine short code or customer service thread.

Fake verification links

The link often leads to a lookalike website that steals login details.

Some pages request a debit card number, CVV, PIN, or one-time passcode.

Requests for secrecy

Some texts instruct you not to tell anyone or to respond only through the provided link.

Real banks do not ask customers to keep security steps secret from support staff.

How to reduce the chance of future scams

Reporting is only one part of the response.

Preventive steps make it harder for scammers to target you again.

  • Turn on bank alerts for withdrawals, transfers, and login attempts.
  • Use strong, unique passwords for every financial account.
  • Avoid using text messages as the primary recovery method when a more secure option is available.
  • Keep your phone’s operating system and apps updated.
  • Do not trust caller ID or sender names without independent verification.
  • Use the bank’s official app or website instead of tapping text links.

It also helps to review whether your email address or phone number has been exposed in a data breach.

Breached contact data is often reused in phishing campaigns and SMS scams.

Are there differences between scam texts and legitimate bank alerts?

Yes.

Legitimate alerts usually avoid asking you to verify identity through a text link or disclose credentials.

They may notify you of activity, but they direct you to open the official app or call a verified number.

When in doubt, compare the message with the bank’s normal communication style.

If the text contains spelling errors, pressure tactics, mismatched branding, or a URL that does not match the institution’s official domain, treat it as suspicious.

When should you delete the message?

Delete the text after you have saved screenshots and submitted your reports.

If you are unsure whether you need to preserve it longer, keep it until the bank confirms there is no account impact or until you finish any fraud claim.

For repeated spam, block the number after reporting.

On many devices, you can also filter unknown senders or silence messages from unrecognized contacts to reduce future interruptions.

Where to report bank scam text if you’re outside the United States?

Reporting options vary by country, but the process is usually similar: notify your bank, forward the message to your mobile provider’s spam service, and submit a report to the national fraud or cybercrime agency.

Common examples include Action Fraud in the United Kingdom, the Canadian Anti-Fraud Centre in Canada, and Scamwatch in Australia.

Check your country’s official consumer protection or cybercrime website for the current reporting portal and emergency guidance.

Key details to include in any report

If you want your report to be useful, include enough detail for investigators to link the incident to a larger campaign.

  • Your phone number and device type
  • The date and time you received the text
  • The sender number or name shown
  • The bank or brand being impersonated
  • The exact message content
  • The URL, phone number, or app name in the scam
  • Whether you clicked, replied, or shared information

Clear, consistent reporting helps banks and regulators identify active fraud operations faster and improves the odds that abusive numbers, domains, and accounts will be shut down.