About this article

By the Banktimer Editorial Team · Published

Banktimer is an independent U.S. consumer-finance publication. Our editors draw on primary and official sources first, such as the CFPB, FDIC, Federal Reserve, and FTC, along with statutes, regulations, and providers’ own agreements and fee schedules. Then we add worked examples and decision tools. Our goal is the most useful, best-supported explanation the sources available to us at the time of writing allow.

This article is general information, not legal, tax, investment, insurance, or financial advice, and reading it does not create a professional relationship with Banktimer. Rates, fees, limits, and rules change, and they vary by state, provider, and contract, so confirm current terms with your bank, lender, insurer, or the agency named in the article before you act. Examples are illustrative unless labeled otherwise. Banktimer is not a bank, lender, insurer, or financial advisor, and we are not responsible for decisions or losses that result from relying on this content. For advice about your own situation, talk to a licensed professional.

The useful question is not only how this works, but which rule changes the reader’s outcome.

Phishing Text From Bank: How It Happens and the Warning Signs to Know can look straightforward until fees, timing, eligibility, and fine print start interacting. This Banktimer guide explains bank phishing text in practical terms and shows which details deserve verification before you act. You will see realistic examples, common mistakes, questions worth asking, and the trade-offs that matter for different financial situations. Where rates, policies, insurance terms, laws, or eligibility can change, the article points readers to current official sources instead of treating a temporary answer as permanent. Read the full guide before you apply, switch, transfer, borrow, insure, dispute, or pay based on the headline alone. Bank Phishing Text…

Reported losses to text-message scams hit $470 million in 2024, five times the 2020 total. A fake fraud alert impersonating a bank is one of the FTC’s top five reported text-scam categories, and it’s specifically designed to look like the real thing.

Only about 11% of text-scam reports to the FTC in 2024 involved an actual dollar loss. Most people who report a suspicious bank text never send money or tap the link — which means the warning signs in this guide work when you catch them early.

Whether you get your money back depends on a legal distinction buried in federal banking rules. Regulation E strongly protects “unauthorized” transfers, but a payment you were tricked into sending yourself is often treated as “authorized” — a gap that voluntary bank and network policies, not federal law, currently fill.

Speed changes your recovery odds more than almost anything else. Wire-fraud recovery data shows a large majority of victims get most or all of their money back when they act within 24 hours, with odds falling to the low single digits after that window closes.

A text message doesn’t need a live scammer to work at scale. One convincing template can be sent to thousands of phone numbers at once, which is why bank phishing texts are cheaper to run and harder to trace back to a single person than a phone call.

Forwarding a suspicious text to 7726 (SPAM) helps your carrier block similar messages network-wide. It’s a free, one-step report that takes seconds and works alongside — not instead of — reporting the same text to your bank and the FTC.

Key Numbers to Know

Figure Value Why it matters
Total reported losses to text-message scams (2024) $470 million About 5 times the reported 2020 total, per the FTC’s most recent text-scam data spotlight
Share of text-scam reports involving an actual money loss About 11% Most reported text scams are caught before any money changes hands
Bank impersonator losses reported to the FTC (2025) Approximately $1 billion Up from $866 million in 2024
Total imposter scam losses reported to the FTC (2025) $3.5 billion Nearly 20% higher than 2024; imposter scams were the most-reported fraud category of the year
Total fraud losses reported to the FTC (2025) Approximately $16 billion Up about 25% from 2024, a record high
Regulation E liability cap if reported within 2 business days $50 Applies to transfers found to be “unauthorized” under federal law
Wire-fraud recovery rate when reported within 24 hours Around 73% recover most or all funds Recovery odds reportedly fall to the low single digits after the first day
FCC carrier text-blocking rule in effect since March 2023 Requires wireless carriers to block texts from numbers unlikely to be legitimate senders

How a Bank Phishing Text Actually Works

A bank phishing text — sometimes called “smishing,” for SMS phishing — is built around the same trade as a scam phone call: a plausible, urgent-sounding message in exchange for your money or your account credentials. What makes the text version distinct is scale and format, not the underlying goal.

The Fake Fraud Alert Opening

The most common version opens by imitating the exact kind of message your real bank actually sends: “Your account has been locked due to suspicious activity,” or “A $000.00 charge was flagged on your card — reply YES to confirm or NO to dispute.” This format works precisely because real banks do send legitimate fraud alerts by text, so the fake version doesn’t have to invent a new pattern — it only has to copy an existing, trusted one closely enough to pass a quick glance.

The Link vs. the Reply-With-Code Variant

One version includes a link to a look-alike login page designed to capture your online banking username and password the moment you type them in. A second, more targeted version skips the link entirely and asks you to reply with a one-time passcode that arrives moments later — a code that is very often the actual second factor protecting your real account, not a harmless confirmation number. A third, quieter version asks for nothing in the text itself and instead provides a phone number to call, moving the interaction into a live call once you’ve already been primed to believe there’s a real problem.

Spoofed Short Codes and Sender ID Look-Alikes

Some bank phishing texts arrive from a standard ten-digit number that has no obvious connection to any bank; others exploit the fact that many phones group messages from a similar-looking sender name into the same thread as a bank’s real alerts, creating a visual impression of continuity that has nothing to do with who actually sent the message. Neither the sender’s number nor how a message is grouped on your screen is proof of who sent it — both can be spoofed or coincidental.

QR Codes Embedded in Texts

A newer variant embeds a QR code in the text image itself rather than a tappable link, betting that a QR code feels less immediately suspicious than a raw URL because it doesn’t display the destination address before you scan it. Scanning it leads to the same kind of look-alike login page as the link-based version — the delivery mechanism changed, but the goal didn’t.

The Psychology Behind Why These Texts Work

Manufactured Urgency

Every version of this scam depends on creating a reason to act before you’ve had time to verify anything independently — a locked account, a large unauthorized charge, or a short reply window (“respond within 15 minutes to avoid a hold”). None of these deadlines are real; they exist specifically to short-circuit the instinct to close the message and call your bank back on a number you already trust.

Borrowed Authority and Familiarity

A text that uses your bank’s real name, a plausible-looking short code, and formatting that echoes a genuine prior alert borrows credibility it hasn’t earned. Scammers often have just enough real information — your name, the fact that you bank with a specific institution, sometimes the last four digits of a card number sourced from an unrelated data breach — to make the message feel personally targeted rather than mass-sent, even when it was sent to thousands of numbers at once.

The One-Tap Design Advantage

A phone call requires a live scammer to sound convincing for the full length of the conversation. A text only has to be convincing for the few seconds it takes you to tap a link or hit reply — after that, a look-alike website or an automated reply-collection system can do the rest of the work without a person on the other end at all. This is part of why text-based bank impersonation scales more cheaply than voice-based versions of the same scam.

Bank Phishing Text

Why a Text Is Harder to Verify in the Moment Than a Phone Call

A phone call gives you tone of voice, hesitation, and the ability to ask a follow-up question and gauge the response — imperfect signals, but signals nonetheless. A text gives you none of that: no voice to sound rehearsed, no live back-and-forth, just a static message designed to be read once and acted on immediately. That absence of interactive friction is exactly why the core defense for a text-based scam has to happen before you respond at all, rather than during a conversation, since there often isn’t one.

Verification: The One Habit That Defeats Most of These Texts

The single most reliable check costs nothing and takes under a minute: don’t tap the link, don’t reply, and don’t call any number included in the text. Instead, open your bank’s official app directly, or type your bank’s web address into a browser yourself, or call the number printed on the back of your card. If there’s a genuine problem, it will show up there — and if the text was fake, this step ends the interaction before it can go any further. This works regardless of how convincing the message looks, because it removes the scammer from the verification path entirely rather than trying to spot every possible tell in the message itself.

Payment Irreversibility: Why the Method a Scammer Requests Matters

Almost everything about whether a bank phishing text victim gets money back comes down to a legal distinction most people never learn until they need it: whether a transfer counts as “unauthorized” or “authorized” under the Electronic Fund Transfer Act and its implementing rule, Regulation E.

Unauthorized Transfers Get Strong, Tiered Protection

If a scammer used a phished password or one-time passcode to access your account and move money without your direct participation, that’s generally treated as an unauthorized transfer. Regulation E caps your liability at $50 if you report within two business days of discovering the loss, $500 if you report later but within 60 days of your statement being sent, and potentially unlimited liability only if you miss that 60-day window entirely. Federal guidance is explicit that being deceived into sharing a password or passcode doesn’t forfeit these protections — you were defrauded into handing over the keys, not into deciding to send money yourself.

Self-Sent Payments Fall Into a Murkier Category

A different scenario arises when the text convinces you to personally log in and send a payment yourself — through Zelle, a bank transfer, or a wire — believing it’s necessary to protect your account. Because you were the one who typed in the recipient and hit send, banks have generally treated this as an “authorized” payment sitting outside Regulation E’s mandatory reimbursement requirement, even though you were unquestionably deceived into doing it. Any reimbursement in this scenario currently depends on your specific bank’s or payment network’s voluntary policy, not a guaranteed legal right — treat any claim otherwise with real skepticism.

The Payment Method Chosen Is Rarely an Accident

A scammer’s instructions about how to send money aren’t incidental. Wire transfers and peer-to-peer apps like Zelle move quickly and are difficult to reverse once funds are withdrawn. Gift cards and cryptocurrency push irreversibility further still — once a code is read aloud or crypto is confirmed, there is often no institution left to call for a recall. Credit and debit cards sit at the opposite end, carrying stronger built-in dispute rights under the Fair Credit Billing Act and Regulation E respectively. A text instructing you toward a wire, a gift card, or cryptocurrency rather than a card payment is worth treating as a warning sign in its own right. Bank Phishing Text

Payment method Typical reversibility First call if scammed
Credit card Strong — chargeback rights under the Fair Credit Billing Act Your card issuer’s disputes department
Debit card Moderate to strong — Regulation E unauthorized-transaction protections Your bank’s fraud or disputes department
Bank wire transfer Weak — a recall is possible but not guaranteed, and odds fall sharply after 24 hours Your bank’s wire or fraud department, immediately
Zelle or similar P2P app Weak on its own — funds are often withdrawn within minutes Your bank, to ask about an imposter-scam claim
Gift cards or cryptocurrency Very weak — often unrecoverable once sent The issuer or exchange, and your bank, as soon as possible

Account Lockdown: What to Do the Moment You Suspect Your Credentials Were Phished

If you tapped a link and entered your username and password, or replied with a one-time passcode, treat the account as compromised immediately rather than waiting to see if anything looks wrong. Call your bank using a number you already trust — not one from the text — and ask specifically for the account to be locked or frozen, your online banking credentials reset, and a review of recent transactions and any newly added payees, since a scammer with fresh access often adds a new payee first to make a follow-up transfer easier. If the same password is reused anywhere else, change it there too; credential phishing rarely stays confined to a single account when the underlying password was shared across services.

Evidence Preservation: What to Save Before You Delete Anything

Resist the urge to immediately delete the message once you realize it’s a scam — it’s the evidence that supports both your bank’s investigation and any report you file afterward. Take a screenshot of the full text, including the sender’s number or short code and the exact timestamp. If you tapped a link, note the web address shown in your browser before closing it, since it often reveals a look-alike domain on close inspection. If you replied or called a number in the text, write down what was said and any name or reference number given. Keep this record in one place — a note, an email to yourself, whatever’s easiest — since you’ll likely need to repeat these details to your bank, the FTC, and possibly your carrier.

Dispute and Reporting Paths: Bank, FTC, IC3, and Your Carrier

Your bank’s fraud department is the first call in every version of this scenario, since only they can freeze an account, attempt a wire recall, or open an imposter-scam claim with a payment network. Beyond your bank, four additional channels each serve a different purpose, and using more than one isn’t redundant.

Forwarding the suspicious text to 7726 (SPAM) — a free, industry-standard short code supported by the major U.S. wireless carriers — reports the message directly to your carrier’s spam-filtering system, which can help block similar messages from reaching other customers on the same network. ReportFraud.ftc.gov is the federal government’s general fraud-reporting portal and feeds directly into the aggregated data the FTC uses to track scam trends like the ones cited throughout this guide. IC3.gov, run by the FBI, is built specifically for scams with an electronic component and is worth filing alongside, not instead of, an FTC report. If the text included a link to a fake banking website, reporting that specific web address to your bank’s fraud team can help get it flagged or taken down faster, since your bank has more leverage over its own look-alike domains than you do individually.

Recovery Timelines: What Realistically Happens After You Report

Reporting quickly changes outcomes more than any other single factor in this guide. An unauthorized transfer reported within two business days caps your liability at $50 under Regulation E; waiting longer, but still within 60 days of your statement, raises that cap to $500. A wire transfer has the best odds of a successful recall within the first 24 hours, after which recovery odds drop sharply as funds are withdrawn or moved onward. A Zelle payment identified as a qualifying imposter scam may be eligible for the network’s voluntary reimbursement process, sometimes called a clawback, in place since June 30, 2023 — but this depends on your specific bank’s participation and its own claims process, not a fixed legal timeline. Reports filed with 7726, the FTC, and IC3 don’t typically produce an individual dollar recovery on their own, but they feed pattern-detection systems that can lead to blocked numbers, frozen recipient accounts, and larger enforcement actions well after your specific case is filed.

How Carriers and Regulators Are Responding

The response to bank phishing texts isn’t limited to consumer-facing warnings. Since March 2023, an FCC rule has required wireless carriers to block text messages originating from numbers that are unlikely to be legitimate senders — including unused numbers, unallocated numbers, and numbers a subscriber has specifically designated as never sending texts — and to establish a point of contact so consumers can report suspicious senders. This is a text-specific counterpart to the STIR/SHAKEN call-authentication framework used for voice calls, though texts and calls are handled through separate technical systems. The FCC has continued examining additional measures, including extending Do-Not-Call-style protections to text messaging and closing loopholes that let a single consent authorize messages from multiple unrelated senders. None of this eliminates bank phishing texts entirely — carriers block enormous volumes of spam and scam texts, but new numbers and sending patterns continue to slip through — which is why the verification habit described earlier in this guide remains the more reliable individual-level defense.

A Realistic Timeline Comparison

Step Typical benchmark What it means for you
Reporting an unauthorized transfer to your bank Within 2 business days for the strongest protection Regulation E liability caps at $50; rises to $500 after 2 days, potentially unlimited after 60
Requesting a wire transfer recall Within 24 hours for the best odds Recovery rates fall from a clear majority to the low single digits after the first day
Filing a Zelle imposter-scam claim As soon as the transfer is identified as fraudulent Coverage depends on your bank’s participation and its own qualifying criteria
Forwarding the text to 7726 Immediately, before or after deleting Helps your carrier block similar messages network-wide; doesn’t recover funds directly
Filing with the FTC and IC3 Same day if possible Supports pattern detection and enforcement, not individual recovery

A Real-World Example: Two Texts, Two Outcomes

A retiree receives a text stating her debit card was used for a $612 purchase in another state and to reply STOP to block it or call an included number to dispute it. She doesn’t recognize the charge and, feeling the urgency, calls the number, where a “fraud specialist” asks her to confirm her full card number and a one-time code just texted to her “to cancel the transaction.” She provides both. The code was, in fact, the passcode protecting her real online banking login, and the scammer used it to add a new payee and transfer funds out within the hour. Because she was defrauded into sharing genuine account credentials rather than personally authorizing the transfer herself, her bank treated the resulting transaction as unauthorized under Regulation E, and her liability was capped well below the amount taken once she filed a documented dispute — though the process took several weeks and required her to reset all of her banking credentials.

A small-business owner receives a nearly identical fake fraud alert but, instead of calling the number in the text, opens his bank’s app directly, as he’s trained himself to do with any unexpected account message. There’s no unusual charge and no lock on his account. He forwards the original text to 7726, reports it to his bank’s fraud team so they’re aware a similar message may be circulating to other customers, and deletes it. The entire verification process takes under two minutes and costs him nothing. Bank Phishing Text

Common Mistakes People Make With Bank Phishing Texts

A frequent mistake is calling the phone number included in the text rather than one independently found on a card or statement, which simply connects the victim to the scammer under a different format. Another is assuming a text can’t be dangerous unless it includes a link, when a reply-with-code request can hand over account access just as effectively. A third is deleting the message immediately out of embarrassment or relief once the scam is recognized, losing the sender details and timestamp that would have supported a bank dispute or an FTC report. A fourth is assuming a disputed or reported transaction is automatically reimbursed, when a self-authorized payment made under deception often falls outside Regulation E’s mandatory protection and depends on voluntary bank or network policy instead. A fifth is reporting only to the bank and skipping 7726, the FTC, and IC3, missing a chance to contribute to the pattern data that gets scam numbers blocked more broadly.

Red Flags Worth Slowing Down For

A Request to Reply With a Code, Not Just Click a Link

Any text asking you to reply with a numeric code that arrived separately is very likely asking for the second factor protecting your real account — treat it exactly like handing over your password.

Pressure to Act Within Minutes

A specific, short reply window is a manufactured constraint, not a real banking policy — legitimate fraud holds don’t expire in fifteen minutes.

A Link That Doesn’t Match Your Bank’s Actual Web Address

Checking the actual destination of a link — not just the display text — before tapping it catches the large majority of look-alike banking sites, since the mismatch is often visible on close inspection.

Being Told to Move Money to a “Safe” or “Protected” Account

No legitimate bank fraud process requires you to personally transfer your own money to a new account to protect it, whether the instruction arrives by text, call, or email.

A QR Code Replacing a Normal Link

A QR code hides the destination address until after you’ve scanned it, which is precisely why some scammers have started using them in place of a visible link.

Questions to Ask Before You Tap, Reply, or Call Back

Before you tap, reply, or call back

  • ☐ Am I opening my bank’s official app or typing its web address myself, rather than tapping anything in this text?
  • ☐ Is this message asking me to reply with a code that arrived separately, which could be the passcode protecting my real account?
  • ☐ Does the linked web address actually match my bank’s real domain when I check it closely?
  • ☐ Am I being pressured to respond within an unusually short window?
  • ☐ If I’ve already tapped a link or replied with information, have I called my bank on a trusted number to lock the account?
  • ☐ Have I saved a screenshot of the message before deleting it, in case I need it for a dispute or report?
  • ☐ Have I forwarded the text to 7726 and reported it to my bank, the FTC, or IC3?

Alternatives and Prevention Habits Worth Building

Turn On Your Bank’s Real Transaction and Login Alerts

A genuine, bank-controlled alert for transfers over a threshold you set, or for any new login, gives you an independent signal that doesn’t depend on trusting an inbound text at all. Bank Phishing Text

Save Your Bank’s Real Number Before You Need It

Adding your bank’s fraud-department number to your phone from your card or a statement, in advance, makes calling back on a trusted number the automatic instinct rather than an extra step to think of under pressure.

Register Your Number’s “Never Send Texts” Status If Applicable

For a landline or a number that should never receive texts at all, checking with your carrier about designating it as such can help it qualify for the FCC’s carrier-blocking protections.

Use Your Bank’s App Instead of Text Links as a Default Habit

Making a habit of checking your account through the app rather than any link, regardless of who appears to have sent it, removes the single step every version of this scam depends on.

Report Near-Misses, Not Just Losses

Forwarding a suspicious text to 7726 and filing a report even when no money was lost still contributes to the aggregated data used to block numbers and identify active campaigns.

Who This Guide Suits

This guide is most useful to anyone who has received a text claiming to be from their bank and isn’t sure whether to trust it, as well as anyone who has already tapped a link or replied with information and needs a clear next set of steps. It’s equally relevant to someone helping an older family member recognize this pattern, or a small-business owner deciding whether an unexpected text about a business account is worth a second look before acting.

Bank Phishing Text

Frequently Asked Questions

How common are bank phishing texts, really?

Reported losses to text-message scams reached $470 million in 2024, about five times the 2020 total, and a fake fraud alert impersonating a bank is one of the FTC’s top five reported text-scam categories.

Will my bank definitely reimburse me if I fall for a phishing text?

Not automatically. Reimbursement is close to guaranteed for a genuinely unauthorized transfer under Regulation E, including cases where you were tricked into sharing credentials, but a payment you personally sent after being deceived typically falls outside that mandatory protection and depends on your bank’s voluntary policy.

Is it dangerous to reply to a scam text even without clicking a link?

Yes, if the reply includes a one-time passcode — that code is often the actual second factor protecting your real account, and sharing it can let a scammer complete a login or transaction without ever needing your password.

What’s the fastest way to report a scam text?

Forward it to 7726 (SPAM), a free service supported by major U.S. carriers, then report it to your bank and, if you lost money or shared credentials, to ReportFraud.ftc.gov and IC3.gov.

How can I tell if a link in a text actually goes to my bank’s website?

Check the full web address shown before tapping — a look-alike domain is often one character off or uses an unfamiliar extension, which is usually visible on close inspection. When in doubt, don’t tap it at all; open your bank’s app or type the address in yourself instead.

What should I do if I already tapped a link and entered my password?

Call your bank immediately using a number you already trust, ask for the account to be locked and your credentials reset, and change that password anywhere else you’ve reused it.

Are QR codes in text messages safe?

Not inherently — a QR code hides its destination until after you scan it, which is why some scammers have started using them instead of a visible link to avoid an obvious mismatch being spotted in advance.

Does forwarding a scam text to 7726 stop it from being sent to other people?

It contributes to carrier-level spam filtering that can help block similar messages network-wide, though it doesn’t guarantee an individual number is blocked immediately.

How fast do I need to report a fraudulent transfer to limit my liability?

Within two business days of discovering it for the strongest protection under Regulation E, which caps liability at $50; waiting longer but still within 60 days raises the cap to $500.

Can a bank phishing text scam happen even if I don’t click anything?

The message itself can’t take money on its own, but a reply containing a code or personal information can be enough — the risk starts with any response, not only with tapping a link.

Is a phishing text the same thing as a phishing email?

They work the same way conceptually — a fake message designed to extract money or credentials — but a text is often harder to verify quickly since it lacks the sender-address details and formatting inconsistencies that can give away a fake email.

Should I report a scam text if I didn’t lose any money or share any information?

Yes — reports of attempted scams, even ones you avoided, support the pattern data carriers and regulators use to block numbers and identify active campaigns before they reach more people.

How to Verify These Numbers Yourself

The FTC’s text-scam data spotlight, published through the Federal Trade Commission at ftc.gov, is the primary source for the $470 million 2024 text-scam loss figure and the finding that only about 11% of text-scam reports involved an actual loss. The FTC’s imposter-scam figures for 2025, including the $1 billion bank-impersonator figure and the $3.5 billion total, are published through the same Consumer Sentinel data reporting at consumer.ftc.gov and ftc.gov. The FCC’s March 2023 order on illegal robotexts, including the carrier-blocking and point-of-contact requirements, is published directly at fcc.gov. Regulation E’s liability tiers are published by the Consumer Financial Protection Bureau at consumerfinance.gov. Because reported figures are updated annually and carrier or bank policies can change without advance notice, verify the current version of any specific number or policy against these primary sources before relying on it for an active situation.

Key Terminology

Term What it means
Smishing Phishing conducted through SMS or text messages rather than email or phone calls
Unauthorized transfer A transfer made without the account holder’s involvement, or through credentials obtained by fraud — subject to Regulation E’s tiered liability caps
Authorized (fraudulently-induced) transfer A transfer the account holder personally initiated after being deceived — generally outside Regulation E’s mandatory reimbursement requirement
Regulation E The Consumer Financial Protection Bureau’s rule implementing the Electronic Fund Transfer Act, governing consumer liability for electronic transfers
Spoofing Falsifying the sender information displayed to a recipient to disguise a message’s real origin
Clawback A process, such as Zelle’s imposter-scam policy, that attempts to recover funds directly from a recipient’s account after fraud is identified
7726 (SPAM) A free short code supported by major U.S. wireless carriers for reporting spam and scam text messages
One-time passcode (OTP) A single-use numeric code, usually sent by text, used as a second authentication factor to confirm a login or transaction

Banktimer Bottom Line

A bank phishing text succeeds by copying the exact format of a message your real bank might actually send, then asking you to act before you’ve had a chance to verify it independently. The single most reliable defense is a habit rather than a checklist: open your bank’s app or type its web address in yourself, and never tap a link, reply with a code, or call a number contained in the text itself. What happens if you’ve already responded depends heavily on a legal distinction between “unauthorized” and “authorized” transfers most people never learn until they need it, and on how quickly you act afterward — reporting to your bank, forwarding the text to 7726, and filing with the FTC and IC3 all matter, even when full recovery isn’t guaranteed. Bank Phishing Text

Sources

Methodology

The text-scam loss figures and category breakdown in this guide reflect the FTC’s most recent text-scam data spotlight, published in April 2025 covering 2024 data, the most current federal figures of their kind available as of this guide’s publication. The 2025 imposter-scam and bank-impersonator figures reflect FTC data published in 2026. The FCC’s robotext-blocking rule details reflect the Commission’s March 2023 order, still in effect and periodically supplemented by additional rulemaking. Regulation E’s liability tiers and the fraudulently-induced-transfer interpretation are drawn from the Consumer Financial Protection Bureau’s published rule text, a stable legal provision not subject to annual change. Zelle’s imposter-scam reimbursement policy reflects network and industry reporting rather than a government mandate, and specific bank participation and eligibility can vary; readers should confirm current policy directly with their own bank. This guide is educational and does not constitute legal advice. Bank Phishing Text

Your next step

The next time you get a text claiming to be from your bank, don’t tap anything in it — open your bank’s official app or type its web address in yourself, and check directly whether the claimed problem is real, saving a screenshot of the original text first in case you need it for a report. Bank Phishing Text