You receive a call on your phone.
The caller says they're from your bank and they're calling about a suspected fraud.

"Oh yeah," you think. Obvious scam, right?

The caller says "I'll send you an in-app notification to prove I'm calling from your bank."

Your phone buzzes. You tap the notification This is what you see.

Still think it is a scam?
1/3

The scammer is on the phone to you.
Their accomplice is on the phone to your bank, pretending to be you.
Your bank send you the notification.
You accept, and scammers proceed to drain your account.

Someone has just lost £18,000 because of this.
https://www.reddit.com/r/UKPersonalFinance/comments/1cih3kd/been_scammed_over_18000_through_my_chase_account/

2/3

It *is* a genuine notification. But it isn't confirming the bank is calling you.

Should the bank word that differently?

In a rush, would you read it thoroughly?

Most likely, in a panic about the fraud, you'd confirm it was a genuine notification (it is!) and accept it.

3/3

@Edent I think it’s just not possible for the average person (or maybe anyone) to evaluate these situations correctly. It’d be better for people to have a blanket rule *never* to trust any incoming call from a business under any circumstances. Hang up the phone, find the number of the business through some trusted channel, and call them back. Don’t try to suss out whether the call is legitimate.

It’s surprising to me that businesses that ought to know better are training people to do exactly the wrong thing. I got a text message from Citibank recently about suspected fraud, asking me to call a phone number they provided. I ignored that number and called the number I found in their app. After working my way through the phone tree, I eventually made my way to the fraud department, where they proceeded to ask me a bunch of questions about sensitive information. It turns out the text message was legitimate, and Citibank expected me to call them at a number that arrived at my phone unsolicited and hand over a bunch of sensitive information.

Citibank’s own fraud protection page warns you of this exact scenario: “Named for SMS (Short Message Service), the technology used for cell phone text messaging, SMiShing messages appear to be from a legitimate company and typically contain a link that takes you to a spoof website or asks you to call a phone number.”