Skip to content
FIN-CSIRT
RS
Report an incident

FIN-CSIRT / Practical lesson

Check who is contacting you on behalf of your bank

Separate a suspicious call or message from verified communication with your bank.

Mobile and online banking usersAbout 4 minutes of reading + 3 questions
Start with the example Has something already gone wrong?

What you will learn

  • Find the bank’s contact details independently of a received message.
  • Recognise requests for security details that should not be shared with callers.
  • Respond if information has been disclosed or a payment approved.

Practice example

The screen shows your bank’s name. Does that identify the caller?

An unexpected telephone call

Unexpected call

We are calling from your bank’s security team. To stop a suspicious payment, read us the one-time code you just received. Stay on the line; there is no time for another call.
Fictional scenario for practice.
Show the example explanation
Caller ID is not proof of identity
A displayed name or number can be spoofed. Check the request by contacting the bank yourself.
A code requested for “protection”
Do not disclose a one-time code to someone who contacts you. Read what the bank’s message actually authorises.
Pressure to stay on the line
Urgency does not remove the need to check. End the conversation and use an official channel.

Find the bank’s channel independently

Banks may contact their customers. Your task is not to label every message fraudulent in advance, but to check an unusual request before acting.

Open the official app you already use or enter the bank’s known address yourself. For a call, obtain the number from the app, official website or back of your card. Do not use a number or link from the message you are trying to verify.

A displayed caller name or number can be spoofed. End a suspicious call and make fresh contact with the bank yourself. Our phone and text scam guide explains how to verify a caller’s identity.

Protect access and authorisation details

Do not disclose your PIN, banking password or one-time code to someone who contacts you. Do not send card details in response to an unexpected message. Read what a code or confirmation request is for before approving anything in the app.

Security codes should remain known only to the owner. A request to disclose a code for “verification”, “receiving money” or “protecting the account” is not a reason to share it with a caller. Read more in the guide to protecting card information.

Check the address and monitor your account

HTTPS encrypts the connection but does not by itself establish that a site belongs to your bank. Check the exact domain; fraudulent pages can also use HTTPS. Instead of opening an unexpected link, use your known app or a previously verified address.

If you cannot verify a public Wi-Fi network, use mobile data for banking or wait for a trusted connection. Enable transaction notifications if your bank offers them and review account activity. Notifications help you notice a problem earlier, but do not replace checking a request.

If you have disclosed information or approved a payment

  1. End communication with the suspicious person and contact your bank immediately through a verified channel.
  2. Explain whether you disclosed card details, a password or a code, or approved a payment. Do not include the actual passwords or codes in a report.
  3. Follow the bank’s guidance on blocking a card, protecting access and reporting a transaction you do not recognise.
  4. Preserve the message, displayed number, call time and disputed transaction details. Do not wait to collect every piece of evidence before first contacting the bank.

Reporting to FIN-CSIRT does not replace contacting the bank to protect your account. The outcome of a disputed transaction cannot be promised in advance.

Check your knowledge · 3

Your turn to choose the next step.

Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.

Questions and explanations are also available without JavaScript.

A caller displays your bank’s number and asks for a one-time code. What do you do?

Why does this matter? A familiar number can make identity seem already verified. A one-time code may approve access or a payment, so reading it to the caller can authorise an action you did not intend.

  1. Read out the code because the number is familiar.

    A displayed number can be spoofed and does not establish identity. You hand an authorisation detail to someone whose identity you inferred only from the phone display.

  2. End the call and contact the bank myself through an official channel.Correct answer

    Independent contact allows verification without disclosing the code to the caller. You remove the caller’s control over the check and reach the bank through a route you chose yourself.

  3. Ask for the same request by text, then read out the code.

    A message from the same unverified source does not solve the identity problem. Switching from a call to a text adds no independent confirmation if both requests come from the same unverified person.

A message claiming to be from your bank includes an HTTPS link. Does that confirm the page is official?

Why does this matter? An encrypted connection protects the transmission from being openly readable, but does not decide whom you are sending information to. A fake page with the bank’s logo and HTTPS can still collect your details.

  1. No; I open the known app or website and check the request.Correct answer

    HTTPS protects the connection but does not establish that the domain belongs to the bank. A known app or address lets you check the request without entering information at the destination supplied in the message.

  2. Yes; HTTPS means the bank has approved the site.

    HTTPS is not a bank’s endorsement of a website owner. Relying on HTTPS skips the domain check and can result in sending secrets to the wrong recipient.

  3. Yes; if the page uses the same logo.

    A logo can be copied and does not verify the domain. A copied bank image can appear on any website; its presence does not verify that site’s operator.

You have already read a code to someone claiming to be from the bank. What is the most useful next step?

Why does this matter? After sharing a code, you may not know whether it has already been used. Checking with the real bank therefore takes priority over waiting for visible loss or an explanation from the suspicious caller.

  1. Wait for the next statement to check for losses.

    Delay may leave more time for misuse. A statement is a later record of events, while protective action may be needed during ongoing misuse.

  2. Call the number the caller dictated to me.

    A number supplied by the suspicious caller has not been independently verified. You may reach the same person again and receive another reassurance instead of actual help from the bank.

  3. Contact the bank immediately through a known channel and explain what I disclosed.Correct answer

    The bank needs to assess exposed services, transactions and appropriate protection promptly. Explaining what you shared and when helps the bank assess which access or payment needs checking.

No registration. Your answers are not sent; the result is just for you.

Remember

Verify the contact independently and keep your PIN, password and one-time code private.

Recognise a phishing message

References

Sources and further reading

For users in Serbia, the primary source is the National Bank of Serbia guidance on safe payment-card, electronic-banking and mobile-banking use. Caller-ID spoofing is additionally explained by the UK Financial Conduct Authority; UK reporting routes and consumer rights have not been applied to Serbia.

Content last reviewed