Scam calls that already know your bank details

This isn't the usual robocall. The person on the line knows your name. They name your bank correctly. They read back the last four digits of your card, and they've mentioned the street you live on.

Then they tell you your account is under attack and they need you to act quickly.

Everything they've recited is available for purchase. It proves nothing. But it's designed to move you past the point where you'd normally ask questions, and it usually works, which is why this is worth recognizing before it happens rather than during.

If your problem is volume rather than targeting, why data brokers drive spam calls covers where the calls come from and how to reduce them. This is about the ones that are aimed.

The script

It varies at the edges and holds its shape in the middle.

The opening establishes credibility. Your name, your bank, sometimes a recent transaction or the last four of a card. This is the whole reason the call succeeds, and it's the part that's bought rather than known.

The threat is urgent and financial. A fraudulent transfer is in progress. Someone in another state is using your card. The account will be frozen. There's no time to call back.

The ask is one of four things, and the request itself is the tell:

  • Read back a verification code that just arrived by text.
  • Move your money to a "safe" or "secure" account to protect it.
  • Install an app so they can "walk you through" the fix.
  • Confirm your full card number, PIN, or online banking password.

No bank does any of these. Not one. A bank that suspects fraud freezes the transaction on their end. They never need your code, never ask you to move money, and never ask you to install remote-access software.

The move-your-money version is the most expensive, because a transfer you make yourself is an authorized payment. That's the entire design. It's why the script never tries to break into your account.

The one rule

Hang up and call the number on the back of your card.

Not a number they give you. Not the number that called. The number printed on your card or on a statement.

Say it out loud now, because the point of the call is to make you feel that hanging up is the risky choice. It isn't. If the fraud is real, it will still be there in two minutes when you reach the bank yourself. If it isn't real, you've lost nothing.

One detail worth knowing: use a different phone if you can, or wait a full minute before dialing. Call-hold scams, where the scammer stays on the line and plays a fake dial tone, are less common than they were but haven't disappeared.

If you already gave them something

A verification code. Change the account password immediately, call your bank on the number on your card, and check for new payees, changed contact details, and pending transfers.

Card details or a PIN. Call your issuer, report it as fraud, and ask for a replacement card.

Access to your device. Disconnect from the internet, uninstall the remote-access app, run a security scan, and change passwords from a different device. Assume anything you signed into while they were watching is exposed.

Money you transferred. Contact your bank immediately and report it to the FTC and the FBI's IC3. Recovery depends heavily on the method and on speed, so make the call before anything else.

Then file a police report. Documentation matters for anything that follows.

How they knew

The credibility comes from three sources, and none of them require breaking into anything.

Data brokers and people-search sites publish your full name, current and past addresses, phone numbers, age, and relatives, compiled from public records and commercial data and sold to anyone. This is the bulk of what a caller recites.

Breach data supplies the rest. Which bank you use, the last four of a card, an old password. Breached records are sold and resold, and get matched against broker profiles to build something current out of something stale.

Caller ID spoofing completes it. The number displayed can be set to anything, including your bank's real published number, so a matching caller ID is not evidence.

The combination is what makes it work. Any one of these alone sounds like a guess. Together they sound like your bank's records.

Delist finds the broker and people-search listings, files the removals, and keeps re-checking them, because brokers routinely repost a profile after it comes down. It can't reach breached data, and it doesn't stop spoofing. What it reduces is how much accurate, current detail a caller can open with. Run a free scan to see what's published about you.

Frequently asked questions

They knew the last four digits of my card. Doesn't that prove it's my bank?

No. Card details appear in breach data and are sold alongside broker profiles. Partial card numbers also appear on receipts and statements. It's a credibility prop, not proof.

The caller ID showed my bank's real number. How?

Caller ID is trivially spoofed to display any number, including a bank's published one. Treat caller ID as decoration.

Would my bank ever ask me to move money to a safe account?

Never. There is no such thing as a safe account a bank moves you to. That request identifies the call as fraud on its own, with no other evidence needed.

Can I get money back if I transferred it myself?

Sometimes, and it depends heavily on the method and how fast you report. Bank transfers and peer-to-peer payments are the hardest, since they're treated as authorized. Call your bank immediately and file with the FTC and IC3.

How do I stop these calls?

You can reduce them. Removing your number from data-broker and people-search listings cuts the supply of the name-and-number pairings these campaigns run on, and carrier call-screening filters more. The Do Not Call registry has little effect on criminals, who aren't following it.

They called my elderly parent. What should I tell them?

Give them the single rule rather than a list of warning signs: never act on an inbound call about money, always hang up and call the number on the card. One rule is easier to hold under pressure than a checklist.

Find out what data brokers know about you

Run a free scan to see which sites are exposing your personal information — name, phone, address, email, and more.

Start your free scan