A wave of fraud built almost entirely on phone calls, texts and a single spoken passcode has drained hundreds of millions of dollars from bank customers, according to federal investigators. The scheme does not rely on hacking or malware. Instead, criminals pose as a bank’s own fraud department and coax victims into reading back the very security codes meant to keep their accounts locked. Once those codes change hands, the money often follows within minutes.
The scale of the problem is laid out in an alert from the FBI’s Internet Crime Complaint Center, which tracks online and telephone fraud reported by the public. Investigators say the tactic has proven unusually effective because it turns a bank’s security tools against the very people they are supposed to protect.
How the account takeover scheme works
The con typically begins with a call, text or email that appears to come from a familiar financial institution. Posing as customer support or a fraud specialist, the caller warns that suspicious activity has been detected on the target’s account and offers to help secure it. In reality, the criminal is already attempting to log in to the victim’s online banking, which triggers the bank to send a one-time passcode by text. The scammer then simply asks the customer to confirm the code that just arrived.
That single number is the key. The passcode, often described as multi-factor authentication or a one-time code, is designed to prove that whoever is signing in also controls the account holder’s phone. Handing it to a stranger effectively hands over the account. According to the FBI advisory, once inside, criminals reset passwords to lock out the legitimate owner, then move funds to accounts they control, frequently converting the balance into cryptocurrency to make recovery far more difficult.
Why the losses reached $262 million
The FBI has tied the surge to more than 5,100 complaints filed since the start of 2025, with reported losses exceeding $262 million. The bureau’s public warning frames the trend as account takeover fraud carried out through impersonation of financial-institution support staff, a category that has grown quickly as criminals refine their scripts.
Part of what makes the scheme so costly is its speed and its psychology. Callers manufacture urgency, insisting that money is actively being stolen and that only immediate action can save it. Under that pressure, people who would normally never share a password read out a passcode they assume is helping their bank. Because the transfers often route into crypto wallets rather than traditional accounts, the funds can be gone before a victim realizes the caller was never from the bank at all.
The role of caller ID spoofing
Adding to the deception, fraudsters frequently manipulate caller ID so that the incoming call or text appears to originate from the bank’s real phone number. That spoofing lends instant credibility to the pitch and discourages the natural instinct to hang up and call back. Consumer-protection agencies have repeatedly cautioned that a legitimate-looking number on a screen is not proof of who is actually calling, and that spoofing technology is cheap and widely available.
Investigators note that the scripts are often polished, referencing real recent transactions or account details that criminals may have gathered from earlier data breaches or phishing. The more specific the caller sounds, the more plausible the emergency feels, and the more likely a target is to comply before pausing to verify.
How consumers can protect their accounts
The single most important safeguard, according to fraud investigators, is a simple rule: a bank will never ask a customer to read back a one-time passcode, and no legitimate representative needs that code to secure an account. Any request for it is a red flag, regardless of how convincing the caller seems. Federal guidance urges people who receive such a call to hang up and dial the number printed on the back of their debit or credit card rather than trusting a number supplied during the call.
Officials also recommend treating unexpected security-code texts as a warning sign in their own right. A passcode arriving without the customer trying to log in can indicate that someone else is attempting to access the account at that moment. The Federal Trade Commission, which maintains extensive guidance on recognizing impersonation and phishing scams, advises consumers to slow down, resist pressure to act instantly, and independently confirm any claim of fraud before sharing information.
Because stolen funds are often converted to cryptocurrency and moved quickly, recovery is difficult once a transfer goes through, which is why prevention carries so much weight. The FBI encourages anyone who believes they have been targeted or defrauded to report the incident to the Internet Crime Complaint Center, both to seek help and to feed the data that shapes future warnings.
A scam that exploits trust, not technology
What sets this fraud apart is that it defeats strong security measures without breaking any of them. Two-factor authentication works as designed; the weak point is the human being persuaded to override it. As banks and platforms roll out ever more sophisticated verification, criminals have adapted by focusing on the one part of the system that can be talked into cooperating. For account holders, the practical defense comes down to a reflex: never share a code, never trust an unsolicited caller claiming to be the bank, and always verify through a number they look up themselves.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview