The Federal Communications Commission says one sentence should end almost any call that claims to be from a bank: banks will never phone or text a customer and ask them to move money to protect it. The agency issued that warning after tracking a wave of impersonation calls built to spoof real financial institutions, and it says the category costs victims more than any other kind of impersonation fraud it tracks. The pitch is almost always the same — an urgent claim that an account has already been compromised and that funds need to move somewhere “safe” immediately, often to a new account, a wire transfer or a cryptocurrency kiosk the caller walks the victim through step by step.
A warning built on a real robocall case
The advisory did not appear out of nowhere. Months earlier, the agency opened an investigation after a financial institution complained that its own customers were receiving fraudulent calls that appeared to come from the bank’s fraud-prevention and customer-service lines. That inquiry led to a formal enforcement action in April 2026 against Voxbeam Telecommunications, an Orlando-based voice service provider the FCC found “apparently liable” for accepting suspicious call traffic and passing it onto American phone networks.
According to the FCC’s own account of the case, Voxbeam carried tens of thousands of calls between March 31 and April 3, 2025, on behalf of a Czech provider called Axfone that had no listing in the commission’s robocall mitigation registry. Many of the calls spoofed the fraud-prevention and customer-service numbers of Bank of America, Chase Bank and other financial institutions. The commission proposed a $4.5 million fine against Voxbeam over the traffic, though the penalty is not final and the company can still respond before any vote to make it permanent.
The scam works in part because caller ID is trivial to fake. A robocall platform can display almost any name or number a sender chooses, including the exact fraud-alert line printed on the back of a real debit card, which is why the FCC maintains a Robocall Mitigation Database meant to keep unvetted foreign carriers from dumping spoofed traffic onto U.S. networks in bulk. The Voxbeam case is what happens when that check fails: tens of thousands of calls carrying a real bank’s number reached real customers before regulators caught up with the traffic, and the complaint that triggered the investigation came from the bank itself rather than from a single victim.
Chairman Brendan Carr calls gateway providers the on-ramp
FCC Chairman Brendan Carr framed the Voxbeam case as a warning to every company that carries this kind of traffic, not only to the scammers who place the calls. “Companies like Voxbeam must ensure they are not accepting traffic from sketchy operators,” Carr said. “These gateway providers are the on-ramps to American phone networks, and with that business model comes significant responsibility.”
Carr added that the volume of calls Voxbeam allowed through shows what happens when that responsibility is ignored. “As we saw in this case, failure to follow the FCC’s robocall mitigation rules can result in tens of thousands of scam calls reaching U.S. customers,” he said. “The FCC is committed to protecting consumers from robocall scams like these.”
The costliest impersonation scam on the FCC’s list
Separate from the Voxbeam enforcement, the commission’s broader advisory pointed to just how much money this category of scam moves. Bank impersonation scams account for the highest losses of any impersonation-scam category the FCC tracks, with victims often losing everything held in the targeted account. The calls typically pressure a consumer to act immediately, warning that an account has already been compromised and that money needs to move to a “safe” location before it can be stolen — the same urgency that ran through the Voxbeam robocalls months earlier.
“Banks will never call or text and ask you to move your money to protect it,” the FCC said in the advisory.
The verification habit the FCC recommends
The commission’s advice does not depend on spotting a fake voice or a spoofed number, both of which have gotten harder to catch by ear alone. Anyone who gets a call claiming to be from a bank or credit card company should hang up and call back using the number printed on an account statement or the back of a debit card, never a number offered during the call itself. The same rule applies to a text message carrying a login link: contact the bank independently rather than tapping through. The FCC also advises never sharing account numbers, Social Security numbers, passwords or one-time PINs over the phone, no matter how official the caller sounds or how urgent the request seems.
The American Bankers Association has built a public-awareness campaign, BanksNeverAskThat, around the same core message, encouraging consumers to memorize a short list of requests no legitimate bank employee will ever make over the phone. The Voxbeam case suggests why that campaign has staying power: even with a $4.5 million fine on the table for one carrier, the underlying script barely changes from one wave of scam calls to the next.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Herbal supplements are landing Americans in the hospital with liver damage, doctors warn
- Long-term use of common heartburn pills is linked to kidney and dementia risk
- 9 pickup trucks with a reputation for falling apart after 100,000 miles
- Consumer Reports names the 2026 models it expects to break down the most