Skip to content

Callback scams and fake bank calls: how to spot them

An email reports a debit and gives a number to cancel it, or your bank seems to call you itself. How to recognise both variants, what banks do not ask for on the phone and what to do if you have already talked to them.

  • approx. 11 min read
  • 13 sources
A smartphone showing an incoming call lies on a kitchen table at night, next to a face-down bank card and a closed laptop.

An email reports an expensive purchase, a text a suspicious debit. To cancel it, you are told to call a phone number. Or your phone rings, your bank’s number is on the display, and a friendly voice wants to protect your account. Both routes lead to the same goal: access to your account or your card. In mid-September 2026 the Swiss Federal Office for Cybersecurity (BACS) reported a sharp rise in such callback cases in Switzerland, and a few days earlier the Austrian consumer platform Watchlist Internet warned about a variant in Austria.

Variant 1: The message that makes you call

In a callback scam, the criminals write first and then make you call them. BACS describes the sequence like this (our translation): an email or text claims “that a paid contract has been concluded, a suspicious transaction has been detected or a payment has been triggered”. A short deadline adds pressure, after which the debit is said to go through. The message contains a phone number for the supposed cancellation.

On the phone, a supposed customer hotline answers. According to BACS, the criminals then try to obtain credit card details or personal information, get you to pass on confirmation codes or accept money requests in a payment app. Sometimes they ask you to install remote access software so the invoice can supposedly be cancelled. If you then log into online banking, they can watch and, depending on the setup, access the account themselves.

The senders change. BACS names fake messages in the name of UBS, TWINT, Migros and MediaMarkt. These companies are being impersonated and are victims themselves. A supposed Migros invoice claimed goods worth more than 765 Swiss francs, including a white wine for around 250 francs. Migros does not sell alcohol in its stores. The numbers stood out too: besides foreign numbers, increasingly Swiss landline numbers with the area codes 021, 022, 026 or 071, meant to look familiar.

In Germany, police crime prevention (ProPK) describes the same family under the name fake customer service: criminals pose as staff of large companies, aiming for remote access or malware. As a check, the police suggest asking (our translation): “Does the support number match the one on the official website?”

  • You do not recognise the charge. A purchase, subscription or debit you did not make, with a deadline of a few hours.
  • The fix is a phone call. Instead of a link, the message contains a phone number for cancelling. You can check the charge in your customer account or via the contact details on the official website.
  • On the phone it is about access. Card number, confirmation code, an approval in the app or a remote access program.

Variant 2: The call showing your bank’s number

In a fake bank call, the criminals call you, often with the real bank’s number on the display. The German Federal Network Agency explains that it is technically possible in several ways to replace the actual caller number with a forged one, even though this is illegal. Its conclusion (our translation): “Caller numbers can be forged and are not fully trustworthy.” The technique is called caller ID spoofing.

Since 1 December 2022, phone providers in Germany must suppress the display of German numbers on calls from foreign networks, with an exception for mobile numbers roaming abroad. According to the Federal Network Agency, the aim is that a German number can be relied on to come from its rightful holder. The display is still no proof. Watchlist Internet calls the Austrian case call spoofing.

The caller usually talks about suspicious transactions and offers help. The caller knows your name, sometimes more. Then you are asked to confirm a request in your banking app, read out a TAN or transfer money to a supposed safe account. What appears in the app for approval can be an order placed by the criminals.

A case decided by the Cologne Regional Court shows what this looks like (judgment of 20 Nov 2023, 22 O 43/23, summarised by the Federation of German Consumer Organisations): a caller showing the bank’s number told a customer that his account and card had been blocked as a precaution and asked him to approve a request in the pushTAN app to unblock them.The app showed the order “Registrierung Karte” (card registration). In fact, the customer confirmed that a digital version of his debit card was stored on someone else’s device. Between 23 and 25 September 2022, the criminals paid 14,040.90 euros with it.

Austria: first the ID Austria text, then the call

In Austria, the criminals combine both routes. On 10 September 2026 Watchlist Internet described a text in the name of FinanzOnline, the Austrian tax portal (our translation): “[BMF] Your FinanzOnline ID expires today. Without renewal, a tax return is no longer possible”. Anyone who taps the link and enters data hands it straight to criminals. The call follows later, using that data.

In Watchlist’s example, a caller claims to be from a Raiffeisen bank, reports an ongoing debit attempt and knows the customer’s access number. She is told not to hang up, to drive to the bank and transfer money there to a supposedly safe account.Watchlist counters (our translation): “Genuine bank staff can block your account directly in an emergency. You do not need to go to the bank for that.” And: “Just because someone knows your personal bank details does not automatically mean they are a bank employee.”

Phishing messages like this supply the data that makes a later call sound credible. The German consumer advice centre’s phishing radar, for example, lists an email on 2 October 2026 that wants to renew a bank’s photoTAN app supposedly expiring that same day.The consumer advice centre recommends checking such notices only in the official banking app or on the bank’s known website. How fake parcel and customs messages are built is covered in the article Parcel and customs texts.

What banks do not ask for on the phone

We put the advice of the police and the Federal Network Agency in Germany, Watchlist Internet in Austria and BACS in Switzerland side by side. On the key points they agree, even though each uses different words.

  • No access data on the phone. German police crime prevention (ProPK) writes (our translation): “Bank employees will never ask you to share access data, install software or make payments.” Watchlist names PIN, TAN, password and online banking access.
  • No remote access. BACS advises never to give unknown people access to your computer. The police say the same about remote maintenance programs.
  • No transfer for protection. An account at risk is blocked by the bank itself. A safe account you are asked to move money to belongs to the criminals.
  • No callback number from the message. BACS (our translation): “Never call back phone numbers given to you in emails or text messages that put you under pressure.”

If someone wants a transfer from you, you can first enter the IBAN in our IBAN check. It shows whether the account has already been reported to us in connection with fraud. No match does not clear the account, because new recipient accounts appear all the time.If the message contains a link, you can enter the domain in the shop check without opening the page. The check is built for online shops, but for a copied bank page it shows the domain’s age and entries on warning lists. More on the principle is in the glossary under phishing.

What to do while the phone is ringing

  1. Hang up.

    Even if the caller insists or says you must not end the call. Watchlist advises hanging up immediately if in doubt.

  2. Call your bank yourself.

    Use the number on your bank card, your statement or the official website. Do not use the callback button or any number from the email or text.

  3. Approve nothing.

    No TAN, no confirmation in the app, no code from a text, because any approval can be an order placed by the criminals. Read what you are asked to approve in the app and cancel if you did not start the order yourself.

  4. Install nothing.

    No remote access program, not even for a supposed cancellation. According to BACS, the criminals can use it to watch your online banking.

If you have already talked, approved or transferred

  1. Inform your bank immediately.

    Use the known number. In Germany you can also have cards and online banking blocked around the clock via the blocking hotline 116 116. In Austria, contact your bank; in Switzerland, BACS advises calling your card issuer straight away if you gave card details.

  2. Cut remote access.

    If you installed remote access software, disconnect the device from the internet and uninstall the program. BACS then recommends changing all passwords you use on that device.

  3. Secure evidence.

    Message, sender, call log with times, account statement. How to do this is under Securing evidence.

  4. File a police report.

    In Germany with the police or your state’s online police station, in Austria with the police. For Switzerland, BACS recommends a criminal complaint in case of financial loss and points to Suisse ePolice for finding a police station. The routes are under Reporting offices.

  5. Stay alert.

    Watchlist points out that the criminals may hold further data and could try again with a different scam.

Who is liable in Germany

Under Section 675j of the German Civil Code, a payment is only effective if you consented to it. Without that consent, the bank must refund the amount under Section 675u without delay, at the latest by the end of the business day after your report.Under Section 675v, it can charge you up to 50 euros for misused payment instruments, and the full loss in cases of gross negligence. Whether gross negligence applies depends on the individual case. In the Cologne case the court ruled it out: the average customer need not know that a different number can be displayed.That is a regional court decision, not a landmark ruling. This section is not legal advice. Whether your bank is liable depends on the individual case, and a consumer advice centre can assess it.

It is different if you made a transfer to a supposed safe account yourself. Then you consented, and the refund claim under Section 675u usually does not apply. Ask your bank immediately to recall the payment. What is possible after that is described on the page Money transferred.Report unknown debits as early as possible, under Section 676b no later than 13 months after the debit. Which other scams are currently circulating is collected in our monthly overview Current scams.

Frequently asked questions

My bank is calling and wants a TAN. Is that genuine?

No. According to Watchlist Internet, banks do not ask for your PIN, TAN, password or online banking access on the phone. German police crime prevention says the same about access data. Hang up and call your bank back on the number on your card or statement.

My bank’s number was on the display. Can the call still be fake?

Yes. According to the German Federal Network Agency, the displayed number can be forged; this is called caller ID spoofing. Since December 2022, calls from foreign networks may no longer display German numbers in Germany, but a displayed number is still no proof of who is calling.

I received an email about a debit with a hotline number. Should I call?

No. BACS advises never to call a number from an email or text that puts you under pressure. Check the debit in your online banking or customer account and use the contact details from the provider’s official website.

I transferred money to a safe account. Will I get it back?

Contact your bank immediately and ask for the payment to be recalled, then file a police report. If you made the transfer yourself, it usually counts as authorised, so the statutory refund claim for unauthorised payments mostly does not apply. The sooner the bank knows, the better the chance of stopping the money.

I allowed remote access on the phone. What now?

Disconnect the device from the internet and uninstall the program. Call your bank on the known number and have online banking and cards blocked if necessary. BACS also recommends changing all passwords you use on that device.

Unsure about a shop?

Enter the address. You get the verdict with a reason for every feature checked.

Check shop

Keep reading

Note

The articles serve to inform and are researched with AI support. Individual cases may differ. For a legal assessment, contact your consumer advice centre or a qualified lawyer.