Bank OTP Scams in the UK: How Fake "Fraud Teams" Steal Your Money
A caller claims to be your bank's fraud team. A one-time code lands on your phone. They ask you to read it back — and your money is gone in minutes. No genuine UK bank will ever ask for your one-time passcode.
What a Bank OTP Scam Looks Like
Scammers impersonate banks in three main ways. All of them end in the same demand: the one-time code on your phone.
The Typical Attack Sequence
- 1. The hook. A call, text or pop-up claims suspicious activity, a blocked card or an unauthorised payment on your account.
- 2. The "verification". They send a genuine-looking one-time code to your phone — sometimes a real code your bank generated, sometimes a fake.
- 3. The ask. "Read the code back to me so we can secure your account."
- 4. The theft. The code approves a payment, adds a payee or logs them into your online banking. Money moves within seconds.
- 5. The cover-up. They may tell you not to contact the bank "because the fraud team is compromised", keeping you quiet while transfers clear.
Why a Real Bank Will Never Ask for Your One-Time Code
Your one-time passcode exists for one reason: to prove you are approving an action. A genuine bank employee can see whether a payment is pending — they never need you to read a code back to them. Treat any request for a code, PIN, password or "safe account" transfer as a scam signal, whatever the caller claims.
Warning Signs in Calls, Texts and Emails
- ⛔ Anyone asks you to read back a code or confirm a PIN/password.
- ⛔ Urgency: "your account is being emptied right now".
- ⛔ An instruction to move money to a "safe account" — safe accounts do not exist.
- ⛔ Requests to install remote-access software or download an "app" from a link they send.
- ⛔ Texts with links claiming your card is blocked, a delivery fee is owed, or a payment failed.
- ⛔ They already know your name, address or partial card number — scammers buy this data from breaches and use it to sound official.
- ⛔ "Don't tell anyone at the bank" or "don't hang up".
What to Do If You Shared a Code or Approved a Payment
- 1. Call your bank now — 159, their official app, or the number on the back of your card. Say: "I think I've been a victim of fraud." Ask them to freeze accounts and recall any pending payment.
- 2. Change your online banking password and check for new payees or devices you don't recognise.
- 3. Report it to Action Fraud at actionfraud.police.uk or 0300 123 2040, and get a crime reference number.
- 4. Keep the evidence — screenshots of texts, caller numbers, times and what was said.
- 5. Watch for follow-up scams — criminals often call "victims" again pretending to be the police or a recovery service. See how to avoid recovery scams.
Under the UK's authorised push payment (APP) fraud rules, banks must reimburse eligible victims up to £85,000. If the bank rejects your claim, you can escalate to the Financial Ombudsman.
How to Contact Your Bank Safely
- ✅ Call 159 — the UK's national fraud hotline that connects you straight to your bank's fraud team.
- ✅ Use the number on the back of your card or the number in your bank's official app or website.
- ✅ Message your bank through its official in-app chat.
- ❌ Never call a number left in a voicemail, text or email, or given by someone who called you.
Common Bank-Impersonation Wording to Recognise
Each of these is a scam. Real banks already know if a card has been used abroad — they don't need you to verify it by moving money or reading codes.
Frequently Asked Questions
Would a real bank ever ask for my one-time passcode?
I gave a scammer my code and money has gone. What do I do?
What is 159?
The caller said they were my bank's fraud team. How do I check safely?
I approved a payment in my banking app by mistake. Can I get the money back?
Why do scammers want my one-time code?
If You Think You've Been Scammed
Do these five things now. Speed protects your money and your evidence.
- 1Stop and secure. Close suspicious pages or apps. If you shared bank details, contact your bank immediately on the official number in their app or on your card.
- 2Change passwords. Update any account where you reused the same password. Enable two-factor authentication (2FA) where available.
- 3Record what happened. Save messages, emails, screenshots and transaction details. Note dates, times and any numbers used.
- 4Report it. In the UK: report to Action Fraud and tell your bank. Forward scam texts to 7726 and phishing emails to [email protected].
- 5Watch for follow-up scams. Be suspicious of anyone claiming they can "recover" your money for a fee — that is a second scam. Only use official channels.