Protecting UK Families & Businesses Knowledge is power — we make sure you have it
Menu ☰
CyberAware UK CyberAwareUK Stay Aware · Stay Secure
🧰 All Scam Tools 🚨 Get Help 📢 Report a Scam
✕ Exit 𝕏 💼 🎧
Menu
Home 📰 Press & Media 🔍 Search
Live Threat Intel
Been Scammed? Start Here
Child Safety Hub
Lock It Down
Scams & Money
Reviews & Tests
Know Your Stuff
Go Deeper
Careers
About Us
© 2026 CyberAware UK
📱🚨

Bank OTP Scams in the UK: How Fake "Fraud Teams" Steal Your Money

A caller claims to be your bank's fraud team. A one-time code lands on your phone. They ask you to read it back — and your money is gone in minutes. No genuine UK bank will ever ask for your one-time passcode.

I've shared a code — help now 🔎 Check a suspicious message
If someone is asking for a code sent to your phone, or telling you to move money to a "safe account", end the call now. Contact your bank on 159, through its official app, or on the number on the back of your card — not on any number the caller gives you.

What a Bank OTP Scam Looks Like

Scammers impersonate banks in three main ways. All of them end in the same demand: the one-time code on your phone.

📞
Fake fraud-team calls
"We've spotted fraud on your account — we're sending a code to verify it's you."
💬
Fake bank texts
"Your card has been blocked. Confirm your details:" with a link to a cloned banking page that harvests your login and codes.
💻
Remote-access pressure
"Install this app so we can fix it" — AnyDesk, TeamViewer or similar, giving the scammer control of your screen.

The Typical Attack Sequence

  1. 1. The hook. A call, text or pop-up claims suspicious activity, a blocked card or an unauthorised payment on your account.
  2. 2. The "verification". They send a genuine-looking one-time code to your phone — sometimes a real code your bank generated, sometimes a fake.
  3. 3. The ask. "Read the code back to me so we can secure your account."
  4. 4. The theft. The code approves a payment, adds a payee or logs them into your online banking. Money moves within seconds.
  5. 5. The cover-up. They may tell you not to contact the bank "because the fraud team is compromised", keeping you quiet while transfers clear.

Why a Real Bank Will Never Ask for Your One-Time Code

Your one-time passcode exists for one reason: to prove you are approving an action. A genuine bank employee can see whether a payment is pending — they never need you to read a code back to them. Treat any request for a code, PIN, password or "safe account" transfer as a scam signal, whatever the caller claims.

Warning Signs in Calls, Texts and Emails

  • ⛔ Anyone asks you to read back a code or confirm a PIN/password.
  • ⛔ Urgency: "your account is being emptied right now".
  • ⛔ An instruction to move money to a "safe account" — safe accounts do not exist.
  • ⛔ Requests to install remote-access software or download an "app" from a link they send.
  • ⛔ Texts with links claiming your card is blocked, a delivery fee is owed, or a payment failed.
  • ⛔ They already know your name, address or partial card number — scammers buy this data from breaches and use it to sound official.
  • ⛔ "Don't tell anyone at the bank" or "don't hang up".

What to Do If You Shared a Code or Approved a Payment

  1. 1. Call your bank now — 159, their official app, or the number on the back of your card. Say: "I think I've been a victim of fraud." Ask them to freeze accounts and recall any pending payment.
  2. 2. Change your online banking password and check for new payees or devices you don't recognise.
  3. 3. Report it to Action Fraud at actionfraud.police.uk or 0300 123 2040, and get a crime reference number.
  4. 4. Keep the evidence — screenshots of texts, caller numbers, times and what was said.
  5. 5. Watch for follow-up scams — criminals often call "victims" again pretending to be the police or a recovery service. See how to avoid recovery scams.

Under the UK's authorised push payment (APP) fraud rules, banks must reimburse eligible victims up to £85,000. If the bank rejects your claim, you can escalate to the Financial Ombudsman.

How to Contact Your Bank Safely

  • ✅ Call 159 — the UK's national fraud hotline that connects you straight to your bank's fraud team.
  • ✅ Use the number on the back of your card or the number in your bank's official app or website.
  • ✅ Message your bank through its official in-app chat.
  • ❌ Never call a number left in a voicemail, text or email, or given by someone who called you.
💡 Bank call safety script: "I'll call you back on the number on my card." Hang up, wait five minutes (or use another phone), then call the official number. A genuine bank will never mind you doing this.

Common Bank-Impersonation Wording to Recognise

"This is the fraud department at [bank]. We've stopped a £1,850 payment to Amazon. I've sent a security code to your phone — read it back so I can confirm your identity."
"Your card has been used abroad. To block the transaction we need you to move your balance to our safe account — I'll stay on the line to help."
Text: "Barclays: your card is temporarily restricted. Visit barclays-security-verify[.]com to reactivate." — with a lookalike link.

Each of these is a scam. Real banks already know if a card has been used abroad — they don't need you to verify it by moving money or reading codes.

Frequently Asked Questions

Would a real bank ever ask for my one-time passcode?
No. A genuine UK bank will never ask you to read out, type in or confirm a one-time passcode sent to your phone. If someone asks for it, they are a scammer.
I gave a scammer my code and money has gone. What do I do?
Call your bank immediately using the number on the back of your card, their official app or 159. Tell them you have been a victim of fraud, and ask them to freeze the account, recall any pending payment and investigate. Then report to Action Fraud and keep every piece of evidence.
What is 159?
159 is the UK's national fraud hotline run by Stop Scams UK. Calling 159 connects you directly to your bank's fraud team on a verified line. It's free to call from most UK landlines and mobiles.
The caller said they were my bank's fraud team. How do I check safely?
Hang up. Wait at least five minutes or use a different phone, then call your bank back on the number on the back of your card, in their official app, or on 159. Never call a number the caller gave you.
I approved a payment in my banking app by mistake. Can I get the money back?
Contact your bank's fraud team immediately. Under the UK's authorised push payment rules, banks must reimburse eligible victims up to £85,000. If you are unhappy with the outcome, you can complain to the Financial Ombudsman Service.
Why do scammers want my one-time code?
A one-time passcode is the final security check before a payment or login goes through. With your code, a scammer can approve a payment, empty an account or take over your online banking within seconds.
🚨

If You Think You've Been Scammed

Do these five things now. Speed protects your money and your evidence.

  1. 1Stop and secure. Close suspicious pages or apps. If you shared bank details, contact your bank immediately on the official number in their app or on your card.
  2. 2Change passwords. Update any account where you reused the same password. Enable two-factor authentication (2FA) where available.
  3. 3Record what happened. Save messages, emails, screenshots and transaction details. Note dates, times and any numbers used.
  4. 4Report it. In the UK: report to Action Fraud and tell your bank. Forward scam texts to 7726 and phishing emails to [email protected].
  5. 5Watch for follow-up scams. Be suspicious of anyone claiming they can "recover" your money for a fee — that is a second scam. Only use official channels.
🚨 Get the full action plan Report to Action Fraud ↗ 🔎 Check the follow-up message

🔗 Related Guides

I've been scammed — what now I clicked a phishing link SIM-swap attacks Reporting to Action Fraud Getting your money back 🔎 Scam Checker
Last reviewed: September 2026 · Sources: Action Fraud · NCSC · Cifashow we verify