Free tools Windows power users keep installed
One-click scans. No signup required.
Do not use a link, phone number, QR code, or attachment in an unexpected bank alert to verify it. Treat the message as unverified, then check the reported transaction or account issue through your bank’s app, a web address you type yourself, or a trusted phone number such as the one printed on your card. A familiar logo, sender name, or caller ID cannot prove the alert is genuine.
Why a convincing alert may still be fake
Scammers can disguise sender names, email addresses, phone numbers, and website addresses to make them resemble a bank. They may also build a phishing site that looks nearly identical to the real one. The FBI describes these tactics as spoofing and phishing: a message may appear to come from a trusted business while steering you to a fake page that steals account details.
Common lures include claims of suspicious activity or login attempts, a problem with an account or payment, a request to confirm personal or financial information, an unfamiliar invoice, or a payment link. Urgent demands and requests to move money are especially serious warning signs. But no visual clue—or absence of one—reliably authenticates an alert.
In guidance about requests to verify account information, the Consumer Financial Protection Bureau says, “Banks and credit unions never ask for account information through email or text message.” Check your bank’s current practices through an independently chosen channel; do not use that statement, or any other single clue, as a substitute for verification. CFPB guidance on bank verification messages.
#1 Best Overall
How to verify an alert safely
- Stop interacting with the message. Don’t click a link or QR code, open an unexpected attachment, reply, or call its number. Don’t provide your password, PIN, one-time passcode, or other authentication secret to an unsolicited contact.
- Choose a trusted route yourself. Open the bank’s app directly, type a known official web address into a fresh browser session, or call the number printed on the back of your payment card. A saved bookmark can also help. Avoid login links in search ads or results; the FBI warns that ads can imitate legitimate businesses. The FBI advises: “Look up the company’s phone number on your own (don’t use the one a potential scammer is providing), and call the company to ask if the request is legitimate.” FBI guidance on spoofing and phishing.
- Ask about the specific claim. Tell the bank what the alert said and ask whether the transaction or account issue is real. A message can refer to a real account event without being a genuine message from the bank.
- If the alert came by phone, end the call and call back independently. Use the number on your card or another trusted source, not caller ID or a number the caller supplies. Caller ID can be spoofed.
Comparing the contact route can help you decide what to do next, but it does not authenticate a message:
| What to check | Unexpected alert | Safer verification route |
|---|---|---|
| Who initiated contact? | The sender or caller contacted you unexpectedly. | You initiate contact by opening the app or placing a new call. |
| Where did the contact details come from? | The link, number, or QR code arrived in the alert. | You select the app, type a known address, or use a trusted number such as the one on your card. |
| What is being requested? | It may ask for credentials, account information, a passcode, payment, or another action. | You ask the bank to confirm the reported issue; do not disclose authentication secrets to the unsolicited contact. |
| Is there pressure or a demand to move money? | Urgency or instructions to transfer funds, withdraw cash, buy gift cards, or use cryptocurrency are warning signs. | Pause and ask the bank through the independently selected route. The CFPB says legitimate government agencies and financial institutions do not tell people to move money to “protect” it. |
What to do if you clicked, shared information, or approved something
If you only opened a link
Close the page without entering information. If you did not download anything or provide details, continue with verification through the bank’s app or a trusted number.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
If you entered credentials or shared a passcode
Contact the bank promptly through an independently verified route. Ask it to secure the account and review activity. Change any exposed password through the genuine app or site, especially if you reused it elsewhere, and enable multifactor authentication (MFA) where available.
If you downloaded an attachment
Contact the bank if account information may have been exposed. If the download may have installed harmful software, update your security software and scan the device. The FTC also directs people who believe a scammer has their personal information to IdentityTheft.gov for tailored next steps.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
If a transaction is unauthorized
Contact your bank immediately using a trusted channel and follow its instructions. For a suspected fraudulent wire transfer, the FBI says to contact the financial institution promptly to request a recall or reversal and report the transfer to the FBI’s Internet Crime Complaint Center (IC3).
How to report a suspicious message
- Forward a suspicious text to 7726 (SPAM).
- Forward a phishing email to [email protected].
- Report the incident to the FTC at ReportFraud.ftc.gov.
These are reporting routes, not a replacement for contacting your bank if you shared information or see an unauthorized transaction. Check the FTC’s current phishing guidance for reporting details.
Rank #4
What MFA can—and cannot—do
MFA adds a sign-in check beyond a password; a hardware security key is one possible factor, if your bank supports it. MFA can help protect account sign-ins, but it does not verify an incoming alert. It also does not make a fraudulent login page safe: entering a password or passcode on a fake site can still expose it. Use MFA as account protection, not as a reason to trust a message or link.
How common are bank-impersonation scams?
In June 2025, the FDIC reported an FTC finding that bank-impersonation scams were the most reported scam occurring through text messages in 2022 and had been reported nearly twenty times as often as in 2019. That comparison is specifically about reported bank-impersonation scams through text messages; it is not a measure of all phishing or of every bank alert. FDIC: Bank Impersonation Scams and Fake Banks.
Quick Recap
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




