Hang up. Look up the number yourself. Wait a day.

← Back to the start

Is this text from my bank real?

Short answer: probably not. And you don't have to figure it out.

Don't tap the link. Don't call the number in the message. Instead, open your bank's app, or call the number on the back of your card. If the alert is real, it'll be waiting for you inside your account. If nothing's there, there was nothing there.

That takes sixty seconds and works whether the text was real or fake — which means you never have to judge the text at all.


Why the text looks so convincing

Because it's supposed to. And because a few things you might rely on prove nothing:

It arrived in the same thread as your real bank texts. Text senders can be spoofed. A fake message can land underneath genuine ones from your bank. This alarms people who notice it, and it's completely routine.

It has your name. Bought from a data broker for pennies.

It has the last four of your card. Same source, or a past breach. See how they got your information.

The link looks right. chase-alerts.com and secure-chase.net are not chase.com. But don't get good at spotting these — just never use a link from a message. That rule needs no expertise and never fails.


The three things it will ask for

A link to log in. The page is a copy. Your password goes to them.

A reply of YES or NO about a charge. Reply either way and a "fraud department" calls you within minutes — and now they called you, and the conversation has begun on their terms.

A code they just texted you. Never say this out loud to anyone. Your bank sends it to keep others out. Anyone asking for it is trying to get in, and your bank will never, ever ask.


What to do

  1. Don't tap. Don't reply. Don't call the number in the text.
  2. Open the bank app you already use, or call the number on your card.
  3. Ask directly: "Did you send me a text about this?"
  4. Delete the message, or forward it to 7726 (SPAM) first — free, and it helps your carrier block the sender.

Never reply STOP. That just confirms a real person reads that number.


If you already tapped and entered your password

Not a catastrophe. Do this:

  1. Change that password on the real site, typed yourself
  2. Change it anywhere else you used the same one — this is the real risk
  3. Call your bank on the number on your card and tell them
  4. Watch your statement for three months, including small charges

If you already read out a code

Call your bank immediately, on the card number. That code likely let someone into an account or approved a transfer. Speed matters here more than anywhere else.

The part worth keeping

You never have to judge whether a text is real. That's the good news buried in all of this.

Open the app, or call the number on your card. Sixty seconds, and the question answers itself — every time, forever, no matter how convincing the message looks.


Related: There's a problem with your account · The three steps