A plain-English explainer for the adult child of an older parent. What the "move your money to a safe account" lie is, how a fake fraud-department transfer unfolds, and the one move that ends it before a dollar leaves the ledger.
TL;DR. A bank impersonation scam is a fraudster posing as your institution's loss-prevention team, using spoofed caller ID to look legitimate. The defining lie is always the same: they say your savings are compromised and you must move the balance to a "safe account" by wire or ACH. No real institution ever asks that. The fix is to refuse every transfer instruction, then verify on a trusted, family-known line before any money moves.
Why did we write this guide?
This is for the son who is 48, lives in Brooklyn, and whose dad in Albany got the message at 9 p.m. on a Tuesday. His screen showed the credit union's loss-prevention department. A calm voice described an unauthorized $4,800 wire to a routing number in Phoenix, and dad, who had authorized nothing, was already opening his online banking ledger.
According to the FBI's San Francisco field office, the "Phantom Hacker" version of this scheme, which always ends with a victim moving funds to a so-called safe account, has cost Americans more than $1 billion since 2024 (see fbi.gov). Separately, the FBI's Internet Crime Complaint Center reports that business-email and wire-redirect schemes drained $3.04 billion in a single year (ic3.gov/AnnualReport/Reports).
So this article is for that family. The bank impersonation scam is the most common version of this attack, and it ends the same way every time, with a transfer. About a six minute read, landing on one rule you can text your dad before bed.
What is the bank impersonation scam, exactly?
A bank impersonation scam is a fraudster posing as a loss-prevention or security employee from your parent's actual institution, a fake bank call dressed up as a rescue. The display name is spoofed to read "Chase Security," "Wells Fargo Loss Prevention," or your credit union's branded line. The FTC documents this bank fraud department imposter pattern as a top loss vector for adults 60 and older (consumer.ftc.gov).
The pitch sounds authentic. To sell it, the impostor cites the institution's name, sometimes a routing prefix or the last digits of an account, plus the vocabulary of a real security desk: dispute, hold, two-factor, ledger, freeze. A breached customer file is enough to seed the bank impersonation scam with detail that feels personal. For ninety seconds, a stranger is wearing the institution's uniform.
How does the fake fraud-department transfer unfold?
The sequence of a wire transfer fraud call is consistent enough to write down, and a bank text-message scam follows the same arc by SMS. The FTC's imposter guidance and CISA's security advisories describe a near-identical script (cisa.gov).
- The spoofed loss-prevention line lights up.
First, the display reads as the institution's security desk. Spoofing that label costs a fraudster nothing.
- An invented unauthorized transaction sets the hook.
Next, calm and rehearsed. "We flagged a $4,800 wire you authorized to an account in Phoenix, can you confirm it?" Your parent says no, and the alarm takes hold.
- The pivot to a "safe account."
Then the tone softens to rescue. "While we investigate, move your savings to a secure account in your own name. I will walk you through the transfer." This is the entire scam in one sentence.
- The one-time passcode gets read aloud.
After that, the institution's real two-factor system texts an OTP. The impostor asks your parent to recite it "to verify identity." That code authorizes the outgoing ACH or wire.
- A fake federal voice closes it.
Finally, your parent is handed to a second actor, an "FBI agent" or "Federal Reserve investigator," who forbids discussing the case with relatives.
The FTC's guidance on recovering from a transfer scam lands on the same idea: verify on a trusted, independent channel before authorizing anything (consumer.ftc.gov/articles/what-do-if-you-were-scammed).
What a real loss-prevention team never does
This is the part to print and tape inside a cabinet door. A genuine security or loss-prevention team at any major U.S. institution does none of the following. Not ever.
- Instruct you to move your balance to a "safe account" or "secure account in your own name" by wire or ACH.
- Ask for your full Social Security number, your debit PIN, or your online-banking password.
- Recite a one-time passcode from a text and ask you to read it back.
- Object when you say "I will verify this independently before I authorize anything."
- Transfer you mid-conversation to "the FBI" or "the Federal Reserve" to pile on urgency.
If any one of those happens, the voice is an impostor running the bank impersonation scam. The Department of Justice has prosecuted dozens of wire-redirect rings that ran this exact playbook (justice.gov).
No institution moves your savings to keep them safe. The transfer instruction is the scam.
Why does the bank impersonation scam fool careful people?
For thirty years the standard advice for suspicious contact was "if anything feels off, end it and reach out independently." The FTC still names that habit as the core defense (consumer.ftc.gov).
However, the safe-account scheme is engineered to defeat that instinct. The display label is your parent's institution. The OTP that arrives is a real passcode from the real two-factor system, triggered when the impostor enters your parent's username on the genuine login page, and your parent is the one reciting it. To the victim, the whole exchange feels like cooperating with the security desk.
Moreover, the emotional override is total. Once the actor shifts from "confirm this fraud" to "let me protect your savings," your parent is already on the same side as the voice, and the next instruction sounds like rescue. App alerts do not solve this, because a fraud notification fires only after the wire is submitted. AARP's helpline at 1-877-908-3360 is excellent, yet it is reached, almost always, after the loss (aarp.org/money/scams-fraud/helpline).
What can I do this week to stop the safe-account scam?
The smallest possible intervention. Sit with your parent this Sunday and agree on one principle out loud: no balance ever moves, by wire or ACH, on the say-so of an incoming voice. Then set up a trusted line they can reach in seconds to verify before authorizing anything, so the impulse to act has somewhere safe to land.
Make the rule plain. Any request to relocate your savings to a "safe account" gets refused, then verified independently before a dollar moves. Not the contact a "supervisor" supplies. Not a link in a text. A line your family chose together, in advance.
The five-minute conversation:
- Sit with your parent and open their online-banking ledger together so the real interface is familiar.
- Agree the principle: no wire or ACH leaves the account on an incoming instruction, full stop.
- Set up the trusted line your family will use to verify, and save it under a clear name.
- Tape a short reminder inside a cabinet door: "No bank moves your savings to keep them safe."
- Rehearse the refusal sentence so it is ready under pressure: "I will verify this myself before I authorize anything."
Why this small fix beats the bank impersonation scam
An impostor with a spoofed label and a polished pitch can imitate the security desk for ninety seconds. However, the whole scheme depends on keeping your parent in that one conversation until the transfer clears. A standing refusal to move money, plus an independent line to verify on, removes the only thing the actor needs: an authorized wire while the pressure is hot.
Common questions about the bank impersonation scam
The display said my institution. How is that possible?
Spoofing a display label is trivial. The text on the screen is just metadata, and anyone with a VoIP setup can write it. The FTC treats a spoofed bank label as a baseline assumption on any unsolicited contact (consumer.ftc.gov). Verify independently and the impostor falls apart.
The voice knew the last digits of my parent's account. Isn't that proof?
No. Account fragments and routing prefixes leak constantly through breaches and data-broker resale. Knowing a few digits is exactly the detail a fraudster buys in advance to sound legitimate. A real security agent already has the file open and will not make your parent confirm sensitive details aloud.
What if a two-factor code arrives while we are talking?
Then stop. A genuine agent will never ask for that passcode. If the text says "do not share this code with anyone, including staff," the institution means it literally. Read it once, never aloud, and verify on your trusted line before doing anything else.
What if my parent already moved money or shared a code?
Reach the real institution's fraud unit right away and ask for a recall or freeze. ACH and wire reversals are time-sensitive, so the first hour matters most. Then file a police report, report to the FTC at reportfraud.ftc.gov and the FBI's IC3 at ic3.gov, and request a dispute under Regulation E. AARP's helpline at 1-877-908-3360 can walk the family through it. Keep every text and screenshot.
Do we need an app to block these schemes?
No. The threat is a persuasive voice, not a virus. The defense is a standing refusal to move savings plus an independent line to verify on. An app will not be opened in the ninety seconds that decide the outcome. The agreement is the tool.
Where to go next
The Resources library has printables you can tape inside a cabinet door, including a "what a real loss-prevention team never does" card. Related explainers: What is an AI voice clone scam?, The "secure your account" gift card scam, The 2026 grandparent scam, and The family word, and how to set one up. The follow-up piece, After the call, walks through the first hour if money has already moved. The kit page explains how the magnet, wallet card, and family-routed secure line fit together.