A 148% surge in a single year
Impersonation scams — fraud where the caller poses as a legitimate business or financial institution — surged 148% year over year according to Identity Theft Resource Center data, with scammers most commonly posing as banks through spoofed phone numbers, fake customer service lines, and fraudulent websites. This growth reflects how effective and scalable caller ID spoofing technology has become for fraud operations.
Why "I recognized the number" no longer means anything
Caller ID spoofing technology allows a fraudulent call to display any phone number the caller chooses, including your actual bank's real, published customer service number. The instinct to trust a call because the displayed number matches what you'd expect from your bank is exactly the assumption spoofing is designed to exploit — the display tells you nothing reliable about who's actually calling.
The one action that genuinely defeats spoofing
Hanging up and calling back using a number you look up independently — from the back of your physical card, a past statement, or the bank's official website typed directly — breaks spoofing entirely, since spoofing only affects what displays on an *incoming* call; it has no effect on a number you dial yourself. This single habit is more reliable than any amount of scrutinizing the call itself.
The two scripts that show up most often
- Reading out a one-time passcode. A genuine one-time code is meant to verify you to your bank, never the reverse — no legitimate representative ever needs you to read one back to them over the phone.
- "Move your money to a safe account." Framed as urgent fraud protection, this instruction to transfer funds to a new account is one of the most consistently effective bank-impersonation scripts, precisely because it's framed as protective rather than as a request.
Why staying on the line is itself a red flag
A caller who pressures you to stay on the phone while you "verify" — rather than hanging up and calling back independently — is specifically preventing the one verification step that would expose a spoofed call. A genuine bank representative has no reason to object to you calling back on a number you look up yourself.
Checking your own accounts independently
A real account issue serious enough to justify an urgent call typically also surfaces in your bank's own app or online banking portal, checked directly and independently of the call itself — a discrepancy between what the caller claims and what your own account actually shows is a strong signal worth noting.
Building the habit before it's tested
Deciding in advance that any call about account security or fraud will always be verified via an independent callback — regardless of how urgent or legitimate it sounds in the moment — removes the need to make that judgment call under the pressure a scam call is specifically designed to create.
Frequently Asked Questions
Impersonation scams surged 148% year over year according to Identity Theft Resource Center data, with scammers most commonly posing as banks or financial institutions through spoofed phone numbers, fake customer service lines, and fraudulent websites.
No — caller ID spoofing technology allows a fraudulent call to display any phone number the caller chooses, including your bank's actual, published customer service number. The number on your screen provides no reliable information about who is actually calling.
Hanging up and calling back using a number you look up independently — from your physical card, a past statement, or the bank's official website typed directly. Spoofing only affects what displays on an incoming call; it has no effect on a number you dial yourself.
Being asked to read out a one-time passcode (which should only ever verify you to the bank, never the reverse), and being urgently instructed to move money to a 'safe account' to protect it from fraud — both are among the most consistently effective scripts used in bank-impersonation scams.
Yes — the Caller ID Spoofing Verification Checklist is a weighted 11-point checklist centered on the callback-verification habit, plus the one-time-code and move-your-money red flags, producing a live 0-100 risk score.