Bank helpdesk impersonation fraud rises sharply
Despite extensive attention to bank helpdesk impersonation fraud, also known as telephone spoofing(opens in new window) , from the media, banks and politicians, losses from this type of fraud continue to rise sharply, particularly among older people.

In 2020, total losses from bank helpdesk impersonation fraud amounted to almost €27 million. At the current rate, total losses could reach €40 million in 2021. Banks now receive around 300 reports each month. The average loss per victim can easily reach €10,000.
In bank helpdesk impersonation fraud, a fraudster calls while pretending to represent the victim’s bank. Sometimes the victim sees the bank’s genuine telephone number on their screen. As technical measures are increasingly preventing criminals from misusing banks’ real telephone numbers, fraudsters now usually call from a random, unknown number.
The fraudster poses as a bank employee and falsely tells the victim that their bank account is no longer secure. The victim may then be tricked into transferring their entire balance in one or more transactions to supposedly ‘secure’ it in a ‘safe account’. However, fraudsters are increasingly using other pretexts to steal large sums from their victims.
Because losses are increasing and fraudsters are changing their methods, banks ran a collective public information campaign aimed at older people earlier this year. Banks also continue to warn customers through online and mobile banking.
Five spoofing myths quickly debunked
- A bank will never ask you by telephone or text message to transfer money
- A bank will never ask you to hand your debit card to someone at home
- A bank will never ask for access to a customer’s computer or smartphone
- A bank will never ask you to send your debit card by post
- A bank will never ask for your PIN verbally, in a message or on a website
If in doubt, call your bank yourself
If a customer receives an unsolicited and unexpected call from someone claiming to represent their bank, they can end the call immediately and call the bank themselves. They should use an official, publicly available telephone number they have found themselves, for example on their debit card, through online banking or in their bank’s mobile app. Never call a telephone number included in a text message or email. If the message is fraudulent, its contact details will also be false.
Fraudsters collect debit cards from victims’ homes or request computer access
Fraudsters posing as bank employees now also trick victims into handing their debit card to someone who visits their home. They may tell the victim to enter the card’s PIN ‘securely’ on the telephone or on a website.
Victims are increasingly told that they must give someone from the bank access to their computer or smartphone, sometimes after downloading and installing special software that enables this. This gives the fraudsters free rein on those computers and smartphones.
‘Safe accounts’ do not exist
A genuine bank will never ask a customer to supposedly ‘secure’ their own bank balance. So-called ‘safe accounts’ do not exist; they are invented by fraudsters. In an emergency, a bank can block an account remotely without the account holder having to do anything.
A genuine bank will never ask a customer to hand over a debit card or send it by post. If a debit card no longer works or is no longer valid, the customer should cut it lengthwise through the copper-coloured payment chip and dispose of it. In an emergency, a bank can immediately block any debit card remotely without the cardholder’s assistance.
A bank will also never ask a customer for access to their smartphone or computer. A bank can do everything necessary in its own systems to manage and, if needed, block a customer’s account. It does not require access to the customer’s computer or smartphone.
Never disclose your PIN to anyone, including a bank employee or the police. Never enter a debit card PIN on a telephone, in a text message or on a website. Cardholders should only enter their PIN themselves on dedicated devices on which the debit card must also be tapped or inserted, such as a payment terminal, an ATM or the online banking authentication device provided by some banks.
Related articles
-
Innovation Takes Center Stage at Annual DNB Symposium on Payments
-
News
-
Payments for all
-
-
Six out of ten retail business owners say they are prepared for card payments failures
-
News
-
Card payments
-
-
Make sure you have (digital) fallback options in case of a potential card payments failure!
-
News
-
Card payments
-
-
DNB presents ‘Payments Strategy’ until 2028
-
News
-
Availability and disruptions
-
-
Arjan Bol on Radio 5 about deferred card payments
-
News
-
Availability and disruptions
-
-
BIC and Identifier ‘FIRHNL22’ added to the SEPA BIC list
-
IBAN/BIC list
-
IBAN and BIC
-