Back to Posts

Learn How Bank Impersonation Scams Work

Elderly person holding a smartphone near an ATM, representing bank impersonation scams targeting seniors

Originally Published: March 23, 2026
Last Updated: Aug. 14, 2026

By Tracey Birkenhauer, journalist and Chief Impact Officer, STACK Cybersecurity

The call comes with a real name, a real balance, and a real transaction from your account. That's what makes it work. No malware, no hacking, and no technical skill on the caller's part beyond a spoofed phone number and a script. Just a voice that sounds official, a story that sounds urgent, and financial details that sound like proof.

Michigan law enforcement has spent the past 18 months tracking a pattern of these calls across Macomb County, and the losses are climbing into six figures per victim. Understanding how the scam works, and why caller ID can't be trusted, is the best defense available to consumers and to the employees who bring these same habits to work.

Executive Summary

Bank and government impersonation scams now cost Americans billions of dollars a year, and Michigan cases show how the pattern plays out locally. Criminals buy stolen account data on the Dark Web, spoof a bank's real phone number, and use invented urgency, such as a fraud alert, a warrant, or a federal investigation, to pressure victims into moving money before they can verify the story. Cryptocurrency kiosks have become a preferred cash-out method, and the FBI reports losses to these machines rose sharply in 2025, with adults over 50 bearing the largest share. Businesses face a version of the same risk: employees who trust caller ID or urgent-sounding requests are the same employees vishing attacks target for wire fraud and credential theft. The defense is the same at home and at work: verify independently, never through a number or link the caller supplies.

Where the Caller Gets Your Information

Victims often ask how a stranger on the phone already knew their account balance or a recent transaction. It feels like proof the caller must be legitimate.

It isn't. That data was purchased. Stolen credentials, account numbers, and transaction histories from data breaches and phishing campaigns circulate on dark web marketplaces long before a scammer ever picks up the phone. Reciting a real detail back to a victim isn't verification. It's a technique built to make the target drop their guard before the ask.

How the Call Sounds Exactly Like Your Bank

Caller ID spoofing costs almost nothing and takes no technical skill to buy. A scammer can make an outgoing call display any number, including a bank's real, published customer service line. A victim who checks that number against the back of their card will see a match. That's not a coincidence. It's the setup.

From there, the script follows a predictable arc: an invented crisis (a large transfer is happening right now), an invented authority (a federal investigation, a warrant, a judge), and an invented urgency that discourages the victim from pausing to verify or telling anyone else what's happening. Each element serves a purpose. The crisis short-circuits careful thinking. The authority figure discourages questions. The secrecy cuts off anyone who might intervene.

Two Macomb County cases from Shelby Township show how effective this is against careful, skeptical people. In one, a caller identifying himself as "Shawn Taylor" from the U.S. Treasury and Social Security Administration told a resident that someone had used her Social Security number and a warrant had been issued for her arrest. Over a series of calls, she wired nearly $110,000 to protect the rest of her money. Shelby Township police, working with investigators in Georgia, identified and arrested a suspect, Kelly Umana, who was charged with false pretenses and held on a $20,000 bond.

In a separate case, an elderly Shelby Township couple received an email claiming fraudulent charges tied to child pornography had been made on their credit card. The email instructed them to withdraw $50,000 in cash, place it in a box, and hand it to someone claiming to be a Treasury Department agent, and not to tell anyone. Two days later, they did exactly that. Police used license plate reader data to identify a suspect, Vedantkumar Patel, who was arrested, extradited from Ohio, and charged with false pretenses and larceny before the case was referred to the FBI for further investigation.

Neither victim was reckless or unintelligent. Both were responding to a script built specifically to bypass caution.

Want to Fortify Your Company's Defenses?

Email: info@stackcyber.com
Phone: (734) 744-5300

Cryptocurrency Kiosks Have Become the Preferred Cash-Out Method

Where older impersonation scams relied on wire transfers or a courier picking up cash, a growing share now ends at a cryptocurrency kiosk, an ATM-like machine that converts cash into digital currency. According to the FBI's Internet Crime Complaint Center (IC3), the bureau received more than 13,400 complaints involving cryptocurrency kiosks in 2025, with losses exceeding $388 million, a 58% jump from 2024. More than half of those complaints came from people over 50, accounting for over $302 million in losses.

The pattern is consistent with the phone scripts described above. A caller posing as a bank, a government agency, or law enforcement instructs the victim to withdraw cash, locate a nearby kiosk, and deposit the money, often walking them through each step by phone. Once the cryptocurrency is sent, the transaction can't be reversed and the funds are typically unrecoverable.

Why Bank Security Settings Matter During an Active Scam

The FBI's IC3 tracks a related and growing category called account takeover fraud, in which criminals impersonate a financial institution's staff or website to gain access to a customer's account. In 2025, IC3 logged about 4,700 complaints in this category, with losses of $359.7 million.

If a person receives an unexpected one-time passcode text for a transaction they didn't initiate, that's a signal to stop, open a new browser tab, and log into their bank's website directly, rather than calling any number the caller provided. From there, they should review the phone numbers and email addresses registered as security contacts on the account and remove anything unfamiliar before contacting the bank through the number on the back of their card.

Free Download

Deepfake Compliance Checklist

TAKE IT DOWN Act requirements, 30-state election disclosure obligations, and internal controls for every business type.

PNC Bank states in its published security guidance that it will never ask a customer for their online or mobile banking password, username, or Card Free ATM access code by phone, text, or email. Most major banks publish similar guidance. Those two sentences, taken seriously, stop most of these scripts before they succeed.

"The cases we've seen follow the same pattern," said Rich Miller, CEO of STACK Cybersecurity. "The caller already has a real piece of your information, and they use it to buy your trust to get you to move your funds. Those who avoid this are the people who hang up and call the number on their own card, every time, no exceptions."

Broader Threat Environment for Financial Firms

These consumer-facing scams aren't happening in isolation from the threats facing the financial sector itself. The Financial Industry Regulatory Authority (FINRA) issued a cybersecurity alert on March 16, 2026, warning member firms that Iranian state-sponsored and Iran-aligned threat actors are actively targeting U.S. financial institutions and critical infrastructure amid heightened geopolitical tensions. FINRA said the current environment presents an elevated risk of cyber intrusions, data theft, ransomware deployment, and destructive attacks.

When a financial institution is breached at the state level, the stolen data doesn't stay contained. It tends to flow into the same marketplaces that supply consumer-facing scammers with the account details that make their calls sound credible.

The Scale of the Problem

The Federal Trade Commission's Protecting Older Consumers 2024-2025 report, released Dec. 1, 2025, found that fraud losses reported by adults 60 and older climbed from about $600 million in 2020 to $2.4 billion in 2024. Because most fraud goes unreported, the FTC estimates the real cost to older adults in 2024 could range as high as $81.5 billion. Roughly two-thirds of the $2.4 billion in reported losses came from cases where a single victim lost more than $100,000.

Most victims never report what happened. Shame and embarrassment keep these cases out of the statistics, which is part of what keeps the pattern durable.

What is Vishing?

Vishing (short for "voice phishing") is a form of social engineering in which fraudsters use phone calls, Voice over IP (VoIP), or automated robocalls to trick regular people into revealing sensitive information, transferring money, or granting unauthorized access to systems.

Unlike standard phishing, which relies primarily on emails, text messages, or malicious links, vishing uses the spoken voice and psychological pressure to build immediate trust or panic.

What to Do Right Now

Log into every financial account and review the phone numbers and email addresses registered as security or two-factor authentication contacts. Remove anything unfamiliar and contact the bank directly using the number on a statement or the back of a card.

If a caller claims to represent a bank, a government agency, or law enforcement, hang up regardless of how convincing the story sounds or what number appears on the screen. Call the institution back using the number on the card, not a number the caller provided, texted, or that appears in a search result.

No bank, government agency, or law enforcement operation will ever instruct someone to withdraw cash and hand it to a courier, deposit it into a cryptocurrency kiosk, or move it to a "safe" account to protect it from fraud. Those instructions exist in exactly one place: a scam script.

Talk to parents, grandparents, and colleagues about this specific pattern, not just a general warning to "watch out for scams." The caller who recites a real transaction, the warrant story, the instruction to visit a kiosk or hand cash to a stranger: these are documented, repeatable elements, and naming them in advance is what keeps them from working.

Victims should file a complaint with the Federal Trade Commission, report the scam to the FBI at ic3.gov, and call their bank immediately using the number on a statement or bank-issued card.

Frequently Asked Questions

Why does caller ID show my bank's real phone number if it's a scam?

Caller ID spoofing lets a scammer make an outgoing call display any number, including a bank's genuine published customer service line. Matching the number on the back of a card doesn't confirm the caller is legitimate.

How do scammers already know my account details before they call?

Stolen account numbers, balances, and transaction histories from past data breaches and phishing campaigns are bought and sold on Dark Web marketplaces. Scammers purchase this data and use it to make the call sound credible before they ever ask for money.

Why are cryptocurrency kiosks used in so many of these scams?

Cryptocurrency transactions are fast and difficult to reverse. Once cash is converted and sent, there's typically no way to recover it, which makes kiosks an attractive cash-out method for criminals running impersonation and investment scams.

What should I do if I get an unexpected one-time passcode text?

Stop and don't respond to the text or the caller who prompted it. Open a new browser tab, log into the bank's website directly, and review the phone numbers and email addresses listed under account security settings for anything unfamiliar.

Does this risk apply to businesses, not just individual consumers?

Yes. The same urgency and impersonation tactics used against consumers are used in vishing attacks against employees to authorize wire transfers or hand over credentials. Training staff to verify requests independently, rather than trusting caller ID, applies equally at work and at home.

Need Help Training Your Team Against Social Engineering?

STACK Cybersecurity helps businesses build employee awareness programs, phishing simulations, and incident response plans that account for vishing and impersonation attacks. Check out our security awareness training.

Email: info@stackcyber.com
Phone: (734) 744-5300

STACK Cybersecurity is a Livonia, Michigan-based managed security service provider and CMMC Registered Practitioner Organization serving businesses across the country. STACK works exclusively with companies, not individual consumers, helping them protect employees, customers, and sensitive data from social engineering, fraud, and the full range of cyber threats. Businesses that want to understand their exposure or build stronger defenses can email info@stackcyber.com or call (734) 744-5300.

Cybersecurity Consultation

Is your company secure against cyber threats? If you're not sure, it's time for a cybersecurity risk assessment (CSRA). STACK Cybersecurity's CSRA will meticulously identify and evaluate vulnerabilities and risks within your IT environment. We'll assess your network, systems, applications, and devices. You'll get a detailed report and action plan to improve your security posture. Don't wait until it's too late.

Schedule a Consultation Explore our Risk Assessment