← SCAMHUNTER.CH

Fake bank adviser and phishing: what to do in the first hours

A call from your bank's "anti-fraud department", an SMS announcing a suspicious payment, an email demanding confirmation: the script is almost always the same, and the first hours decide what can still be blocked.

By the ScamHunter.ch investigation team · Updated 26 August 2026 · Reading time: 9 min

Spoofed call, fraudulent SMS and lookalike domain linked to preserved evidence and the official bank channel
Editorial illustration: the call, the message and the lookalike domain form a single chain of evidence that must be frozen before it disappears.

Bank adviser impersonation is one of the most effective frauds circulating in Switzerland, because it does not attack the bank: it attacks you. The fraudster does not need to break a security control if he can get you to approve the operation on his behalf. This guide describes what actually happens, what to do and in what order, and what an investigation can still reconstruct afterwards.

The essentials — No bank asks for a code, a password or the approval of a notification over the phone. Hang up, call your bank back on its official number, have payment methods blocked and request the recall of transfers in writing. Then preserve everything: messages, phone numbers, full URLs and receipts.

How bank adviser impersonation works

The scheme rests on three combined levers. First credibility: the fraudster often knows your name, sometimes your bank, sometimes the last digits of a card, obtained through a data breach or an earlier phishing message. Then urgency: a fraudulent payment is supposedly under way and must be stopped within the minute. Finally authority: the number displayed imitates the bank's own, because caller ID can be falsified without difficulty.

From there, the whole exchange has a single objective: to make you produce the one element the fraudster cannot obtain alone. It will be a code received by SMS, the approval of a notification in your app, the installation of a "security" tool that is in fact remote-control software, or a transfer to a "safe account" that exists in no bank.

The signals that expose a fake adviser

The six first actions, in order

  1. Hang up and call the bank on its official number — the one on the back of your card or in your contract, never the one given during the call. Use a different line if possible, since a call can be held open.
  2. Have payment methods blocked: cards, e-banking, pending payments, and have any unknown device linked to your access revoked.
  3. Request the recall of transfers already sent, explicitly and in writing. Note the exact time of your request and the name of the person you spoke to.
  4. Change your credentials from a clean device, different from the one used during the attack, especially if software was installed.
  5. Report the facts to the Federal Office for Cybersecurity, submit the fraudulent page to antiphishing.ch and file a complaint with your cantonal police.
  6. Freeze the evidence before deleting anything: messages, numbers, full URLs, transfer receipts.
Do not clean up too fast — The instinct to delete messages, reset the phone or clear history destroys precisely what would link the attack to known infrastructure. Isolate the suspect device, but do not wipe it before everything has been saved.

What your bank can and cannot do

Your bank can block your payment methods, attempt a recall of the transfer with the beneficiary institution, provide transaction records and document the chronology. What it cannot do is compel a foreign bank to return funds, guarantee you a refund, or identify the perpetrator: that falls to criminal proceedings and the authorities.

Whether you are refunded depends on your contractual terms and on the circumstances, in particular on how the codes travelled. This is where a structured file changes things concretely: it lets your bank, your legal expenses insurer or your lawyer examine a dated, sourced account rather than an approximate memory.

The traces to preserve for an investigation

A phishing campaign is almost never isolated. It reuses domains, hosting, page templates and cash-out routes from one victim to the next. These are exactly what an OSINT investigation works with afterwards:

If the funds were converted into cryptocurrency, the trail often remains readable on public ledgers: see our guide on first actions after a crypto scam. The technical terms used here are defined in our glossary.

The mistakes that cost the most

Have your case reviewed

Our investigators reconstruct the chronology, analyse the infrastructure used and trace visible flows to produce a file your bank, your lawyer and the authorities can work with. Feasibility review before any engagement.

Open my investigation file
A team specialised in OSINT and digital investigation, based in Geneva. Editorial responsibility: Danilson Ramos. No investigation or recovery outcome is guaranteed.

Frequently asked questions

Can my bank call me to ask for a code?

No. No Swiss bank asks by phone, SMS or email for an authentication code, an e-banking password or the approval of a notification in your app. Anyone requesting these, even while displaying the bank's official number, is trying to approve a fraudulent operation. Caller ID can be falsified: it proves nothing.

The transfer has left: can I still get it back?

Sometimes, if you act very quickly. As long as the funds have not been withdrawn from the receiving account, the sending bank can attempt a recall of the transfer with the beneficiary bank. That recall is never guaranteed: it depends on how fast the request is made, the destination country and the cooperation of the receiving institution. Ask for it explicitly and in writing, without waiting until the next day.

Will my bank refund me after a phishing attack?

It depends on your contractual terms and on the circumstances. Banks look in particular at whether codes were passed on by the customer and whether displayed warnings were followed. A clear, chronological and documented file markedly improves the review of your case. No refund can be promised to you in advance, either by your bank or by a third party.

Should I file a complaint even for a small amount?

Yes. Filing a complaint with the cantonal police officially records the facts, opens the way to requests addressed to banks and platforms, and allows cross-referencing with other victims of the same network. Many phishing campaigns hit hundreds of people: your report may complete an existing case.

Official sources

This article is informational and does not constitute individual legal advice. For any decision, consult a qualified professional with regard to your situation.