Fake bank adviser and phishing: what to do in the first hours
A call from your bank's "anti-fraud department", an SMS announcing a suspicious payment, an email demanding confirmation: the script is almost always the same, and the first hours decide what can still be blocked.

Bank adviser impersonation is one of the most effective frauds circulating in Switzerland, because it does not attack the bank: it attacks you. The fraudster does not need to break a security control if he can get you to approve the operation on his behalf. This guide describes what actually happens, what to do and in what order, and what an investigation can still reconstruct afterwards.
How bank adviser impersonation works
The scheme rests on three combined levers. First credibility: the fraudster often knows your name, sometimes your bank, sometimes the last digits of a card, obtained through a data breach or an earlier phishing message. Then urgency: a fraudulent payment is supposedly under way and must be stopped within the minute. Finally authority: the number displayed imitates the bank's own, because caller ID can be falsified without difficulty.
From there, the whole exchange has a single objective: to make you produce the one element the fraudster cannot obtain alone. It will be a code received by SMS, the approval of a notification in your app, the installation of a "security" tool that is in fact remote-control software, or a transfer to a "safe account" that exists in no bank.
The signals that expose a fake adviser
- You are asked for a code, a password or an approval. This is the decisive signal: a bank never needs these, since it issues them.
- You are placed under time pressure. Artificial urgency exists to prevent verification.
- You are told not to hang up, or to stay on the line while you check your app.
- You are asked to install software for assistance or screen sharing.
- You are given a destination account different from your usual ones, in the name of "securing" your money.
- The website address differs by one character or ends in an unusual domain: the lookalike domain is the technical backbone of most campaigns.
The six first actions, in order
- Hang up and call the bank on its official number — the one on the back of your card or in your contract, never the one given during the call. Use a different line if possible, since a call can be held open.
- Have payment methods blocked: cards, e-banking, pending payments, and have any unknown device linked to your access revoked.
- Request the recall of transfers already sent, explicitly and in writing. Note the exact time of your request and the name of the person you spoke to.
- Change your credentials from a clean device, different from the one used during the attack, especially if software was installed.
- Report the facts to the Federal Office for Cybersecurity, submit the fraudulent page to antiphishing.ch and file a complaint with your cantonal police.
- Freeze the evidence before deleting anything: messages, numbers, full URLs, transfer receipts.
What your bank can and cannot do
Your bank can block your payment methods, attempt a recall of the transfer with the beneficiary institution, provide transaction records and document the chronology. What it cannot do is compel a foreign bank to return funds, guarantee you a refund, or identify the perpetrator: that falls to criminal proceedings and the authorities.
Whether you are refunded depends on your contractual terms and on the circumstances, in particular on how the codes travelled. This is where a structured file changes things concretely: it lets your bank, your legal expenses insurer or your lawyer examine a dated, sourced account rather than an approximate memory.
The traces to preserve for an investigation
A phishing campaign is almost never isolated. It reuses domains, hosting, page templates and cash-out routes from one victim to the next. These are exactly what an OSINT investigation works with afterwards:
- The full URL of the fraudulent page, including everything after the domain name, and the date of access.
- The original message kept whole, with its technical headers if it is an email.
- The calling numbers and the precise timestamp of each call.
- The transfer receipts: amount, currency, IBAN and beneficiary name, operation reference.
- The exact name of any software installed and when it was installed.
- Your exchanges with the bank, with contact times.
If the funds were converted into cryptocurrency, the trail often remains readable on public ledgers: see our guide on first actions after a crypto scam. The technical terms used here are defined in our glossary.
The mistakes that cost the most
- Waiting until tomorrow. A transfer recall is decided in hours, not days.
- Calling back the number given during the call. It reaches the same person.
- Leaving the software installed "just to see": it grants continuous access.
- Answering a second time to a "recovery service" that contacts you afterwards. Re-victimisation is a common secondary fraud, and it targets the same people.
- Reporting nothing out of embarrassment: without a report, no cross-referencing is possible.
Have your case reviewed
Our investigators reconstruct the chronology, analyse the infrastructure used and trace visible flows to produce a file your bank, your lawyer and the authorities can work with. Feasibility review before any engagement.
Open my investigation fileFrequently asked questions
Can my bank call me to ask for a code?
No. No Swiss bank asks by phone, SMS or email for an authentication code, an e-banking password or the approval of a notification in your app. Anyone requesting these, even while displaying the bank's official number, is trying to approve a fraudulent operation. Caller ID can be falsified: it proves nothing.
The transfer has left: can I still get it back?
Sometimes, if you act very quickly. As long as the funds have not been withdrawn from the receiving account, the sending bank can attempt a recall of the transfer with the beneficiary bank. That recall is never guaranteed: it depends on how fast the request is made, the destination country and the cooperation of the receiving institution. Ask for it explicitly and in writing, without waiting until the next day.
Will my bank refund me after a phishing attack?
It depends on your contractual terms and on the circumstances. Banks look in particular at whether codes were passed on by the customer and whether displayed warnings were followed. A clear, chronological and documented file markedly improves the review of your case. No refund can be promised to you in advance, either by your bank or by a third party.
Should I file a complaint even for a small amount?
Yes. Filing a complaint with the cantonal police officially records the facts, opens the way to requests addressed to banks and platforms, and allows cross-referencing with other victims of the same network. Many phishing campaigns hit hundreds of people: your report may complete an existing case.
Official sources
This article is informational and does not constitute individual legal advice. For any decision, consult a qualified professional with regard to your situation.