← All articles

Staying safe on the phone

How to check that a phone call is really from your bank

Caller ID can be faked. Security questions can be looked up. Here is what actually works — and a five-minute conversation to have with your family this week.

The 15-second answer: hang up. Call back on the number printed on your bank card or your statement — never a number the caller gave you, and never by pressing a button they tell you to press.

That one habit defeats almost every version of this scam. Everything below is why it works, and what to do in the situations where calling back isn't practical.

Caller ID is not evidence

Caller ID shows whatever number the calling system says it's using. There is no verification step in that process. Making a call appear to come from your bank's real customer service line is routine, and it is exactly what a caller trying to sound official will do.

So the sentence "but it came up as my bank on my phone" carries no information about who is on the line. It is worth saying that plainly, because caller ID feels like proof in a way it simply isn't.

The same applies to a caller who tells you to hang up and dial a number they read out, or to press a key to be "transferred to the fraud department." Both keep you inside a channel the caller controls. Look the number up yourself, from something physical you already have.

Security questions stopped proving anything

The traditional way a bank confirmed you were you was to ask things only you would know. That model has quietly broken.

Your mother's maiden name, the last four digits of your Social Security number, your date of birth, your previous address, even a recent transaction — this class of information turns up in breach data. Someone can know a startling amount about your life without having any legitimate connection to you.

This is the part worth sitting with, because it inverts the usual instinct:

A caller proving they know things about you is not proof of identity. It only proves they have access to information about you. Those are very different claims, and scam calls work by blurring them.

A caller who opens with your full name, your address, and the last four of your card is not demonstrating legitimacy. They may simply be reading a file. Real banks know this too, which is why good ones will never ask you to confirm a password, a PIN, or a full card number on an inbound call.

What actually proves identity

The thing that works is a shared secret that neither side can look up — something that exists only because both people agreed to it beforehand, or something you can independently confirm through a channel you chose yourself.

In practice that takes three forms, in rough order of reliability:

1. Call back on a published number

The strongest option, and it costs nothing. You end the inbound call and start a new outbound one to a number you sourced yourself: the back of your card, your statement, or the contact page you reached by typing the bank's address into your browser.

The key detail is that you chose the channel. A caller can control what appears on your screen; they cannot control who answers when you dial your bank directly.

One practical wrinkle: on some phones, hanging up doesn't immediately clear the line if the other party stays connected. If you're worried, call back from a different phone, or wait a minute and confirm you hear a dial tone first.

2. A code word agreed in advance

For family, this is the highest-value thing you can set up, and it takes one conversation. You agree — in person, not over text — on a short phrase. If someone calls claiming to be a relative in trouble, you ask for the phrase.

This matters more than it used to. A voice on the phone is no longer strong evidence of who is speaking; a short clip of someone's audio is enough to produce a convincing imitation. A code word doesn't care how good the voice is.

Choosing one: pick something that has never appeared on social media and isn't guessable from your family's public life. Not a pet's name, not a street you lived on, not a child's school. Two unrelated words work well. Say it out loud a few times so it's actually memorable under stress — a code word nobody can recall during a panicked call is not a code word.

Agree on the other half too: if the caller can't give the phrase, the call ends. No exceptions, no matter how urgent it sounds. Urgency is the pressure that makes these calls work, and deciding the rule in advance is what lets you hold to it.

3. A time-limited phrase both sides read aloud

The limitation of a fixed code word is that it's fixed. Once it's been said on a call someone else overheard, or written into a text thread, it's weaker.

The stronger version generates a fresh phrase for each conversation, shows it on both people's screens at the same moment, and expires it after a minute. Both sides read it aloud; if the words match, you're talking to the person you think you're talking to. If they don't, you hang up.

This is the approach SimplyAuth uses, and I'll be straightforward that it's the piece I built. It requires both people to have the app, which makes it a fit for the handful of people you exchange sensitive information with regularly — a parent, an accountant, a business partner — and not for a cold call from a stranger. For a cold call, method 1 remains the right answer.

Do this with your family this week

If you take one action from this page, make it this conversation. It takes five minutes:

  1. Agree on a code word with your parents, your partner, and your adult children. In person.
  2. Agree on the rule: no phrase, no money, no information, call ends. Say explicitly that nobody will be offended by being asked.
  3. Say the quiet part out loud: "If I ever call you sounding panicked and asking for money urgently, ask me for the word." Naming the scenario in advance is what makes it recognisable later.
  4. Write down the call-back rule for anyone who might get an official-sounding call: hang up, find the number yourself, call back.

Older relatives are targeted disproportionately with exactly this kind of call, and the framing that lands best is usually not "you might get scammed" but "let's set up a thing so you never have to figure it out in the moment."

Once you know who you're talking to

Confirming identity is the first half. The second half is what you do next — because the moment someone is verified, people tend to text the account number, or email the document, and it sits in a thread on somebody's servers indefinitely.

Whatever tool you use, the principle is the same: send sensitive details through something that encrypts them and doesn't keep them afterwards. SimplyAuth does this, and so do one-time-link features in the major password managers. Any of them beats a text message.

I'm Kevin — I build SimplyAuth, which does the time-limited shared phrase described in method 3, and I answer the support email myself. I've tried to keep this page useful whether or not you ever install it: the call-back method costs nothing, needs no app, and defeats the large majority of these calls. Use that first.

Questions about how the verification works? The FAQ covers it in detail.