The caller knows your address and ID number? That still does not prove they work for your bank
Real personal details may come from a breach and make a false story convincing. Do not confirm more information — end the call and return through a trusted channel.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 15 September 2026
- READING TIME
- 8 min read
- TOPIC
- Identity and Access
A “bank employee” calls and immediately gives your name, address, national ID number or the last digits of a card. The conversation does not begin with a question. It begins by demonstrating that the caller already knows something. It is easy to conclude that access to the data proves the call is genuine.
That is the wrong test. Personal details can come from an earlier breach, document, form, public register or another scam. A true fact about you does not establish the identity of the person saying it.
Do not correct or complete the scammer’s story
The caller may deliberately provide incomplete information: “I can see a card ending in 12; please confirm the other two digits.” They may ask for a security answer, current bank, transfer limit or text-message code under the guise of verification.
Do not confirm that the address is current, that you bank with the named company or that you are currently abroad. Each answer can complete the profile and prepare a more convincing second attempt.
Say only that you will contact the organisation yourself, then end the call. Open the bank’s app or call a number printed on the card or found on an official website you entered yourself. Do not return the call from recent history or use a number texted by the caller.
A text-message code does not identify the agent
A one-time code normally approves a particular action: a sign-in, settings change, new device or payment. Read the entire message. If you did not start the operation described there, do not enter the code or read it over the phone.
A genuine employee may have access to some customer information, but a safe process does not require them to take over your banking session. Do not install remote-access software, share your screen or move money to a “technical” or “safe” account.
If a stranger genuinely has your information
Record the phone number, time, information quoted and organisation being impersonated. Report the attempt to the real bank or company through its official channel. Use your country’s national cybercrime reporting service for suspicious messages and links.
For people in Poland, the government provides a free service to reserve a PESEL national identification number through the mObywatel app, Gov.pl or a municipal office. The service also provides a history of checks against that number. Other countries have different identity-theft protections, so use the relevant official service where you live.
If you disclosed a password, change it on the genuine site and close unfamiliar sessions. If you shared card details or approved an operation, contact the bank immediately. A caller knowing some information does not automatically mean every account is compromised; base the response on what was actually disclosed or authorised.
Workplace verification cannot rely on the caller’s knowledge
At work, a scammer may know a manager’s name, contract number, supplier or project. Such details may be public or widely exchanged between business partners. Employees need permission to end the call and return through the corporate directory, ticketing system or an established contact.
Security questions based on personal facts are weak when their answers may have leaked. Financial instructions and access changes need an independent process, not more information exchanged within the same call.
What the sources confirm and what Breachroad recommends
Poland’s Financial Supervision Authority advises people in its cyber-fraud guidance to remain cautious even when a caller knows a name, card number, PESEL or address. On 17 August 2026, Poland’s Ministry of Digital Affairs reiterated that a PESEL can be reserved free of charge in the app, through Gov.pl or at a municipal office, and recommends keeping it reserved by default.
Breachroad’s conclusion is to separate two questions: “Is the information true?” and “Is the caller who they claim to be?” The first answer can be yes while the second remains unknown. Our identity-theft response guide covers further protective steps. Teams can practise calmly ending and independently verifying suspicious contact through cybersecurity awareness training.


