'Your bank is calling' — vishing and caller-ID spoofing
A call from the bank's number, a calm 'consultant' and a supposed break-in on your account. We break down the fake-bank-employee scam and how to stop it.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 1 June 2026
- READING TIME
- 6 min read
- TOPIC
- Human Security
Your phone rings. On the screen — the number of your bank’s hotline. A friendly “consultant” informs you that an unauthorised transaction attempt has been detected and your funds “need securing”. This is vishing — voice phishing — and one of the most dangerous scams, because it plays out live, under pressure, with the criminal in full control of the narrative.
Caller-ID spoofing: why your bank shows up
Just like with SMS, the calling number can be faked. The criminal arranges for your phone to display the real number of a bank, the police or the prosecutor’s office. This is the strongest social-engineering element — we see a known number and trust it automatically. That’s why the number on the screen is not proof of the caller’s identity.
The recurring scenarios
- The “bank employee” — “we’ve detected a break-in; to save your money, transfer it to a technical / safe account”. The “technical” account belongs to the criminal.
- The “police / CBŚP officer” — “you’re taking part in an operation to catch a dishonest bank employee; please cooperate and keep it confidential”. The secrecy cuts the victim off from the loved ones who might snap them out of it.
- Installing a “security app” — in reality a remote-access tool that hands the screen and banking to the fraudster.
The common denominator: pressure, secrecy and haste. The criminal gives no time to think and keeps the victim on the line so they can’t verify the story.
The rules that defuse vishing
- A bank never asks you to transfer money to a “safe account”, for your full password or card PIN, or to install a remote-access app. Ever.
- Hang up and call back on the number from the back of your card or the bank’s official site — typed in manually, not “call back” from your call history. A real bank will understand.
- No genuine institution requires secrecy from your family. A request for discretion is an alarm signal.
What to do in practice
If you get such a call: don’t share any details, end the conversation and call the bank yourself. Don’t install anything at the caller’s instruction. If you’ve already shared details or installed an app — immediately disconnect the device from the network, call the bank from another phone and block access.
In organisations, it’s worth training finance teams on second-channel verification for any unusual phone instruction — the same discipline that protects against phishing. Spoofing technology is cheap and available; the only effective defence is a habit: don’t trust the displayed number, call back yourself.
Want to see how your finance team would react to such a call? We run controlled social engineering tests and training — get in touch.
What KNF confirms about vishing
Poland’s financial regulator describes vishing as telephone fraud often using caller-ID spoofing and impersonation of a bank, public authority or police. A displayed number is not identity proof. The script commonly creates pressure around a transfer, loan or account compromise, then asks for an action that gives the attacker data or control.
Not every bank call is fraudulent. Perform no high-risk operation during that conversation; end it and contact the institution independently.
What a bank does not need
An employee does not need your complete password, BLIK code, card PIN or approval code for an operation you did not initiate. They do not need remote-access software or a transfer to a “technical account”. An app prompt describes the transaction—read it rather than treating the code as caller verification.
Breaking the attack
- Do not confirm data or open an SMS link sent during the call.
- Hang up without negotiating.
- Call the number on the card, official app or manually entered website.
- Review transactions and active devices.
- Report the number and script to the bank and relevant authorities.
If remote-access software was installed, disconnect the device, do not use it to reset passwords and call the bank from another phone.
Vishing in organisations
Telephone instructions involving payment, employee data or supplier changes require a second channel and a record in the business system. Finance teams need authority to refuse. An exercise measures hang-up, callback, escalation and documentation, not memorisation of suspicious phrases.
Sources: KNF — Vishing, CISA — Recognize and Report Phishing.


