Hi everyone, it feels like scam texts are becoming rampant again lately. Several of my friends who bank with Santander and BBVA have received messages saying ‘su cuenta ha sido bloqueada’ (your account has been blocked) and almost clicked on the link. I thought it would be a good idea to create a post summarizing the latest common bank scam tactics to give everyone a heads-up.
SMS Phishing (Smishing)
This is the most classic and common tactic, often related to [frozen bank accounts]. Scammers will impersonate your bank, such as CaixaBank, ING, etc., and send you a text message. The content is usually something like ‘Suspicious login detected,’ ‘Your account has been suspended,’ or ‘You have a transaction to confirm.’ The message includes a link that looks very similar to the bank’s official website but is actually a phishing site.

Never click it! Once you click the link and enter your username, password, or mobile verification code, your account is at risk. The correct course of action is to click the link to verify ignore and delete the message directly, or open your bank’s official app or website yourself to check.
Phone Scams (Vishing)
This is the ‘upgraded version’ of SMS scams. Scammers might first send you a phishing text. Once you take the bait, they will call you, posing as bank customer service. They can even use technology to make the caller ID display the bank’s official number! On the phone, they’ll use very professional-sounding jargon, create a sense of urgency, and pressure you into providing personal information or verification codes to ‘cancel a non-existent transaction’ or ‘unblock your account.’ Remember, bank customer service will never call you to ask for your full password or verification codes.
How to Identify and Prevent Them
I’ve put together a simple table to help you quickly identify these scams, with some insights from experiences with frozen Spanish bank accounts:
| Scammer’s Tactics | What Your Bank Will Actually Do |
| Asks you to log in via a link in a text/email | Unlike physical [bank robberies], for digital security, you should always log in only through the official app or website. |
| Asks for your full password or verification codes over the phone | Will never ask for this sensitive information |
| Creates a sense of urgency, pressuring you to act immediately | Will give customers enough time to handle issues |
| Link URLs have strange spellings | The official website address is always correct |
Everyone must remember one principle: Never log into your online banking through a link in a text message or email! No matter how authentic it looks. If you encounter any uncertain situation, hang up the phone immediately and then go to the bank’s official website or call the customer service number listed there to verify. I hope everyone can protect their finances. Feel free to share any scams you’ve encountered below!