A text lands in the very same thread where your bank really does send you its codes: “We have detected unauthorised access to your account. Verify your identity here,” and below it a link. With the bank’s name as the sender, arriving mid-afternoon between one errand and the next, almost no one hesitates. And that is the problem: whoever signed the message is not your bank, but someone who has impersonated it so that you are the one who opens the door for them.
It is the pattern we see most often at our firm these days. It is worth putting a name to what is happening and, above all, knowing what to do in the first few minutes.
Smishing, vishing, phishing: the same trick through three doors
Behind the three words lies a single idea: impersonating a trusted organisation so that you hand over your login details or authorise a transaction believing you are dealing with someone you are not.
- Smishing: the text — or the WhatsApp message — that impersonates your bank, Correos or the tax office and pushes you towards a link.
- Vishing: the call from a supposed employee of the “security department” pressing you to confirm details or to move your money “to a safe account”.
- Phishing: the email with the copied logo that takes you to a website identical to the real one.
The medium changes; the trap is the same. And increasingly they come chained together: first the text and, minutes later, the call from the “adviser” that lends credibility to the earlier message.
Why it works, and why it is not going away
It is not the victim’s carelessness. The deception is designed to work: the message lands in the bank’s genuine thread, the copied website is indistinguishable from the real one, and the call rushes you so there is no time to think.
The official figures show the scale of it. Spain’s security forces recorded 464,801 cybercrimes in 2024, and almost nine in ten — 412,850 — were computer fraud, that is, scams; the number of victims topped 350,000 (Ministry of the Interior, Report on Cybercrime in Spain 2024). INCIBE, for its part, points to identity impersonation as the most significant problem of the year: of the almost one hundred thousand enquiries handled by its 017 helpline — 21.8% more than the year before — 14% had to do with precisely that, impersonation (INCIBE, Cybersecurity Review 2024). In plain terms: it will reach you, if it has not reached you already.
The signs all these scams share
The sender changes, so does the pretext and the brand being impersonated, but the skeleton is always the same. If you recognise several of these signs at once in a message or a call, go no further:
- Urgency with a clock on it. A short deadline, a “final notice”, something you lose if you don’t act now. It is not there by accident: it is there so you have no time to check.
- A channel they choose. The link in the message, the number calling you, the app they want you to install. Never a channel you open yourself.
- A request no organisation makes. Your passwords, your PIN, the CVV, or the one-time code that has just arrived on your phone.
- A pretext that sounds like a rescue. Protecting your money, unblocking your account, cancelling a charge. They place themselves on the side of the person solving your problem.
- One true detail that lends credibility. Your name, the last digits of your card, a delivery you really are expecting. It usually comes from leaks that have nothing to do with the organisation, and it proves nothing.
On their own, none of them prove much. Together they describe exactly how the deception works.
What to do right now
If you have just received the message or the call and have not yet given anything away:
- Never give out your passwords, your PIN or the one-time codes (OTP) that reach you by text. Your bank will never ask you for them by phone or by message; anyone who does is impersonating it.
- Do not click the link or open the attachments. The address may look legitimate and not be.
- Hang up and call them yourself, using the number on the back of your card or through the official app. Do not carry on the conversation they have started, and do not call back the number that shows on your screen.
- Report it to the Policía Nacional or the Guardia Civil. It is the first formal step and stops the matter fizzling out into nothing.
- Keep all the evidence: screenshots of the text or the email, the number that called, the website and any activity on your account. The sooner you save it, the better.
If you have already given away details or made a payment
Here the advice changes, and it is blunt: do not write it off and do not sit still. The sensible thing is to put yourself as soon as possible in the hands of a solicitor who specialises in cybercrime, one who can look at your particular case and act with the speed the situation demands.
At our firm in A Coruña we handle this kind of matter every day. You can see how we work on our cybercrime page and write to us without waiting from our contact page. If one thing matters when this happens, it is not letting time slip by.
Can the money be recovered?
This is the question that really matters once it has happened, and the honest answer is that in many cases it can. The payment services rules start from a premise that works in your favour: a transaction you did not authorise is one that must be refunded, and it is not for you to prove you did not consent to it — it is for the bank to show it was properly authenticated. Being tricked by a third party into typing in your credentials is not, without more, the same as authorising anything.
What you will hear when you call the bank is almost always the opposite, and the word that will come up is “negligence”. That is where the matter is decided. We go into it in detail in does the bank have to give my money back after a phishing scam?.
The types we are seeing most
The same criminals reuse a handful of scripts and adapt them to whichever organisation they are impersonating. These are the specific cases that bring us the most enquiries:
Banks impersonated
- The text impersonating Abanca: the “blocked” account and the link that takes your credentials.
- “A call from Abanca”: the fake security department that asks you to move your money.
Delivery companies impersonated
- The text posing as Correos: the “held” parcel that ends up costing you your card details.
Frequently asked questions
How do I tell a genuine message from my bank apart from a fake one?
Be wary of any message that rushes you, that asks for passwords, PIN or one-time codes, or that includes a link to “verify” or “reactivate” your account. Your bank never asks for that information by text, email or phone. When in doubt, click nothing: close the message or hang up and call yourself using the number on your card, or go in through the official app.
Is what has happened to me a criminal offence?
Yes. Impersonating an organisation in order to deceive you and get hold of your money or your data amounts, depending on the case, to the offence of fraud and other offences under the Criminal Code. The fact that the amount is small, or that it was only an attempt, does not make it a minor matter: it is worth reporting and putting on record.
I have already given out my details or made a transfer — is everything lost?
Do not write it off. Gather and keep everything that documents what happened as soon as you can — screenshots of the message, the number that called you and the activity on your account — and put yourself in the hands of a solicitor who specialises in cybercrime who, with that evidence in front of them, can examine your case and decide the steps to take.
Is it worth going to a solicitor?
Yes, and it is not something to put off. A specialist solicitor works out in legal terms exactly what has happened, puts the evidence in order and steers the matter down the appropriate channel, so that you stop moving blind and know what options you have.
Can I get back the money that was taken from me?
In many cases, yes. The payment services rules require transactions you did not authorise to be refunded, and it is for the bank to prove the transaction was properly authenticated and consented to, not for you. We cover it in full in does the bank have to give my money back after a phishing scam?.
The bank says I was negligent and will not refund anything — is that the end of it?
No. That answer is the usual one and it does not close the door. A lapse is not gross negligence, and falling for a well-built deception does not automatically make you responsible for what happened. Before writing the money off, it is worth having a solicitor look at your case.