Bankinter text or call saying your account is blocked, what to do

How to spot the text or call impersonating Bankinter, what to do in the first hours if you gave your codes and when the bank must refund the money.

Two Bankinter customers receive the same message and both end up with an empty account, but only one of them has a straightforward claim against the bank. The first taps the link, types his credentials into a website that imitates the bank’s, and when the confirmation code arrives he enters that too. The transfer is ordered by the fraudster using those credentials. The second receives a call from someone claiming to be from the security department, is told that his account has been compromised and is persuaded to move the money himself to a “safe account”. Under the Criminal Code both are victims of fraud under article 248, with the same penalty for the perpetrator. Under payment services regulation they are not in the same place. In the first case the customer did not authorise the transaction and the bank is legally obliged to refund it. In the second the bank will argue that the account holder gave the order himself, with his own signature and from his own device, and the claim becomes far more contested. What tips the balance is who executed the payment order and what the bank did when it saw it go through. That detail, which customers tend to regard as secondary, decides a large part of the outcome.

How to recognise the message impersonating Bankinter

The messages in circulation follow a pattern with few variations. They warn you of a login from a device you do not recognise, of a charge for a specific amount you did not make, of a transfer pending confirmation or of your account having been blocked for security reasons. In every case they offer a quick way out. A link, almost always shortened or on a domain that is not bankinter.com, or a phone number you must call immediately to “verify your identity”. Bankinter has sent nothing. It is the impersonated institution, and that determines who you report and who you claim against.

The three names you will see in the news describe the same scam through different channels. Phishing is the email with a link to a fake website. Smishing is the same by text message. Vishing is the phone call in which someone passes himself off as the bank. The usual pattern now is a combination. The text arrives, you do not tap, and a few minutes later a supposed employee calls who already knows your name and refers to the message you have just received. The coordination between the two is what makes the whole thing believable.

Why it looks real

The sender of a text message can be forged. Fraudsters configure the send so that the message shows the bank’s name as sender, and your phone groups it in the same thread as the bank’s genuine notifications. That the fake message sits between two real ones says nothing about its authenticity. Something similar happens with calls, because the number on screen can also be spoofed. The caller uses the bank’s vocabulary, knows your name and sometimes the last digits of your card, obtained from earlier data leaks or from the very fake website you have just typed into. On top of all this comes urgency. You are told the money will leave in minutes unless you act, and under that pressure most people do what they are asked. The method is designed to work on ordinary people in an extraordinary situation.

What no bank ever does

This rule applies across all Spanish banks and serves to decide on the spot. No bank asks you by phone, text or email for your full access password, or for the one-time code that has just arrived, or for the full card details with expiry date and security code. No bank asks you to move your money to a “safe account” to protect it, because no such account exists at any bank. No bank asks you to install a remote control application on your phone or computer so that a technician can “check” your device. Any one of those requests, on its own, identifies the call as a scam. That is enough to hang up, and there is no need to argue with the person on the other end.

What to do when you receive it

Do not tap the link or call the number in the message, and do not return the missed call. If you are unsure whether the account really has a problem, call the number on the back of your card or open the bank’s official app, which is where genuine alerts appear. Keep the text without deleting it, with the sender’s number or name and the time, and take a screenshot. Even if you did not fall for it, that message will be useful if days later you receive a call that ties in with it.

If you already gave your codes or made a payment

The first hours decide how much money is recovered and how easily. Call the bank through the official channel, report what happened, ask for your cards and online banking access to be blocked and change every password from a device other than the one you used to tap the link. If you installed an application at the caller’s request, uninstall it before touching anything else and treat that phone as compromised until someone checks it. Review the movements on all your accounts, not only the one they mentioned, including credit cards and pre-approved loans, because fraudsters frequently take out a quick loan and transfer it in the same session. Note every transaction you do not recognise with its amount, time and recipient.

Then keep everything. The text, screenshots of the fake website if you have them, the call log with number and duration, any emails received afterwards and the confirmation messages the bank sent you. Do not delete anything from the phone even if it embarrasses you. That evidence is what allows the sequence to be reconstructed and shows that you did not order the payment.

Payment services regulation obliges the bank to refund transactions the customer did not authorise. The bank may refuse if it considers the customer acted with gross negligence, and that is the standard reply in these cases, on the argument that it was you who entered the codes or made the transfer. Whether that argument succeeds depends on how the facts unfolded and on how the claim is framed, and that is the lawyer’s job. At the firm we do this within our cybercrime practice, and I have explained in more detail what the bank is obliged to refund in this article on bank refunds after phishing.

The criminal route and what the police report adds

Whoever emptied your account has committed fraud under article 248 of the Criminal Code, punishable with six months to three years in prison, or with a fine where the amount defrauded does not exceed 400 euros. Deception through a fake website or a call impersonating the bank fits the offence without difficulty. The criminal classification does not change with the method, but your position against the bank does, as the table shows.

Situation Who executes the transaction Criminal classification Against the bank
You tap the link and type codes into the fake website The fraudster, with your credentials Fraud, article 248 Criminal Code Unauthorised transaction, obligation to refund
You are called and transfer the money yourself to a “safe account” You, deceived Fraud, article 248 Criminal Code The bank will argue you authorised it and the claim is contested
You install a remote control app and the fraudster operates from your phone The fraudster, from your device Fraud, article 248 Criminal Code Contested, the bank will allege gross negligence
Amount defrauded not exceeding 400 euros Any of the above Fraud punishable with a fine Same obligation to refund if you did not authorise it

The report is filed at any National Police station or Guardia Civil post, and the sensible choice is to do it where you live, which is where the loss occurred. Bring the documentation I have just described. The report does not get your money back by itself, but it does things you cannot do on your own. The bank will ask for it in order to process your claim. The court can require the receiving bank to identify the holder of the destination account and order the balance to be frozen if anything is left. And it fixes the date and the facts in an official document, which carries weight when months later the bank disputes your version.

The usual outcome is that the investigation is shelved because the perpetrator operates from outside Spain or the money trail is lost in third-party accounts. That closure does not affect your right against the bank. The claim for the unauthorised transaction does not depend on anyone being convicted, and in this other article I explain how the two routes fit together.

The risk of ending up as a money mule

Part of the money from these scams passes through the accounts of private individuals who have lent them in exchange for a commission or who have accepted “a job” consisting of receiving transfers and forwarding them. Whoever does that, even without taking part in the deception, is the first identifiable link in the chain and risks being investigated on the strength of the victim’s report. If someone has asked to use your account to receive a payment that is not yours, do not do it, and if you already have, speak to a lawyer before the police call you in.

What we do at the firm

People who claim on their own tend to make two mistakes that cost money. The first is to accept as final the bank’s letter attributing the transaction to their negligence, when that letter is only the start of the discussion. The second is to describe the facts in a way that reinforces the bank’s version, because the customer, with the best of intentions, explains what he did without noting what the bank should have done and did not. In a case like this, at the firm we review the full sequence of the scam and the transactions, file the report with the evidence in order and pursue the claim against the bank as far as necessary, within our cybercrime practice. You can call +34 677 841 007 or write through the contact page. When you call, have to hand the screenshot of the text with sender and time, the call log, the list of unrecognised transactions with amount and date, the bank’s reply if you already have it and the police report if you have already filed it.

Frequently asked questions

Will Bankinter refund my money if it was me who entered the codes on the fake website?

The fact that you typed the codes does not mean you authorised the transfer. The payment order was given by the fraudster using credentials obtained by deception, and under payment services regulation that transaction is unauthorised and the bank must refund it. The bank will try to attribute gross negligence to you for entering the details, and that is where the case is argued on the specific facts and on the evidence you have kept.

Do I have to report to the police before claiming from the bank?

The police report and the claim against the bank are independent, but it is advisable to report as soon as possible. The bank usually asks for the report in order to process the refund, the court can identify the destination account and freeze the balance, and the report leaves an official record of the date and the facts. If the criminal case is later shelved, that does not affect your claim against the bank.

What if the fake text arrived in the same thread as the official messages or the call came from the bank’s real number?

That happens because the sender of a text and the number of a call can both be spoofed, and it does not mean the bank was involved or that the message is genuine. For the purposes of your claim it is a favourable fact, because it explains why the deception was credible and makes it harder for the bank to attribute gross negligence to you. Keep the whole thread without deleting anything.

Is it worth claiming for 3,000 euros, and do I need a lawyer?

It depends on the method. If you typed the codes into a fake website and the fraudster made the transfer, the claim has a solid basis and for 3,000 euros it is worth pursuing with a lawyer, because the bank will reply with a legal letter and you need to answer in the same terms. If it was you who made the transfer to the safe account, the matter is more contested and the evidence has to be assessed first. For amounts of a few hundred euros the sensible course is to exhaust the complaint with the bank itself and not go to court, unless there are several transactions or a loan taken out in your name.