CaixaBank text or call saying your account is blocked: what to do

A text or call impersonating CaixaBank, blocked account or unrecognised charge. How to spot it, what to do today and when the bank must refund the money.

You receive a text that appears to come from CaixaBank, tap the link, enter your password on a page that mimics the bank’s, and within minutes someone orders a transfer from your account that you never wanted to make. Someone else receives the same text, is then called by a supposed employee of the bank and, following his instructions, is the one who moves the money to a «safe account» to «protect the savings». For the Spanish Criminal Code both situations are fraud under article 248. For the bank they are different things, and on that difference depends whether the refund is a clear legal obligation or a contested dispute. In the first case the transaction is unauthorised, because you did not order it even though the fraudster had your credentials, and payment services legislation obliges the bank to refund unauthorised transactions. In the second, you signed the transaction with your own code, and the bank will argue that it was a valid instruction even if obtained by deception. What tips the balance is who gave the order and what the customer knew at that moment. That is why it pays to reconstruct precisely what happened before writing anything off.

How the text impersonating CaixaBank works

CaixaBank is the impersonated bank. It does not send these messages and plays no part in them. The fraudster uses a bulk messaging service that allows the sender name to be faked, which is why the text lands on your phone inside the same thread as the bank’s genuine alerts. The phone groups messages by sender name, not by real origin, and that technical detail is what gives the fraud its appearance of authenticity.

The content follows a pattern that repeats with few variations. A charge or transaction you do not recognise, your account or card blocked for security, a new device linked to your access, or a request to verify your identity. Many messages include the name of the official app, CaixaBankNow, precisely so that the reader associates the alert with the application already installed. They all end the same way, with a shortened link or a domain that resembles the official one but is not, and a short deadline to act. The page the link leads to reproduces the bank’s design and asks for the user number, the full password and, in many cases, the code that then arrives by text.

The second phase is the call. Once the fraudster has your details, or even before, you are phoned by someone who introduces himself as a member of the security department. The number on your screen may have been manipulated to match one of the bank’s, and the caller knows your name and some of your details because you have just typed them into the fake site. He tells you suspicious transactions are under way and that your cooperation is needed to stop them. That cooperation consists of reading out the code you receive, approving operations in the app, installing a remote-control application or moving your balance to an account he gives you.

Why it looks genuine

Three elements combined make careful people fall for it. The message arrives in the right thread, the caller has information only the bank should hold, and the story fits something we all worry about, that someone is draining our account right now. The fraudster does not ask for money, he asks for help to prevent it being stolen, and that disarms suspicion. Time pressure completes the picture. If the block is imminent, nobody stops to check the link’s domain.

What no bank ever does

This is not specific to CaixaBank. It is common to all Spanish banking and serves as an instant decision rule. No bank asks you by phone or text for your full access password. No bank asks you to read out or forward the one-time code you have just received. No bank asks you to move your money to a «safe account», because no such account exists at any bank. No bank asks you to install a remote-control application so that an employee can «check» your phone. And no bank resolves an account block through a link sent by message. If the conversation reaches any of those points, the conversation is with a fraudster, regardless of what the screen shows.

What to do right now

If you have only received the message, do not tap the link and do not reply. Keep it, because it is evidence, and report the attempt to the bank on the telephone number printed on the back of your card or from within the official app, never on the number shown in the text or by returning the call.

If you have already entered your credentials, read out a code or made a payment, the first hours decide how much money is recovered. Call the bank through that same official channel and ask for your access, your cards and any pending transaction to be blocked. Change your passwords from a device that has not been tampered with. If you installed an application at the supposed employee’s request, switch the phone off and do not use it for banking again until it has been cleaned. Gather what you have, namely the text with its sender, the number that called you, the time of the call, screenshots of the fake site if you can still see them and the statement showing the movements. File a complaint with the Policía Nacional or the Guardia Civil attaching all of it. You can do so in A Coruña even if the money went to another province or abroad, because the loss occurred here.

There are two things you must not do. Do not delete anything, neither the message nor the call log nor any emails that arrived afterwards. And do not sign or accept, in the heat of the moment, any bank document acknowledging that the transactions were ordered by you. That acknowledgement will be used against you.

What can be recovered depending on how the money left

The legal position changes with the type of transaction, and that distinction determines the strength of the claim against the bank.

How the money left Who executed the transaction Position against the bank
Card charge using details captured on the fake site The fraudster Unauthorised transaction, refund enforceable
Transfer ordered by the fraudster with your credentials The fraudster Unauthorised transaction, refund enforceable
Transfer or Bizum you made yourself to the account you were given You, under deception Authorised transaction, claim more contested
Loan or credit taken out by the fraudster using your access The fraudster Contract open to challenge, no duty to pay instalments on something you never signed

In the first two rows payment services legislation requires the bank to refund unauthorised transactions. The bank usually replies that the customer acted with gross negligence by handing over the credentials, and whether that negligence exists depends on the specific facts of each case, the content of the message, the call and how the transactions were executed. In the third row the debate is different, because the instruction came from you, and there the alerts the bank issued or failed to issue and the nature of the movements carry weight. How that claim is framed, what is demanded and on what grounds is the lawyer’s job. At the firm we practise in cybercrime and at that point what we do is fix the correct classification of each transaction and prepare the claim against the bank with the evidence you have kept. I have set out the bank’s position in more detail in bank impersonation scams and what to do and in when the bank must refund after phishing.

The criminal route, the penalty and what happens if the case is closed

Whoever runs this operation commits fraud under article 248 of the Spanish Criminal Code, punishable by six months to three years in prison, or by a fine if the amount does not exceed 400 euros. The complaint opens an investigation that usually traces the accounts the money went to and, often, the person who opened them. The organisers almost always operate from outside Spain, which is why a share of these cases ends up closed because they cannot be identified.

That closure of the criminal case does not shut the claim against the bank. They are two separate routes and the second does not depend on the first succeeding. What the criminal case does provide, even when closed, is documentation on the destination accounts and on the mechanics of the fraud, and that documentation is used afterwards.

There is a further risk for anyone who, without being the victim of the text, has lent their account to receive money and forward it in exchange for a commission. That person, the money mule, is the only one identifiable within Spain and ends up investigated for money laundering even if they say they did not know where the money came from. If you have received an unexpected deposit followed by a request to forward it, do not move it.

Frequently asked questions

Does CaixaBank have to refund me if my money was stolen through a fake text?

If the transactions were ordered by the fraudster using your credentials and you did not give that order, they are unauthorised transactions and payment services legislation obliges the bank to refund them. The bank may refuse on the grounds that you acted with gross negligence, and that is where the matter is decided according to what exactly happened. If you moved the money yourself following the fake employee’s instructions, the claim exists but is more contested.

I was the one who entered my details on the fake site, do I lose the right to claim?

Not automatically. Handing over your credentials under deception does not by itself amount to gross negligence, and the quality of the deception counts. A text that appears in the bank’s thread, bearing the name of the official app, followed by a call from someone who knows your details, is a fraud built so that a careful person falls for it. The bank will have to back its refusal with facts, and how it is answered is part of the claim.

Do I have to report it to the police for the bank to refund the money?

The police report is not a legal requirement for the refund, but in practice the bank asks for it and it should be filed within the first hours. It documents the fraud, allows the destination accounts to be traced and removes any doubt as to whether you consented to the transactions. File the report with the text, the caller’s number and the statement.

Is it worth claiming for 1,000 or 2,000 euros, or do I need a lawyer?

It depends on the bank’s response. If the bank refunds of its own accord within the first few days, which happens, you need nobody. If it refuses citing negligence and the amount is a few hundred euros, the cost of fighting it may exceed what you would recover, and I will tell you it is not worth it. From amounts above a thousand euros, and provided the transaction was executed by the fraudster and not by you, the claim is usually worthwhile and should be framed by a lawyer, because the first written claim shapes everything that follows.

If you claim on your own, the specific risk is twofold. You may accept in writing, without realising it, that the transactions were ordered by you, and you may let the bank set the narrative of gross negligence without anyone contesting it on the facts of the case. At the firm what we do is classify each transaction, gather the evidence of the impersonation and direct the claim against the bank, alongside the criminal complaint, as part of our work in cybercrime and criminal law. You can call +34 677 841 007 or write through contact. When you call, have to hand the undeleted text, the number and time of the call, the statement showing the affected movements, the date you notified the bank and whatever answer it gave you, and the police report if you have already filed it.