Text or call “from Kutxabank” saying your account is blocked, what to do

How to spot the text or call impersonating Kutxabank, what to do in the first hours if you gave your credentials or made a payment, and when you need a lawyer.

For the bank to refund the money, the transaction has to be unauthorised, and that requirement decides most of these cases. Spanish payment services regulation obliges the bank to reimburse what left the account without the customer’s consent. If the fraudster logged in with the credentials you typed into a link and ordered the transfers himself, you did not authorise the transaction. If it was you who sent the Bizum or the transfer to a “safe account” because a voice claiming to call from Kutxabank told you to, you ordered the transaction, deceived though you were. Both are fraud under criminal law. Against the bank they do not carry the same weight, and a good share of the claims that get rejected fail because the victim tells the story without separating one from the other and, when it comes to proving it, has already deleted the message and cannot remember the number the call came from.

Kutxabank is the impersonated institution here. The messages and calls do not come from it, and what I explain applies to any Spanish bank, because the pattern is the same under one logo or another.

How the scam arrives

The message warns that your account has been blocked, that a charge you do not recognise has been made for a specific amount down to the cents, or that someone has logged in from a new device, and asks you to “verify your identity” by tapping a link. The link is shortened or leads to a domain that resembles the official one without being it. The site that opens copies the online banking design and asks for your username, password and sometimes your card number. The moment you enter the details, the fraudster has them.

The most effective variant combines the text with a phone call. Minutes after you have tapped the link, or even if you have not, someone calls claiming to be from the bank’s fraud department. They know your name and part of your details, and they explain that someone is trying to rob you and that, to stop it, they need the code that has just arrived on your phone. That code is the confirmation of a transfer the fraudster has already set up with your credentials. In other versions they ask you to move your balance to a “safe” account they dictate, or to install a “security” app that in fact hands control of your phone to a third party.

Variant How it presents itself What it is after Who orders the transaction
Text with a link Notice of a blocked account, unrecognised charge or new device, with a shortened link or a non-official domain Getting you to type username and password into a copied site The fraudster, using your credentials
Call from a fake employee Someone claiming to be from the fraud department, who knows your details, asks for the code you have just received The code that confirms a transaction already set up The fraudster, using the code you read out
Text followed by a call First the alert message, shortly afterwards the call “to help you” Credibility, and with it your credentials or code The fraudster
Move to a “safe account” You are told your account is compromised and must move the balance to another they give you Getting you to make the transfer yourself You, deceived
Remote access app You are asked to install a programme to “check” your phone Seeing your screen and operating in your name The fraudster, from your own device

The last column is the one that matters afterwards. When the fraudster ordered the transaction with credentials or codes obtained by deception, it is an unauthorised transaction. When you ordered it yourself, it is fraud on an authorised transaction, and the route to recovering the money is a different one.

Why it looks genuine

The sender of a text message can be spoofed, so the message appears on your phone in the same thread as the genuine alerts the bank has sent you for years. The number displayed on the call can also be manipulated to match one published on the bank’s website. The personal details the caller knows, your name, part of your ID number, the last digits of a card, come from earlier data leaks and serve to remove your doubts. The amount of the supposed charge is specific and the urgency is deliberate, because the aim is to make you act before you think. And when the call comes right after you have entered details on the fake site, the fraudster knows you are already primed to believe him.

What no bank ever does

No Spanish bank asks for your full access password by phone, text or email. None asks for the confirmation code sent to your phone, because that code exists precisely so that nobody but you knows it. None tells you to move your money to another account to protect it. None asks you to install a remote access app. None sends a link to “unblock” your account or “verify” your identity. If you are ever in doubt about a communication, hang up and call the number on the back of your card or inside the official app yourself. If the call was genuine, you will have lost nothing.

What to do in the first hours

The first thing is to cut off contact with whoever is calling you and not to ring that number back. Then call the number on the back of your card or inside the official app, report what has happened and ask for your cards and online banking access to be blocked. The sooner that report is on record, the better for you.

Keep everything. Take screenshots of the text showing the sender, date, time and link, and do not delete the message. Note the number the call came from and the time, and keep your call log. If you installed any app, disconnect the phone from the internet and do not use it for banking until someone you trust has checked it. Change your passwords from another device.

There are two things you must not do. Do not engage with anyone who calls in the following days offering to “recover” your money, because that is the second phase of the same scam. And do not sign or accept any document in which you acknowledge having authorised the transactions or having been careless without a lawyer reviewing it first, because that paper will weigh against you later.

If you have already given your credentials or made a payment

This is where the distinction from the opening comes back. When the transactions were executed by the fraudster with the credentials or code you handed over under deception, payment services regulation requires the bank to refund unauthorised transactions. The banks’ usual reply is that the customer handed over their credentials and that this amounts to gross negligence, on which basis they refuse to reimburse. Whether that argument succeeds depends on the specific circumstances and on how the claim is framed, which is the lawyer’s job. I have covered this in more detail in what the bank must refund after a phishing attack and in bank impersonation scams and what to do.

When it was you who ordered the transfer or the Bizum to the account they dictated, the transaction is authorised and the bank does not have the same refund obligation. There is still a way forward, because the money has gone to an identifiable account and because the way the banks reacted to warning signs of fraud can also be examined, but it is a longer road and needs to be set up properly from the start.

At the firm, when someone arrives at this point, we look at how the money left and what evidence exists, and we run the claim against the bank and the criminal complaint in a coordinated way so that they do not contradict each other. You can see how we handle these matters under cybercrime.

The offence of fraud, the complaint and the limitation period

The conduct falls under Article 248 of the Spanish Criminal Code, which defines fraud and includes fraud committed through computer manipulation or using another person’s credentials. The penalty is imprisonment of six months to three years. If the amount defrauded does not exceed 400 euros, it is a minor fraud and the penalty is a fine. Basic fraud becomes time-barred after five years and minor fraud after one year, counted from the date it was committed.

The complaint can be filed at any National Police station or Guardia Civil post, and also at the duty court. The fraudster usually operates from outside your city and sometimes from outside Spain, but that does not force you to travel. The investigation as a general rule ends up before the courts of the place where the loss occurred, which usually coincides with the town where your account is held.

It is worth knowing what the complaint is for, because most of these cases are closed without identifying the perpetrator. The complaint puts the facts and the date formally on record, allows the court to ask the banks for the identity of the holder of the account that received the money and to order it frozen if any balance remains, and proves to your own bank that you were the victim of a crime. Closure of the criminal case for failure to find the perpetrator does not end the claim against the bank, which follows its own course.

If the money passed through your account

These frauds need accounts to receive the money and to forward it from. Anyone who agrees to receive a transfer from a stranger and pass it on elsewhere in exchange for a commission, often after a supposed job offer, ends up identified as the holder of the receiving account and charged with money laundering, which is punishable even when committed through gross negligence. If that is your situation, or if you have been summoned over it, you need a criminal defence from the first statement, and what you say without a lawyer can fix how the facts are classified.

Those who claim on their own tend to accept the bank’s first refusal as final, to describe the facts one way in the criminal complaint and another in the claim, and to lose along the way the message and the number that proved the deception. At the firm we act for victims of bank impersonation and provide criminal defence to those who have ended up flagged as the receiving account, and we run the claim against the bank and the criminal complaint in a coordinated way. You can see what we do under cybercrime and criminal law, and reach us on +34 677 841 007 or through our contact page. When you call, have to hand the account statements with the date and amount of each transaction you do not recognise, the screenshots of the text and of the number the call came from, the criminal complaint if you have already filed it, and the bank’s written reply if you already have one.

Frequently asked questions

I read out the SMS code over the phone to someone claiming to call from Kutxabank and transfers were made, does the bank have to refund me?

The transaction was ordered by the fraudster using a code obtained by deception, so it is an unauthorised transaction and payment services regulation obliges the bank to refund it. The bank almost always replies that you handed over the code and that this amounts to gross negligence. Whether that argument succeeds depends on the specific circumstances of the call and on how the claim is framed, so the refund is not automatic and the bank’s refusal is not the last word either.

Do I have to report it to the police before claiming from the bank, and is it any use if they never catch the fraudster?

You should report it as soon as possible and notify the bank the same day, without waiting for one to finish before starting the other. The complaint puts the facts formally on record, allows the court to identify and freeze the account that received the money, and proves to your bank that you were the victim of a crime. Most of these cases are closed without identifying the perpetrator, and that closure does not harm the claim against the bank, which follows its own path.

If you entered no details and installed nothing, there is no transaction to claim for. You can report the attempt to your bank on the number on the back of your card or inside the official app, and notify INCIBE on the 017 line, which collects these reports. Check your account movements over the following days and delete the message only once you are sure nothing has happened.

Is it worth claiming with a lawyer or can I do it myself?

If the amount is a few hundred euros and the bank refunds you on first contact, you do not need a lawyer. You do need one when the bank rejects the claim alleging negligence, when it was you who made the transfer or the Bizum under deception, when the amount matters to your finances, or when you have been summoned as the holder of an account that received money from a fraud. In those cases, how the facts are described and what evidence is put forward from the start conditions the outcome.