Text or call claiming to be from Banco Sabadell, the scam and what to do

How to spot the fake text or call impersonating Banco Sabadell, what to do in the first hours and what you can recover if you gave your codes or paid.

When a complaint about a text message impersonating Banco Sabadell reaches an investigating court, proceedings are opened for fraud under article 248 of the Spanish Criminal Code and the judge orders what decides the case in those first weeks. The court writes to the bank where the money landed so that it identifies the holder of the receiving account and freezes whatever balance is left, asks the telephone operator for the data behind the number that sent the message or made the call, and requires the impersonated bank to provide the technical detail of the transaction, with the IP address, the device and the exact time it was ordered. If the Policía Nacional or the Guardia Civil have acted before that stage, it is because the victim reported the same day and gave them time to request that the funds be held in the receiving account before it was emptied. That is the real course these cases take, and two separate things depend on it which must be kept apart from the outset, the prosecution of whoever committed the fraud and the recovery of your money, because they do not always come from the same place or at the same pace.

How to recognise the message or the call

The pattern repeats with few variations. A text arrives warning that the account has been blocked, that there is an unrecognised charge, that someone has logged in from a new device or that you must verify your identity to keep the service. It contains a link, almost always shortened or with a domain that imitates the bank’s name but is not the official one, and an artificial rush, a deadline of a few hours or the threat that the account will be disabled. The link opens a page copied from the bank’s own site which asks for the username, the password and, immediately afterwards, the code the real bank sends by text to sign transactions.

The second stage is the call. Someone introducing themselves as the bank’s “security department” or “fraud department” says they have detected suspicious movements and offers to cancel them. They know your name, sometimes the last digits of your card or your approximate balance, because they have just obtained it from the fake page or from an earlier data leak. With that credibility they ask for the code that arrives on your phone, suggest moving the money to a “safe account” until the danger passes, or tell you to install an application so that a technician can check your phone. That application is remote-control software and, once installed, the person on the other end operates your online banking as if they were you.

Method What they tell you What they are after
Text with a link Account blocked, unrecognised charge, new device, verify identity Your username and password on a fake page
Call from the “security department” Suspicious transactions detected that must be cancelled The signing code you receive by text
Transfer to a “safe account” Your money is at risk and must be protected That you order the transfer yourself
Remote-control application A technician needs to check your phone Operating your banking from another device
Bizum or card charge A refund is being processed or a purchase confirmed That you accept a payment request or give card details

Why it looks genuine

The sender name of a text message can be forged. That is why the fraudulent message appears on your phone within the same thread as the bank’s genuine alerts, above or below the last legitimate text, and nothing on the screen sets it apart. The same happens with calls, the number displayed may be one similar to the bank’s or a direct copy of it. Added to that, the caller already knows things about you, speaks fluently, keeps the conversation going for as long as it takes for the code to arrive and, in many cases, chooses the evening or the weekend, when branches are closed and checking is more awkward. None of this requires great technical skill, it is a well-rehearsed script, and it works on people of any age and background.

What no bank ever does

This is not a peculiarity of Banco Sabadell, which here is the impersonated bank, but a rule common to all Spanish banking. No bank asks you by phone or by message for your full access password. None asks you for the code it has sent you to sign a transaction, because that code exists precisely so that only you know it. None suggests moving your money to another account to protect it, asks you to install remote-control software, or sends you a link by text to unblock your account or verify your identity. If you receive any of these requests, hang up, do not reply to the message and call the number printed on the back of your card or found inside the official app. That call, made by you rather than answered from whoever called you, is the only reliable check.

What to do right now

If you tapped the link but did not enter anything, the risk is low. Change your password from the official app and watch your transactions for a few days. If you entered your username and password, gave the code over the phone or installed the application, act in the following order and do it within the first hours, because the money moves quickly from one account to another and every onward transfer is one more account the court will have to write to.

Call the number on the back of your card or through the official app, ask for online banking access and your cards to be blocked, and have them read out every transaction of the last few hours, including pending ones. On that same call ask that they be recorded as unrecognised and note the time and the name or reference number you are given. If you installed anything, disconnect the phone from the internet, but do not wipe it or delete the application yet, because it is evidence. Do not delete the text. Take a full screenshot showing the sender’s number or name, the date and the time, and copy the exact address of the link without opening it again. Keep your call log. Write down, while you remember, what you were told and what you did at each moment.

With that, go to the Policía Nacional or the Guardia Civil and file a report. The sooner the better, because a request to hold the funds in the receiving account only works if there is still a balance. One more warning, which we see often at the firm. In the days after a fraud, messages tend to arrive from supposed law firms or companies offering to recover the money in exchange for an advance payment. That is a second fraud on the same victim. No serious professional charges you up front for a promise of recovery.

If you have already given your codes or made a payment

Two situations must be distinguished, and the bank treats them very differently. The first is the unauthorised transaction, the one ordered by the fraudster with the credentials obtained on the fake page or through remote control of your phone, without you signing it. Payment services regulation obliges the bank to refund those transactions, and that obligation does not depend on the bank’s goodwill. In practice the bank frequently replies that the customer was grossly negligent for entering the codes on a link or giving the code over the phone. Whether that argument holds or not depends on the facts of each case, on what the bank’s own systems detected and on how the claim is framed, and that is the lawyer’s job.

The second situation is the transfer you made yourself, persuaded by the call, to the “safe account”. That transaction is authorised in the formal sense, even though the authorisation was obtained by deception, and the ground for claiming against the bank is harder, though not closed. What is examined is what the bank did when faced with a transaction that was anomalous in amount, destination and time, and what controls it had in place. What can be demanded and on what grounds I explain in more detail in bank refund after phishing and in bank impersonation scam, what to do.

In both cases there is a written claim to the bank and, if it does not refund, a subsequent route of complaint that ends, if necessary, in court. At the firm, at that point, we review the transaction and the bank’s reply and put the claim together from our cybercrime practice.

Fraud under the Criminal Code

Whoever sent you the text or called you commits fraud under article 248 of the Spanish Criminal Code, punishable with six months to three years in prison. If the amount defrauded does not exceed 400 euros, the conduct is a minor offence and the penalty is a fine. There are aggravated forms depending on the amount or the manner of commission which I do not detail here, but the base penalty is already imprisonment, and the courts join proceedings when the same organisation has defrauded many people with the same campaign, which is almost always the case with these mass text messages.

You can file the report in A Coruña even if the money ended up in an account in another province or another country. The courts’ criterion is that fraud is investigated where the victim ordered the payment or suffered the loss, and in an online banking case that is where you were and where you hold the account. The report can be filed at a police station or at the duty court, and it must include the screenshots, the link address, the statement showing the transactions and the reference of your communication to the bank.

What happens if the case is shelved and the risk of ending up as a money mule

Many of these cases end in a provisional dismissal. The holder of the receiving account turns out to be someone who lent their account for a commission, or lives outside the European Union, or the money was converted into cryptocurrency within hours and the trail went cold. A provisional dismissal does not mean there was no crime or that you were not defrauded, and it in no way prevents the claim against the bank, which runs along a different route with different rules. The case is reopened if new information appears, which happens when another victim provides a lead you lacked.

The other side of these chains is the person who received the money. If you have been offered a job that consists of receiving transfers and forwarding them, or asked to lend your account for a deposit in exchange for keeping a share, you are the mule in a fraud. Even if you do not know where the money comes from, you can end up under investigation for money laundering or for the fraud itself, with the balance seized and criminal proceedings against you. If you find yourself in that position, do not move the money and seek advice before giving a statement.

What is at stake and what we do

If you claim on your own, the concrete risk is twofold. On the banking side, replying to the bank with an explanation that admits what it should not, accepting a partial refund presented as final settlement, or letting time pass until the claim loses force. On the criminal side, reporting without the evidence that supports a freeze on the funds and watching the case being shelved within months. At the firm we file the report with the evidence in order through our criminal law practice, we claim from the bank the refund you are entitled to through our cybercrime practice and, if the bank refuses, we sue. You can call +34 677 841 007 or write through contact. When you call, have to hand the screenshot of the text with the number and the time, the statement with the transactions marked, the time and reference of your call to the bank, the bank’s written reply if you already have it and a copy of the police report if you have already filed it.

Frequently asked questions

If the transaction was ordered by the fraudster with those codes and you did not sign it, payment services regulation obliges the bank to refund the amount. The bank usually argues that the customer was grossly negligent, and whether that argument succeeds or not depends on how the facts unfolded and how the claim is framed. Having fallen for a link does not close the door on its own.

Is it worth reporting to the police and is it required for the bank to refund?

It is worth it, and in the first hours it is what allows a request to hold the money in the receiving account. A refund by the bank does not legally depend on a police report, but the bank almost always asks for one and its absence is used against you. Report the same day and keep a copy.

What if they called me pretending to be the bank and I made the transfer myself?

The transaction counts as authorised even though the authorisation was obtained by deception, and claiming against the bank is harder than when the fraudster made the payment. It is not impossible, what is analysed is what the bank did when faced with a transaction out of the ordinary in amount, destination and time. Against whoever called you, the criminal route is the same as in any fraud.

Do I need a lawyer or is it enough to claim from Sabadell?

If the bank has refunded your money on the first claim, you do not need one. Nor is it worth it if the amount lost is small and the bank has already refused, because the cost of litigating may exceed what is recovered, and in that case the police report is the only step that makes sense. When the amount is significant and the bank refuses citing negligence, yes, because the claim is won or lost on how the facts are proved, and that is not improvised.