Text or call from Santander saying your account is blocked: what to do

Texts and calls impersonating Santander, how to spot them, the offence of fraud, what to do in the first hours and when the bank must refund you.

If money has left your account after a text message or a phone call claiming to come from Santander, it is not up to you to prove that you were deceived. Where a customer denies having authorised a payment, the payment services legislation places the burden of proof on the bank, which must show that the transaction was properly authenticated and, if it intends to keep the money, that the customer acted fraudulently or with gross negligence. The rule in criminal proceedings is similar, because it is the prosecution that has to prove the fraud, and in these cases the evidence comes from the victim. The practical consequence is the same on both fronts. What you keep, what you delete, what you state and what you sign in the first few days decides whether the bank can build a case for negligence and whether the criminal complaint has anything to work with.

It should be said from the outset that Santander is the bank being impersonated in this scam, not the one committing it. By number of customers it is the most impersonated bank in Spain, and that only means that anyone, customer or not, can receive these messages.

How to recognise the message

The fraudulent text, known as «smishing», arrives with the bank’s name as the sender and often lands in the same thread as genuine messages you have received before. That does not mean it comes from the bank. The alphanumeric sender ID of a text message can be forged, and your phone groups messages by that name, not by their real origin. The pattern repeats with few variations. There is an alarm, there is urgency and there is a link, almost always shortened or on a domain that resembles the official one without being it.

Variant What the message or call says What the fraudster is after
Account blocked or suspended That you must complete a mandatory security check to regain access That you open a cloned website and type in your username and password
Unrecognised charge or transfer That a large transaction has been ordered and you should click the link if you do not recognise it Your credentials, and to set up the follow-up call to obtain the code
New device linked That a new phone has been added to your account and you should cancel it from the link Your login and signing credentials
Loan paid in by mistake That a loan has been granted to you in error and you must return it to an account That you transfer to the fraudster a loan taken out with your own credentials
Verification with your card That you install an app and hold your card against the phone to confirm your identity To read the card data via NFC and use it

All five variants lead to the same place. The link opens a page that imitates the bank’s, with its logo and colours, and whatever you type there goes straight to the fraudster in real time.

Why it looks genuine

The cloned website is only the first step. With the credentials you have typed in, the fraudster logs into your online banking and sees your name, your balance, your recent transactions and the last digits of your cards. With that data comes the second part, the phone call, known as «vishing». Someone rings claiming to be Santander’s security department, tells you that unusual access has been detected, reads out real transactions from your account and asks you to cooperate in order to «cancel» a transfer or «protect» the money. The incoming number may show as the bank’s, because that can be forged too.

What the fraudster needs on that call is the one-time code the bank sends by text or through the app when a transaction is ordered. That code reaches your phone because, at that very moment, someone is executing the transfer with your credentials and the system is asking you to confirm it. If you read it out, the transaction is authenticated. The other two usual requests are that you move the money yourself to a «safe account» that in fact belongs to the fraudster, and that you install a remote access application so that «a technician» can check your phone.

What no bank ever does

This is common to all Spanish banks and does not depend on the institution. A bank does not ask you by phone or text for your full login password or your signing key. It does not ask you to read out the code you have just received. It does not ask you to move money to another account to protect it. It does not ask you to install a remote access app or to hold your card against your phone to verify anything. It does not call you to return a loan to an account that is not yours. The bank may block a suspicious transaction and notify you, but the check is always made through the official channel. If you have the slightest doubt, hang up and call the number printed on the back of your card or the one inside the official app.

What to do in the first hours

If you have clicked the link, typed anything in or taken the call, the order matters. Call the number on the back of your card or the one in the official app and block your cards and online banking access. Change your credentials from the official app, never from a link. If you installed an app at the caller’s request, switch off your data connection and uninstall it before using online banking again. Do not reply to or call back the number in the text. Do not take any further calls from the supposed bank even if they know your details, because they know them precisely because they have taken them from you.

As for evidence, do not delete anything. The text with its date and time, the link address, screenshots of the cloned site if you took any, the call log with the number and duration, the official app’s notifications about transactions or new devices, and the account movements are the material that will support the complaint and the claim. With all of that, file a report with the Policía Nacional or the Guardia Civil. No rule makes the refund conditional on a police report, but the bank will ask for it and it is the document that records the facts before a third party from day one.

One thing you should not do is sign, at the branch, any document acknowledging that you carried out or consented to the transactions, nor give a hastily drafted written account of what happened. That paper is later read as an admission of negligence.

If you have already given your credentials or made a payment

The payment services legislation requires the bank to refund the amount of a transaction the customer did not authorise. The fact that the fraudster used your credentials does not make the transaction authorised, because authorisation is given by the account holder, not by whoever executes it with data obtained by deception. And, as said at the start, it is the bank that has to prove that you acted fraudulently or with gross negligence if it wants to keep the money.

This is where things usually go wrong. The bank’s standard reply, when it comes, is that the transaction was correctly authenticated and that the customer was grossly negligent in handing over their credentials. In the case of a loan taken out with your credentials, the bank also demands the instalments. That this reply is the first does not mean it is the last. What decides the matter is how the claim is framed, with what documentation and with what arguments against the allegation of negligence, and that is the lawyer’s job. At the firm we handle these claims against banks under cybercrime, and on the blog we explain in more detail what the bank must refund after a phishing attack and what to do after a bank impersonation scam.

The offence, the police report and what to expect

What has been done to you is fraud under article 248 of the Spanish Criminal Code, punishable by six months to three years’ imprisonment. If the amount defrauded does not exceed 400 euros the penalty is a fine, and there are aggravated forms carrying higher penalties where the sum is large or the victims are many. The report can be filed at your local police station or Guardia Civil post, and the competent courts are, as a general rule, those of the place where you made the disposal of the money, that is, where you live and operate your account, even if the perpetrator is in another province or another country. The limitation period for this offence is counted in years, so you do not lose the right to report it for having taken a few weeks to react.

You should also know what usually happens next. The money goes to third-party accounts, often opened in the name of people who have lent their account in exchange for a commission, the so-called money mules, and from there abroad. The investigation frequently identifies the mule and not the organiser, and when no one is traced the case is provisionally closed. That closure does not affect your right against the bank. The claim for the unauthorised transaction is independent of whether the fraudster is ever convicted, and the police report continues to serve its purpose as evidence of the facts.

If you are the one who has received money into your account and forwarded it on behalf of someone who promised you a commission, or who returned a «loan paid in by mistake» to the account you were told, your position is different. Anyone who moves money of unlawful origin can end up investigated for money laundering even without knowing for certain where it came from, and the court will not simply take your word for it. In that case you need a defence before you make any statement.

Claiming on your own or with a lawyer

What you risk by doing it alone is that the bank fixes its version of the facts from what you told it in the first calls, that gross negligence is built out of your own words, and that the claim is exhausted without ever having been put with the evidence and the arguments the law gives you. In a case like this, at the firm we review all the documentation, file or complete the police report and conduct the claim against the bank as far as it needs to go. You can call +34 677 841 007 or write through contact, and our cybercrime page sets out what we do in this field. When you call, have to hand the original text, the screenshots, the call log, the statement showing the transactions, the date you notified the bank and what it replied, and the police report if you have already filed it.

Frequently asked questions

Does Santander have to refund me if I entered my credentials on the fake website myself?

As a general rule, yes. A transaction executed with credentials obtained by deception is not a transaction authorised by you, and the payment services legislation requires the bank to refund it unless it proves that you acted fraudulently or with gross negligence. That proof falls on the bank, not on you. How the claim is framed so that the allegation of negligence does not succeed is the lawyer’s job.

Do I have to report it to the police for the bank to refund me?

No rule makes the refund conditional on a police report, but the bank will ask for it and it is the evidence that records the facts before a third party from day one. Report it as soon as possible, with the text, the screenshots, the call log and the account movements.

Can I still claim if weeks have gone by and I have already signed a loan or made a transfer under deception?

Yes. The passing of weeks does not close the criminal route, whose limitation period is counted in years, nor the claim against the bank. The loan taken out by the fraudster with your credentials and the transfer you made under deception are challenged by different routes, and a lawyer should review it before you pay any instalment or accept the bank’s version in writing.

Do I need a lawyer for this?

Not always. If the bank has refunded the money after your first notification, or the amount is small and the bank has reimbursed it, you do not. You do need one when the sum is significant, when the bank refuses the refund alleging gross negligence, when a loan has been taken out in your name, or when the money passed through your account and you may end up under investigation. In those cases, the cost of getting it wrong is usually higher than the cost of getting it right.