Text or call from Unicaja about a blocked account, what to do

How to spot the text or call impersonating Unicaja, what to do in the first minutes, the offence of fraud and when the bank must refund the money.

Someone who has just typed their login details into a website imitating Unicaja tends to do the same thing within the hour. They go to the police station, file a report, leave with a stamped copy and assume the recovery of the money is under way. What they have done is open a criminal case for fraud against an unknown perpetrator, who in most cases is never identified, and that court has no power to order the bank to reimburse what has left the account. The duty to refund an unauthorised payment transaction arises from payment services legislation and falls on the bank where you hold the account, whether or not the fraudster is ever found. The party that decides whether you get your money back is the bank, and it is before the bank that you must act correctly from the first minute. You also go to the police, for a different reason, which I explain below.

Unicaja is the impersonated bank here. Criminals use its name and branding because it has a large customer base and anyone with an account there reacts to a message about it. Nothing that follows attributes any conduct to the bank.

How to recognise the text or call impersonating Unicaja

The pattern repeats with few variations. A text message warns that the account has been blocked for security reasons, mentions a charge you do not recognise or a new device linked to the account, or asks you to verify your identity, and ends with a link. That link is shortened or leads to a domain that is not the bank’s official one, even though the page it opens copies the logo, the colours and the login form. When you enter your username and password on that cloned site, the criminals receive them in real time.

The second phase is the call. Minutes or hours later someone rings, introduces themselves as Unicaja’s “security” or “fraud” department, knows you have received the text and mentions a charge or an access attempt that does in fact appear on your account, because they caused it with the credentials they have just captured. From there they ask for the one-time code arriving by text in order to “cancel” the transaction, when that code actually authorises it, or ask you to move your balance to a “safe account” while the incident is resolved, or ask you to install a remote assistance app so the adviser can “check” your phone, through which they take control of the device.

Variant How it appears Who executes the transaction
Text with link to a cloned website Blocked account, unrecognised charge or new device, with a shortened link The fraudster, using the captured credentials
Call from the fake adviser after the text Asks for the one-time code to “cancel” a charge The fraudster, using the code you give them
Transfer to a “safe account” They convince you the account is compromised and that you should move the balance You, under deception
Remote control app They have you install an assistance program to “check” the phone The fraudster, from your own device

The last column matters in legal terms. Whether the transaction was executed by a third party with your credentials or ordered by you under deception changes how the claim against the bank is framed, and in the second case the bank usually argues that the instruction was yours.

Why it looks genuine

The sender of a text message can be spoofed so that the bank’s name appears, and many phones group messages by that name, so the fake one lands in the same thread as the genuine ones. The number they call from is spoofed too, and it often shows a dialling code matching the city where the bank has its head office. The fake adviser knows your name, the last digits of your card or your approximate balance because they obtained them from the cloned site or from an earlier login to your online banking. The charge they mention exists because they attempted it, and the code you receive is genuine because the bank sends it to authorise that transaction in progress. Everything you see is real except the person speaking to you.

What no bank ever does

This applies to all Spanish banks and does not depend on the institution. The full login password, the electronic signature and the one-time code sent to your phone are never requested by telephone, text or email. Nor is a customer ever asked to move money to another account to protect it, to install a remote control app, or to enter their credentials through a link on a page other than the official app. If you receive any of these requests, the communication is fraudulent however convincing it sounds, and the only valid check is to hang up and call the number printed on the back of your card or shown inside the official app.

What to do in the first minutes

Hang up and do not call back the number on screen or the one in the text. Call the number on the back of your card or use the official app, ask for your login credentials and cards to be blocked immediately and state, on that same call, that you do not recognise the transaction or transactions that have gone out. Note the time and, if given one, the incident reference.

Delete nothing. The text with the link, the call log, the emails or alerts you received and the app notifications are the evidence of how the fraud happened. Take screenshots of the cloned site if it is still open and of your transaction history. If you installed a remote assistance app, capture the screen with the app installed before uninstalling it, and do not factory reset the phone until all of that is saved. Evidence lost at this stage cannot be recovered.

Do not sign or accept any document, form or message from the bank in which the transaction is treated as valid or in which you acknowledge ordering it. Be wary too of anyone who calls in the following days offering to recover the money in exchange for an upfront payment, because that is the second round of the same scam.

A warning for those who receive the call the other way round. If someone proposes that you receive a transfer into your account and forward it in exchange for a commission, they are recruiting you as a money mule. The account receiving the victim’s money is the first one the bank identifies and the first to reach the court, and whoever made it available to the fraudster may end up under investigation for money laundering or as a participant in the fraud.

If you have already given your details or made a payment

The money may have left in one of two ways. If the fraudster operated with the credentials they extracted from you, this is an unauthorised payment transaction, and for those transactions payment services legislation places a refund obligation on the bank. If you were the one who ordered the transfer to the “safe account”, the bank will tend to treat it as your own instruction and refuse the refund, although that response is not the final word and there are grounds on which it can be contested.

The bank’s usual reply, in either case, is that the customer was negligent in handing over the credentials or the code. Being told so does not make it so in legal terms, and the Supreme Court has already ruled on banks’ liability for fraudulent transactions of this kind (judgment 571/2025). How that claim is framed, with which documents and which arguments against the allegation of negligence, is the lawyer’s work, and at the firm it is what we do in cybercrime when a client arrives with the bank’s refusal in hand. I have explained in more detail what the bank is obliged to refund in bank refund after phishing and in bank impersonation scam, what to do.

It is the offence of fraud, and what the police report is for

What has been done to you is fraud under Article 248 of the Spanish Criminal Code, punishable by six months to three years’ imprisonment. The same article covers anyone who obtains the transfer through computer manipulation or by using another person’s credentials without deceiving anyone in person. If the amount defrauded does not exceed 400 euros, it is a minor offence punishable by a fine.

The police report has a specific purpose. It is the route by which the destination account is traced and whatever remains in it is frozen, and it is a document the bank will ask for and which, in the later claim, shows that you acted as a victim. What the report does not do by itself is get your money back.

You can file the report at the National Police station or the Guardia Civil post in your town even if the fraudster, the destination account and the bank’s head office are in another province. The criterion applied to these frauds places jurisdiction with the court of the place where the victim was deceived and made or suffered the disposal of the money, which is where you were when you took the call. The offence takes years to become time-barred, so the report does not have the urgency of hours that blocking your credentials and notifying the bank do have.

Most of these cases are provisionally dismissed because the perpetrator is not identified, or are joined to proceedings in another court investigating the same network. The dismissal takes away none of your rights against the bank. The claim against the bank does not depend on a conviction, and the dismissal order, like the report, is one more document in that claim. If at some point someone is arrested, the case is reopened and you can join it as a private prosecutor to claim your loss, with the caveat that the person identified is almost always the mule, with little or no assets.

What is at stake and what we do at the firm

Claiming on your own usually ends in a letter from the bank attributing the transaction to your negligence and a file in which something has been recorded, in your own words, that is later used against you. With sums of several thousand euros that first response conditions everything that follows. At the firm we practise in cybercrime and criminal law, we analyse how the money left and through which channel, we conduct the claim against the bank and the lawsuit if it is refused, and we handle the police report and the private prosecution in the criminal case where it adds something. You can call +34 677 841 007 or write through contact. Have to hand the original text message, the call log with time and number, the screenshots of the website and of your transaction history, proof of your notification to the bank with its date and, if you already have them, the bank’s written reply and the copy of the police report.

Frequently asked questions

Call the number on the back of your card or open the official app and ask for your credentials and cards to be blocked, state that you do not recognise any transaction that has gone out and note the time. Do not call back any number from the text and do not hand over any code you receive. Keep the text, the screenshots and the call log, and do not reset the phone until everything is saved. Then file a police report and, if money has left the account, speak to a lawyer before replying to the bank in writing.

Can I get the money back if I made the transfer myself because I was deceived over the phone?

This is the most contested scenario, because the bank will treat the instruction as yours and refuse to refund it. A refusal does not close the matter. It depends on how the instruction came about, what controls the bank applied and how the deception is documented, and those are questions to be analysed with the statements and the communications in front of you. It is worth examining before writing it off.

Do I have to report it to the police before claiming from the bank?

It is not a prior requirement, and notifying the bank should not wait for the report. It is advisable to report, because the bank usually asks for a copy, because it allows the destination account to be traced and because it shows in the claim that you were the victim. What the report does not do on its own is oblige the bank to refund you anything.

Is it worth claiming for 2,000 euros, and do I need a lawyer?

It depends on the amount and on how the money left. With small sums, if the transaction was executed by a third party with your credentials and the bank refunds it after your notification, you need no one. If the bank refuses on grounds of negligence and several thousand euros are involved, a claim with a lawyer is usually worthwhile, because amounts up to 15,000 euros go through the simplified verbal procedure and the bank’s initial refusal does not decide the outcome. When the sum is very low and part of it has already been recovered, the cost may not justify litigation, and we will tell you so at the first consultation.