LearnDebt & Credit › Scams

In short: Never share passwords, codes or one-time codes, and refuse to be rushed. A genuine bank never asks for your security code; if you are defrauded, freeze the card with your bank and report it.

Spot Scams and Fraud – Protect Your Money

Scammers rely on pressure and urgency so you act before you think. Once you know the patterns, you can see through most schemes in seconds.

  • For any email or text with a link, pause first: real banks never ask you to enter your details or codes through a link.
  • Never share passwords, PINs, one-time codes or confirmation codes — no matter who is calling or how urgent it sounds.
  • Check return promises: high gains without risk do not exist. Pressure, a countdown or an “exclusive coach” are red flags.
  • If you are hit, act at once: freeze your card and account with your bank, change your passwords, and report it to the police.

What matters

The most common mistake is reacting under stress instead of checking. A classic phishing scam: a text says your account is “locked” and a link leads to a near-perfect copy of your bank — enter your login and code there and the criminals drain it in minutes. Investment fraud works the other way, through greed: shady crypto or trading “coaches” promise unrealistic returns, even show fake profits at first, and nudge you to deposit more — a pyramid scheme that collapses. Shock calls (the “grandparent scam”), advance-fee fraud (“pay first, win later”) and fake shops with unbeatable prices follow the same pattern: artificial pressure plus a promise that is too good to be true. Check the sender, the URL and the tone calmly — legitimate organisations always give you time.

8 weeksto reverse aSEPA directdebit, noquestionsasked~120 daystypicalcredit-cardchargebackdeadlineSecondsuntil aninstanttransfer isirreversible116 116card-blockinghotline,around theclock
In an emergency, deadlines matter: a direct debit can be reversed for 8 weeks, an instant transfer is irreversible within seconds – block your card right away via 116 116.
ExampleA fake shop offers a console for 199 € instead of 499 € on prepayment — if the goods never arrive, the 199 € are usually gone, and the 300 € you thought you saved was simply the bait.
Keeping an eye on your cards and logins helps you notice anything odd sooner — see bank accounts & cards.

In depth

A reversal is not a safety net

Many assume the bank will simply claw the money back if something goes wrong – that is only half true. A SEPA direct debit can be reversed within eight weeks with no questions asked, but a transfer you authorised yourself almost never can, because it counts as approved. Fraudsters exploit exactly this: they get you to make the transfer yourself, ideally via instant transfer, which is irreversible at the recipient within seconds. Credit cards often allow a chargeback, for example when goods never arrive, but this usually requires deadlines of around 120 days and supporting evidence. Anyone who „confirms“ a payment with a TAN in online banking has legally consented – even if the prompt actually authorised an account being drained. The next-level lesson: before every approval, check the amount and recipient IBAN inside the TAN message itself, not what a website or caller claims.

When authenticity is the weapon

Advanced scams don’t rely on clumsy bait emails but on realism and speed. With so-called spoofing, a genuine bank or police number shows on your display because the caller ID is forged – a visibly correct number is therefore no proof. In a shock call, someone poses as a desperate child or an official and pushes for the immediate handover of cash or jewellery; the supposed time window is the real lever. A calm counter-check defuses almost every one of these: hang up and call the institution back on a number you already know yourself, never the one given during the call. Real banks and authorities never put you under seconds of pressure and never ask for a TAN, card PIN, or the contents of a confirmation text. The very phrase „you must act right now, or else …“ is the warning sign – no matter how professional the rest sounds.

The first hours afterwards

If something does happen, speed above all decides how big the damage gets. Block your card via the German blocking hotline 116 116 (around the clock, reachable from abroad with the country code +49) and block your online access directly with your bank. File a police report promptly, since the report is often a precondition for the bank to consider any goodwill. Ask the bank in writing to recall the transfer; with instant transfers the chance is slim, but for ordinary transfers the attempt is worthwhile in the first hours. Document everything with screenshots, timestamps and IBANs – a seamless record helps both the investigation and any possible refund. If you disclosed credentials, change the password everywhere the same combination was used, because criminals try stolen data across many sites in turn. And don’t underestimate the aftermath: victims end up disproportionately often on lists for follow-up fraud, such as bogus „recovery services“ that offer to retrieve the lost money for an upfront fee.

An unrequested code is a completed attack

Understand what the six-digit code that lands on your phone actually does: it is the second half of a login or a payment authorisation, so once you read it aloud you have finished a transaction the fraudster started. Picture the sequence. You get a call from someone claiming to be your bank's fraud team; while you listen, they enter your details on the real banking site or set up a payment. That triggers the genuine code to your device. They then ask you to "confirm" it, and the moment you say the digits, the money moves or a new payee is added. The code did not protect you; you handed over the last lock. The single reliable tell is timing: a code that arrives when you did not just tap a button is a red flag, not a favour, because a real one-time code only appears in response to an action you personally took a few seconds earlier. If a code turns up out of nowhere and a voice on the phone wants it, the correct move is to say nothing, hang up, and assume someone is mid-way through draining an account. No real institution needs you to speak a code back to a human on a call, ever.

When the line never really hangs up

A specific trick defeats the usual advice to hang up and call your bank back yourself: the fraudster keeps the phone line open at their end. You press end, hear a dialling tone that is actually still their line, dial your bank's real number, and reach the same criminal, who now "answers" as the bank and confirms everything they told you. Some run a fake tone or a fake bank greeting to sell it. This is why "I called them back to check" is not proof by itself. Two habits break it. First, call back from a different phone where you can, so a brand-new line has to be opened. Second, if you only have one phone, wait several minutes, or call a friend or a speaking clock first and confirm you can actually reach someone else, before dialling the number printed on your card or shown inside your banking app. As an illustration of the stakes, imagine being told a "pending transfer" of around one thousand of your currency clears unless you verify now: real urgency never depends on you staying on one line the caller controls. If they resist you hanging up, that resistance is the answer.

The safe-account move is always fraud

One instruction reliably separates a scam from a real bank: being told to move your money to a "safe" or "holding" account. No genuine institution ever asks you to transfer your balance somewhere for protection, because their systems already protect your account by freezing it, not by emptying it. Yet this line works because it inverts the victim's instinct. You are frightened that money is at risk, so an offer to move it to safety feels like rescue. The account you are pushed towards is controlled by the fraudster, and the transfer looks fully authorised because you made it yourself. Treat any of these phrasings as a stop sign: "move your funds to a safe account," "withdraw cash and hand it to a courier for safekeeping," "buy gift cards and read us the numbers," or "install this app so we can secure your device." Each routes value away from you in a form that is hard to claw back. The decision framework is blunt: any request that ends with your money leaving your own account is the fraud itself, regardless of how official the caller sounds. If you hear it, end the contact and verify independently before touching a single control.

Slowing a scam that is built on speed

Fraud engineered around pressure collapses the moment you introduce a delay, because the script depends on you deciding while alarmed. Give yourself permission to be slow. A practical technique is to say one prepared sentence and mean it: "I don't make money decisions on unexpected calls; I'll call my bank back myself." Then hang up. A real employee will not object to you verifying; a fraudster will escalate, guilt-trip, or warn you that hanging up "proves you're involved" because their only asset is your continued attention. Watch for the tells that you are being rushed: a countdown ("the transfer completes in two minutes"), secrecy ("don't tell staff at the bank, they may be compromised"), and isolation ("stay on the line, don't hang up"). Each exists to stop you consulting anyone calmer. An expensive beginner mistake is treating politeness as an obligation, staying on a call you already distrust because ending it feels rude. It is not rude; it is the correct action. Build a household version too: agree with a partner or relative that any request to move money gets a mandatory pause and a second opinion, so no one person can be pressured into acting alone.

Checklist

  • Never share a code, PIN, password or one-time code
  • Treat pressure and urgency as a warning sign
  • Do not open links from email or text — use the app or official number
  • If defrauded: freeze the card, call the bank, report it
Common myths

Myth: My bank will text me when I need to confirm my details.

Reality: No. No legitimate bank asks you by text or email to enter a code, PIN or password — that is always phishing.

Myth: You can spot a scam by bad spelling and clumsy emails.

Reality: Not anymore. Modern scams use flawless text, real logos and spoofed senders — what matters is the content of the request, not the grammar.

Sources

Education, not advice. How we work and check figures: Editorial. Figures as of 2026, last reviewed 07/04/2026.

Frequently asked questions

I clicked a phishing link — what now?

Just clicking is usually harmless. The risk starts if you entered details: change your passwords right away, call your bank, and watch your account. If you gave card data, freeze the card with your bank immediately.

How do I tell a real bank message from a fake?

Real banks never ask for a code, password or PIN by email or text, and they never rush you. When in doubt, do not tap the link — open the app or call the official number on the back of your card.

What are common warning signs of a scam?

Typical red flags include unexpected pressure to act immediately, requests for codes or passwords, promises that sound too good to be true, and unusual payment methods like gift cards or crypto. A demand for secrecy is another strong signal that something is wrong.

How can I protect my accounts before anything happens?

Use strong, unique passwords and turn on two-factor authentication where offered, and keep your devices and apps updated. Being cautious about which links you click and which numbers you call back reduces the chance of being caught out.

What is the difference between phishing, smishing and vishing?

These are the same trick delivered through different channels: phishing by email, smishing by text message and vishing by phone call. In each case the goal is to get you to hand over credentials or money, so the same caution applies everywhere.

All lessons · Glossary · Editorial · Kontoo does the math and explains – this is general education, not tax, legal or financial advice.

Your data stays with you. Full stop.

Kontoo collects, sees and stores none of your personal data. No account, no cloud.

No accountNo cloudNo cookiesNo ads