By Jackson Godwin. Cybersecurity Analyst & Penetration Tester.

The Fake Bank Fraud Alert That Stole My Card Information
Disclaimer: This story is fictional but inspired by real phishing and smishing attacks targeting bank customers. It is written to educate readers about banking fraud, social engineering and cybersecurity awareness.
The Message Looked Urgent
It happened on a busy Tuesday afternoon.
I was at work when my phone buzzed.
The text message appeared to come from my bank.
It read:
“URGENT: Suspicious activity detected on your card. Your account has been temporarily restricted. Verify your account immediately to avoid permanent suspension.”
At the bottom of the message was a link.
At first glance, everything looked genuine.
The sender’s name matched my bank.
The wording sounded professional.
Nothing seemed unusual.
Panic Took Over
My first thought wasn’t about scams.
It was about my money.
Had someone hacked my account?
Had my credit card been stolen?
Without thinking carefully, I tapped the link.
That single decision almost cost me everything.
The Website Looked Perfect
The page that opened looked identical to my bank’s official website.
It had:
- The correct logo.
- Matching colours.
- Professional design.
- Security icons.
- A login page I had seen many times before.
If someone had shown me the real website and the fake one side by side, I probably wouldn’t have noticed the difference.
I Logged In
The page asked for my online banking username and password.
I entered both.
After pressing Log In, another page appeared.
It explained that additional verification was required because of the suspicious activity.
That sounded reasonable.
After all, protecting my account was exactly what I wanted.
Then It Asked for My Card Details
The next page requested:
- My credit card number.
- Expiration date.
- CVV security code.
It explained that verifying the card would remove the temporary restriction.
I hesitated.
For just a second.
Then I reminded myself that I believed I was already on my bank’s website.
So I entered the information.
One More Step
Immediately afterwards, I received a one-time password (OTP) by text message.
The website instructed me to enter the code to complete the security verification.
Without realising what was happening, I entered the OTP.
The page displayed a reassuring message.
“Verification Successful.”
Then it redirected me to my bank’s real homepage.
I felt relieved.
I believed the problem had been solved.
I had no idea I had just handed everything the criminals needed.
The First Transaction Appeared
Less than ten minutes later, my phone vibrated again.
A transaction alert.
Then another.
Then another.
The fraud alert I had tried to prevent had become real.
Only this time, it wasn’t my bank contacting me.
It was cybercriminals spending my money.
(Continue in Part 2, where I’ll explain how the fake website captured my banking credentials, reveal the warning signs I completely missed, and show how phishing websites steal card information in just a few minutes.)







