By Jackson Godwin. Cybersecurity Analyst & Penetration Tester

I Called the Bank Immediately
The moment I saw the second transaction alert, I knew something was wrong.
I didn’t click the link again.
Instead, I searched for my bank’s official customer service number and called them directly.
After verifying my identity, the representative checked my account.
Her first question surprised me.
“Did you recently enter your banking details on a website?”
I replied:
“Yes… your website asked me to verify my account.”
There was a brief silence.
Then she said the words I never wanted to hear.
“That wasn’t our website.”
The Truth Hit Me Instantly
My heart sank.
The fraud alert itself had been fake.
The website had been fake.
The login page had been fake.
Everything had been carefully designed to make me believe I was protecting my account.
In reality, I had handed my information directly to cybercriminals.
They Already Had Everything They Needed
The bank explained what had happened.
The fake website had collected:
- My online banking username.
- My password.
- My credit card number.
- My card’s expiration date.
- My CVV security code.
- The one-time password (OTP) sent by my bank.
That OTP wasn’t verifying me.
It was authorising them.
By entering it on the fake website, I unknowingly approved the criminals’ access.
The Website Disappeared
While speaking with the fraud department, I tried opening the phishing website again.
It no longer worked.
The page had disappeared.
The criminals had likely taken it offline after collecting enough victims.
That made the scam even harder to investigate.
I Remembered Something Strange
Looking back at the text message, I noticed something I had completely ignored.
The website address wasn’t exactly the same as my bank’s official domain.
It contained one extra letter.
The difference was so small I hadn’t noticed it during the panic.
That tiny detail had been the biggest warning sign.
Panic Made Me Stop Thinking Clearly
The fraud investigator explained something important.
Phishing attacks don’t succeed because victims are careless.
They succeed because criminals create urgency.
The message convinced me that:
- My account was in danger.
- Immediate action was necessary.
- Delaying could make the situation worse.
Instead of slowing down, I rushed.
That’s exactly what the scammers wanted.
The Bank Acted Quickly
The fraud department immediately:
- Blocked my online banking access.
- Cancelled my credit card.
- Stopped additional transactions where possible.
- Began investigating the fraudulent payments.
Fortunately, several attempted purchases failed because the account had already been frozen.
But some transactions had already gone through.
The investigation had only just begun.
I Learned One Painful Lesson
The fake website didn’t hack my bank.
It didn’t bypass advanced security systems.
It simply convinced me to provide everything voluntarily.
That was the most frightening part.
Technology wasn’t the weakest link.
I was.
In the final part of this story, I’ll explain how the investigation ended, reveal the most common signs of fake banking alerts, and share practical ways to recognise phishing attacks before they steal your money.
Continue Reading: The Fake Bank Fraud Alert That Stole My Card Information (Part 3)







