By Jackson Godwin. Cybersecurity Analyst & Penetration Tester.

The Question I Was Waiting For
The caller remained calm.
His tone never changed.
He still sounded professional.
Then he said,
“For security purposes, I just need to confirm a few details before we block the suspicious transaction.”
That sentence might sound perfectly reasonable.
After all, banks do verify customers in some situations.
So I listened carefully.
Then came the first request.
“Can you please confirm the One-Time Password (OTP) that has just been sent to your phone?”
At that exact moment, I knew something wasn’t right.
Why That Request Was a Red Flag
Seconds earlier, my phone had received an SMS containing a verification code.
The message also included a warning that the code should not be shared with anyone.
The caller acted as though giving him the code was part of the security process.
In reality, verification codes are designed to help confirm your identity—not someone else’s.
Legitimate organizations generally do not ask customers to reveal passwords, PINs, or one-time verification codes over an unsolicited phone call.
That request immediately changed the entire conversation.
Then He Tried Another Approach
When I refused to provide the code, the caller didn’t become angry.
Instead, he became even more polite.
“Sir, I’m only trying to help you stop fraudulent activity.”
He paused for a moment before adding,
“If we cannot verify your account now, the transaction may continue.”
Again, he was trying to create urgency.
This is a common tactic used in many social engineering scams.
The goal is to make you feel that delaying your decision will have serious consequences.
When people feel pressured, they are more likely to act without carefully thinking things through.
He Wanted Me to Trust Him
The caller continued speaking confidently.
He used banking terms.
He sounded experienced.
He never raised his voice.
Everything about the conversation was designed to make me believe he was genuine.
That’s one of the biggest lessons I want readers to remember.
Scammers don’t always sound suspicious.
Many sound:
- Calm.
- Friendly.
- Professional.
- Helpful.
Sometimes they are excellent communicators.
They understand that trust is often more powerful than technology.
The Simple Question I Asked
Instead of arguing, I asked him one question.
“If you’re really calling from my bank, which branch are you calling from?”
There was a brief silence.
He answered with a general response.
I asked another question.
“Can I end this call and contact the bank myself using the official customer service number?”
This time, his answer changed.
He quickly replied,
“No, sir. If you end this call, the security process will be interrupted.”
That sentence confirmed my suspicion.
A genuine bank representative should not discourage you from contacting the bank through its official channels.
I Ended the Call
Without saying another word, I thanked him for his time.
Then I hung up.
Immediately afterward, I called my bank using the official customer service number listed on its website and mobile app.
I explained everything that had happened.
The representative checked my account.
There was no suspicious transaction.
No fraud alert.
No ongoing security investigation.
The earlier phone call had not come from the bank.
Why Independent Verification Matters
That experience reinforced one of the most important cybersecurity habits anyone can develop.
If someone contacts you claiming to represent:
- Your bank,
- A government agency,
- A telecommunications company,
- A delivery service,
- Or any other organization,
and asks you to take urgent action, pause for a moment.
Instead of relying on the contact details provided during the call, end the conversation politely and use official contact information that you already trust.
For example:
- The phone number is printed on the back of your bank card.
- The customer support number is listed on the bank’s official website.
- The contact information is inside the bank’s official mobile application.
Independent verification gives you control of the conversation.
The Biggest Lesson
That day reminded me that cybersecurity isn’t always about spotting obvious scams.
Sometimes it’s about slowing down.
Thinking clearly.
And refusing to let urgency make important decisions for you.
The caller sounded convincing.
The conversation felt real.
But one simple habit—verifying independently—prevented me from becoming a victim.
In the final part of this article, I’ll share the warning signs of bank impersonation scams, explain what to do if you’ve already shared information with a scammer, provide a practical checklist you can use today, answer common questions, and finish with lessons every bank customer should remember.









