Serving Shropshire ยท Herefordshire ยท Welsh Borders ยท Est. 2014Helpdesk open ยท avg 14 min response01584 517 234
Fresh Tech
01584 517 234Book a call โ†’
Cyber SecurityScamsTraining

Listen to a Real Bank Scam Call: The Code Trick

SJ
Sam James ยท Aug 11, 2026 ยท 7 min read

The real call, shared with permission. A fraudster posing as a bank fraud team spends nine minutes building trust, then asks for a six-digit code from a text message.

A fraudster posing as a bank fraud team nearly talked a client into reading out a one-time code. Hear the call, and the one line that stopped it dead.

TL;DR: One of our clients, Willem, took a call from a man claiming to be from his bank's fraud team. The story was plausible, the manner was flawless, and the entire nine minutes was aimed at one thing: getting Willem to read out a six-digit code from a text message. He read the text properly, saw the words 'enter the code to authorise', and refused. The fraudster then threatened him and hung up. The recording is above. The rule that saved him fits on one line: a code sent to your phone authorises something. If somebody rang you, never read it out.

Willem asked us to share this as widely as we can, because he nearly fell for it and he reckons plenty of other people would. He is right. Play it to your team.

Why this one was so good

Most scam calls are easy to spot. This one was not. Listen to the recording and you will notice the caller never once sounds rushed, never once fumbles, and never once asks for anything that sounds obviously dodgy. That is the point. Here is what he actually does, in order.

He opens with a small, specific, believable problem. Not a fortune, just ยฃ273.11 to a motorcycle insurance company. Small enough to be real, odd enough to be alarming. He even offers a reason it was flagged: it does not match your usual spending. That is exactly what a genuine fraud team would say.

He gives himself authority props. Calls are recorded for security and monitoring. He apologises for the abrupt call. Later on, when challenged, he upgrades himself to a 'senior fraud department representative'. None of it means anything, but all of it sounds like a bank.

He invites you to check, then explains away what you will find. He is happy for Willem to log into online banking, because he knows there is nothing there. So he gets his excuse in early: declined transactions only appear when there was not enough money, and this one was stopped before it ever reached your account. That is nonsense, but it is confident nonsense, and it turns the absence of evidence into more proof that he is who he says he is.

He does the security speech himself. This is the cleverest bit:

Caller: Just to make it perfectly clear, an official Barclays card representative would never dare to ask you for any credentials, anything relating to long card numbers, expiration dates or security codes, as well as, of course, usernames and passwords.

Read that again. He is reciting the bank's own anti-fraud advice, unprompted, to a man he is in the middle of defrauding. It is inoculation theatre. Once he has said it, anything he asks for afterwards feels like it must be outside that list, because surely a criminal would not warn you about criminals.

He raises the stakes just before the ask. Eight minutes in, out of nowhere, a second fake transaction appears: ยฃ1,200 to an energy company. Willem's answer is immediate, 'definitely not us'. Now there is real money on the line and a reason to act this second. The six-digit code request lands about twenty seconds later. That sequence is not an accident.

The tell, if you know what you are listening for

About halfway through, the caller slips in a question that has nothing to do with a declined payment:

Caller: And also just to clarify, would you currently have the card attached to any sort of Google Pay or Apple Pay wallets?

Willem: Yes.

A genuine fraud team would not need to ask. They can see it. He asked because it decides which attack he runs next.

We cannot know for certain from the recording alone what the code was for, and we are not going to pretend otherwise. But there are only really two candidates, and both end the same way:

  • He was adding the card to a digital wallet on his own phone. You put someone else's card details into Apple Pay or Google Wallet and the bank texts a code to the real cardholder to approve it. Get the cardholder to read that code out and the card is now live on the criminal's handset, ready to spend in shops and online until the limit runs out. UK Finance has flagged this repeatedly: once a criminal has a one-time passcode, they can authenticate fraudulent transactions or register your card in their own digital wallet. Which? has reported individual victims losing over ยฃ18,000 in a matter of hours this way.
  • He was sitting on a checkout page pushing a real payment through. The bank texts a code to confirm it is you. He needs you to read it out to complete the purchase he is making.

Either way, the code is not confirming a cancellation. It is the last brick in a wall he has spent nine minutes building. There is no such thing as a 'cancellation code'.

The moment it fell apart

Here is the exchange, lightly tidied for readability. Card and phone digits have been removed.

Caller: Just to go ahead and confirm the cancellation of the pending payment, we'll be issuing you with a six-digit cancellation code. That's going to be sent to the mobile number ending in [removed]. Do you have that in your possession?

Willem: Yeah.

Caller: Now, with this reference code, all it does is confirm the cancellation of the pending payments, as well as confirming to the Barclaycard team it's not yourself who's attempted to place that today. That's been sent to you now via text message. Just very kindly confirm the six-digit reference number for me.

Willem: It says never to share this code with anyone.

Caller: That's correct. So you can see that's a one-time verification code. It's for one-time use.

Willem: Yeah, but it says not to share this code with anyone.

Caller: I'm fully aware of what the text message would state, Willem.

Willem: No, it just says here, 'Enter the code to authorise.' So I'm definitely not going to share this code with you.

That is the whole defence, and it cost nothing. Willem did not detect the scam through technical knowledge or suspicion of the caller. He simply read the text message that had just arrived on his phone, out loud, and noticed that the words on the screen did not match the words in his ear.

The caller says something remarkable in reply: 'I'm fully aware of what the text message would state.' He knows exactly what it says. He has heard people read it back to him hundreds of times. He is banking on you not stopping to think about it.

Then he proved it himself

When Willem said he thought the call was fraudulent, the professional manner evaporated in about four seconds:

Caller: Then we'll let the payment go through and then you can call the number on the back of your card and ask them why that's happened, okay? Because you didn't want to cooperate with us from the get go.

And, as a parting shot:

Caller: Have fun waiting in the queue when you call the number on the back of your card.

That is not how a bank behaves. A real fraud team cannot choose to let a fraudulent payment through as a punishment for you being careful, and would not want to. Genuine security people are pleased when you refuse to give them something. It means the training worked.

If you are ever unsure mid-call, this is a reliable test: say you would like to hang up and call the bank back yourself. A real employee will say yes, immediately, and often suggest it before you do. A fraudster will talk you out of it, because the moment you hang up, the whole thing is over.

What to do if you get a call like this

Three things. That is genuinely all.

1. Stop. Hang up. Call 159.

159 is a free short code, run by Stop Scams UK, that connects you straight to your own bank's fraud team. It is the phone equivalent of 999 for scams. It covers over 99% of UK current accounts, including Barclays, Lloyds, HSBC, NatWest, Santander, Nationwide, Monzo, Starling and TSB. Crucially, it cannot be spoofed or impersonated, which is more than can be said for the number showing on your screen.

Hang up first. Then dial 159. If the original call was genuine, you have lost thirty seconds. If it was not, you have just saved your money.

2. Treat every code as an authorisation, because it is.

A one-time code is not a reference number, a cancellation code, a verification of identity, or a security check. It is a signature. Reading it out is signing something you cannot see. The text always tells you what you are actually signing, in the first line, if you read past the digits. Willem read it. That is the entire story.

3. Give your team explicit permission to be rude.

Most people hand over the code because hanging up on a polite, professional-sounding person feels unforgivably impolite. So take that off them. Make it a standing, written rule that nobody in your business will ever be in trouble for ending a call, refusing a code, or checking with someone first, even if the caller turns out to be legitimate. Fraudsters rely on good manners far more than they rely on technology.

Why this matters for businesses, not just people

This was a company credit card, on an account shared with a colleague, used for buying on a business account with a supplier. That is why the caller kept probing: who else uses the card, how many people have access to the supplier account, is it linked to a wallet. Every answer was a map of the business.

Criminals stole ยฃ1.28 billion through payment fraud in 2025, according to UK Finance's 2026 report. There is one genuinely encouraging number in there: impersonation fraud, exactly this sort of call, fell 12% by value and 11% by case volume. That is not luck. It is people like Willem knowing the trick before it arrives.

Which is why he wanted this shared, and why it is worth nine minutes of your next team meeting. The same instinct catches its email cousin, where a fake invoice or a message from your 'supplier' asks you to change bank details. We have written up how that one works in our guide to business email compromise, and the phone scam we saw earlier this year used a different hook to reach the same place.

What to do if you have already read out a code

If you or someone in your team has read out a code, do not sit on it out of embarrassment. Speed matters more than anything else here.

  1. Call your bank right away on 159, and tell them a code was shared.
  2. Ask them to check for any device or digital wallet added to the card, not just for transactions. This is the step people miss, and it is the one that keeps the card being spent on after it is 'sorted'.
  3. Report it to Action Fraud on 0300 123 2040, or to Police Scotland on 101.
  4. Tell whoever looks after your IT. If the caller knew details they should not have, something else has leaked, and that is worth finding.

If you would like us to run a short session with your team on this, or you are not sure whether an email or a call you have had was genuine, get in touch or ring us on 01584 517234. We would much rather have the conversation before, than after.

And if you want to know whether criminals can currently send email pretending to be your business, that takes us fifteen minutes to check and costs nothing: get a free email security check.

More reading
Related articles
Got an IT question?
Call us. We pick up.

20 minutes. No sales pitch. Just a straight answer to your IT question.

Book a 20-min call โ†’
Alex
Need help with your IT? Chat with me!