Santander and NatWest customers were warned in 2023 about fraudulent text messages claiming that a transaction had been detected from a new device. Recipients were told they needed to verify the activity to continue using online banking, with an embedded link directing them to a counterfeit website designed to collect login credentials and personal information.
The wording was simple, but the attack model was not. A banking smishing campaign can combine brand impersonation, sender-ID manipulation, cloned websites, real-time credential interception, one-time-passcode theft, account takeover and the rapid movement of funds through mule accounts. What appears to the customer as one suspicious text may be the first visible stage of a larger fraud operation.
For a FinCrime audience, bank impersonation is not only a communications-security problem. It sits at the intersection of cyber-enabled fraud, identity compromise, unauthorised transactions, authorised push payment fraud, mobile-device security and money laundering.
The warning therefore remains relevant beyond the original campaign. Criminals continue to exploit trust in financial institutions while adapting their methods to stronger authentication, improved transaction monitoring and changing reimbursement rules.
Listen the podcast
Watch the video
Why the “new device” message works
A message stating that a payment or login has been detected from a new device creates immediate uncertainty. The customer does not recognise the activity, but believes delay could allow money to leave the account or online access to be suspended.
A scam may use the bank’s name, familiar formatting and a plausible security event. It may even appear inside an existing message thread because sender identities can be spoofed or abused through business-messaging infrastructure.
The presence of a recognised brand or conversation history is therefore not proof of authenticity. The relevant question is whether the customer initiated the action and whether the request can be verified independently through the official banking application, website or telephone number.
From smishing to account takeover
The embedded link usually leads to a website that reproduces the bank’s login page. Its address may contain the institution’s name with extra words, altered characters or a misleading subdomain. On a mobile screen, the full domain may not be obvious.
The page requests login and personal information, which more advanced operations relay to the criminal in real time.
As the victim enters credentials, the fraudster attempts to access the genuine account. If the bank sends a one-time code or approval request, the fake site asks the customer to provide or confirm it.
The customer believes they are cancelling suspicious activity. In reality, they may be authorising a login, registering a device, creating a payee, provisioning a card to a digital wallet or approving a payment.
This distinction matters because authentication does not eliminate social engineering. It proves that a credential or approval was supplied, but not necessarily that the customer understood the action.
When the message becomes a telephone scam
A fraudulent text may direct the recipient to call a number rather than open a website. The person answering adopts the language of a bank fraud department, provides a case reference and asks security questions to make the interaction appear procedural.
The caller may then claim that payments are pending or that the customer must move money to a protected account. No legitimate bank requires a customer to transfer funds to a secret “safe account”.
Caller identification cannot resolve the risk. Telephone numbers can be spoofed so an incoming call appears to originate from a bank, police force or government agency.
The reliable response is to end the contact and reconnect independently. Customers can use the number printed on their card, the official banking application or, for participating UK institutions, call 159 to reach their bank safely.
Unauthorised fraud and APP fraud
Bank impersonation attacks can produce two different outcomes.
In unauthorised fraud, the criminal uses stolen credentials or account access to make a transaction the customer did not approve. In authorised push payment fraud, the customer instructs the bank to send money but does so because they have been deceived about the recipient or purpose.
The distinction affects investigation, reimbursement and the evidence required. It also shows why scam prevention cannot sit solely inside account-takeover controls.
UK Finance reported that criminals stole £1.28 billion through payment fraud in 2025. Unauthorised losses declined, but APP losses rose to £576.4 million. The divergence reflects a wider shift from defeating systems directly to manipulating legitimate users.
Impersonation fraud declined during the year, but remains a high-impact typology. Telecommunications-originated scams represented a smaller share of APP cases than online-originated scams, yet accounted for a disproportionately large share of losses.
Why phishing links remain valuable
A phishing page can serve several purposes beyond stealing an online-banking password.
The data may support identity theft, card fraud, credential stuffing or targeted follow-up calls. The site also identifies which victims hold valid accounts and are willing to engage, allowing criminals to prioritise higher-value targets.
Stolen credentials can also be sold to other actors, while specialised groups provide phishing kits, call operations and mule accounts as modular criminal services.
The final payment is therefore only one component of the chain. Effective disruption requires action against fraudulent domains, messaging accounts, call infrastructure, receiving accounts and the onward movement of proceeds.
The mule account is the conversion point
Once an account is compromised or a victim is persuaded to transfer money, the fraudster needs somewhere to receive it. That role is performed by a mule account belonging to an individual, business or synthetic identity.
Funds are moved onward quickly, divided between accounts, withdrawn as cash, spent through cards or converted into cryptoassets. Speed reduces the chance of recall and distances organisers from the original victim.
This makes the receiving institution as important as the sending bank. A payment warning may prevent one loss, but identifying the recipient network can protect multiple potential victims.
What a resilient personal control stack looks like
The first control is independent navigation. Customers should not use links, telephone numbers or QR codes contained in unexpected banking messages. They should open the official application directly, type the known website address or contact the bank through a trusted number.
The second is transaction-specific authentication. One-time codes and approval prompts should be read in full. The amount, payee and action must correspond exactly to something the customer initiated. A code should never be disclosed to an unsolicited caller.
The third is account hygiene. Banking and email accounts should use unique passwords and multifactor authentication where available. Remote-access software should never be installed at the request of an unexpected caller. A genuine bank does not need to control a customer’s device to cancel fraud.
Customers should enable transaction alerts, monitor contact-detail changes and review devices registered to their accounts. Unexpected wallet-provisioning or new-device notifications should be reported immediately.
Suspicious texts can be forwarded to 7726. Anyone who has entered credentials, disclosed a code or approved an unexpected action should contact their bank immediately rather than waiting for a fraudulent transaction.
What banks need to detect
A resilient banking control stack cannot rely on one indicator. A new device, password reset or payee may each be legitimate. Risk becomes clearer when several events occur together.
Institutions should connect changes in device, IP address, geolocation, telephone number, password, payee profile and transaction behaviour. A new-device enrolment followed by a password reset, rapid payee creation and high-value transfer is more meaningful than any event alone.
Behavioural analytics can identify unusual hesitation, navigation, copy-and-paste activity or a customer acting while apparently coached. Call-centre intelligence may reveal that the customer is repeating scripted explanations or refusing to end another telephone call.
Payment interventions should be specific. Generic warnings are often clicked through. More effective prompts describe the typology, ask whether anyone instructed the customer to conceal the payment’s purpose and create space for independent verification.
Recipient-side analytics are equally important. New accounts receiving payments from unrelated customers, rapid pass-through behaviour, common devices and linked beneficiary networks can indicate mule activity.
Reimbursement changes incentives, not the threat
Since 7 October 2024, eligible victims of in-scope APP scams made through Faster Payments and CHAPS have benefited from mandatory reimbursement protections, generally up to £85,000 per claim.
The rules provide an important consumer safeguard, but reimbursement does not prevent criminal proceeds from entering the fraud economy. A victim may be financially restored while the criminal network retains the stolen funds.
The framework therefore increases pressure on both sending and receiving payment service providers to prevent scams, intervene appropriately and control mule-account exposure.
It also reinforces the need for fair treatment where a customer technically authorised a transfer while operating under sustained deception.
The wider ecosystem matters
The fraud journey often begins before a bank sees a payment. A malicious advert, search result, social-media account, text message, domain or telecoms service may provide the initial access to the victim.
UK data for 2025 showed that most APP cases originated online, while telecommunications accounted for a smaller but financially significant share. This supports a whole-system response rather than placing responsibility solely on customers and banks.
Ofcom’s 2026 measures to strengthen disruption of scam messages and spoofed calls reflect that direction. Mobile providers are expected to collect and act on scam intelligence, while broader initiatives seek faster sharing of malicious URLs, telephone numbers and account indicators.
Banks, payment firms, telecoms providers, online platforms and law enforcement each hold different fragments of the attack chain. Effective prevention depends on connecting them quickly enough to stop value moving.

What this means for financial crime leaders
The Santander and NatWest warning began with a familiar text: a transaction from a new device required verification. Its wider significance lies in the criminal operating model behind that message.
Modern bank impersonation fraud combines cyber compromise with human manipulation. Criminals use stolen data to create credibility, trusted brands to trigger action, fake interfaces to collect credentials and mule networks to convert deception into transferable value.
Customer education remains necessary, but it cannot carry the control burden. Institutions need integrated device intelligence, authentication context, behavioural monitoring, recipient analytics and rapid cross-industry data sharing.
The strongest programmes will not ask only whether a customer authenticated a payment. They will ask whether the surrounding behaviour suggests that the customer understood the transaction, acted independently and intended to pay the actual recipient.
A suspicious text is not merely an attempt to steal a password. It is an entry point into a coordinated fraud and laundering chain. Disrupting it requires banks to connect communications risk, account security, payment behaviour and mule infrastructure before a fabricated security alert becomes a real financial loss.




The warning issued to Santander and NatWest customers illustrates how a simple fraudulent text can serve as the entry point to a much broader financial-crime operation. Criminals use convincing security alerts to capture credentials, intercept authentication codes, manipulate customers into approving payments and move stolen funds through networks of mule accounts.
For customers, the most effective defence is independent verification. Unexpected banking messages should never be answered through the link or telephone number provided. The bank should instead be contacted through its official application, website or a trusted number. One-time codes and approval prompts must also be treated as transaction credentials and never disclosed to unsolicited callers.
For financial institutions, customer education alone is insufficient. Effective prevention requires the integration of device intelligence, behavioural analytics, account-change monitoring, payment context and recipient-side mule detection. Banks must assess not only whether a transaction was authenticated, but whether the customer understood the action and was acting independently.
Ultimately, modern bank impersonation fraud exploits the gaps between communications, identity and payment controls. Closing those gaps requires coordinated action from banks, payment providers, telecommunications companies, online platforms and law enforcement before a fabricated security warning becomes a genuine financial loss.