Bewary Get Bewary
Scam patternPublished Sep 17, 2026

Is this caller ID spoofed or a real call from my bank or the government?

Bewary fraud research, published by Andrey Khayrullaev, founder. How we research scam patterns.

What the caller says

Caller ID: METRO FIRST BANK, 800-555-0134. Caller: Hi, this is fraud, this is fraud support. We got two Zelle tries on your checking, $4,980 to a Jason R. and $2,250 to a wallet. Do not open the app right now. I repeat, do not open it. The app is where the outside user is sitting. I am going to cancel from the secure side. You will get a six-digit bank code. Read it back so I can attach the reversal. No, it is not a login code, it is the cancel code. Okay, I did not get it, send it again. Read it slow. If you see a prompt for QuickSupport, install that. It lets our fraud server show you the reversal screen. Do not tell the branch this is a wire issue or they will freeze the claim. Stay on the line. If this call drops, the hold releases at 4 p.m.

SCAM

It's a scam. Caller ID can be forged, and the FTC says scammers can fake the number that appears on your phone. The thing that settles it is the demand inside the call: credentials, one-time codes, payment, or remote access before you can check your own account.

How to spot this scam

  • Do not trust the bank or agency name shown on caller ID.Why
  • Hang up when the caller tells you not to open your own app.Why
  • Never read a one-time passcode to an inbound caller.Why
  • Refuse every payment demand made inside a threat call.Why
  • Do not install remote-access software for a caller.Why
  • Let local or familiar numbers go to voicemail when you did not expect the call.Why
  • Hang up when they order you to stay on the line for a reversal.Why
  • Treat arrest, tax, and Social Security threats as impersonation.Why

What to do now

  1. Press end now and do not explain.Why
  2. Open your bank app from your phone's home screen and check alerts there.Why
  3. Call your bank if you gave a code, login, payment, or screen access.Why
  4. Reset passwords from a device the caller never saw.Why
  5. Cut the device off the internet if you installed remote access.Why
  6. Save the call log, voicemail, texts, receipts, and app names before deleting anything.Why
  7. File the report at ReportFraud.ftc.gov and with the impersonated company.Why

What it looks like on your phone

Recreated example of the scam call: Caller ID: METRO FIRST BANK, 800-555-0134.
Caller: Hi, this is fraud, this is fraud support. We got two Zelle
A representative example based on common reports. Exact wording varies.

Got a message like this? Check yours free

Paste any text, link, or number you are unsure about. Bewary gives you a straight answer in seconds, and the exact reason why.

Private. Never sold, never tied to you.

The detail behind this

The reasoning behind each line above, for when the immediate question is settled.

Why each of those gives it away

Do not trust the bank or agency name shown on caller ID.

Spoofing lets a caller send a false name or number through the phone network, so your screen can say IRS, SSA, FTC, or your bank while the call is controlled by a fraud crew. The display is packaging. The demand is the evidence.

Hang up when the caller tells you not to open your own app.

That line keeps you away from the one place that would expose the lie. Scammers say the app is infected, mirrored, or unsafe because they need you trapped inside their script while they trigger logins, transfers, or password resets.

Never read a one-time passcode to an inbound caller.

That code approves something happening at that moment, such as a login, new device, password reset, Zelle transfer, or card wallet enrollment. The caller renames it as a cancellation code because the real label on the text would stop you.

Refuse every payment demand made inside a threat call.

The FTC warns that only scammers demand payment by gift card, cryptocurrency, or wire transfer. Banks do not clear a fraud alert by making you send money to a safe account, buy cards, or move cash while a stranger coaches you on the phone.

Do not install remote-access software for a caller.

Apps such as AnyDesk, TeamViewer QuickSupport, or similar support tools can let the caller see your screen, steer your clicks, and watch codes arrive. The script calls it a secure server patch or fraud tool. It gives them your hands.

Let local or familiar numbers go to voicemail when you did not expect the call.

Neighbor spoofing makes the number look nearby, often with your area code and exchange, because familiar numbers get answered faster. The crew can rotate that display number again in minutes, so the digits are not identity.

Hang up when they order you to stay on the line for a reversal.

That order blocks the normal escape routes: calling the card number, checking the app, asking a spouse, or walking into a branch. It also lets the caller coach every sentence if a bank employee asks why you are moving money.

Treat arrest, tax, and Social Security threats as impersonation.

The IRS says it generally contacts taxpayers first by regular mail, not by a surprise call demanding immediate payment. A Social Security number cannot be suspended. Scammers use warrants, frozen accounts, and legal departments because frightened people stop checking details and start obeying steps.

Working through the steps

Press end now and do not explain.

A fraud caller uses every extra sentence to tighten the panic, repeat the deadline, or make you feel responsible for the fake loss. If they call back from another number, let it go to voicemail. Do not debate the caller ID.

Open your bank app from your phone's home screen and check alerts there.

Do not call back from the recent-calls screen, and do not use a number the caller gave you. Starting from your app, card, or statement breaks the spoof because you choose the route instead of trusting the route they displayed.

Call your bank if you gave a code, login, payment, or screen access.

Say it was an inbound spoofed call and give the exact path: Zelle, wire, card wallet, crypto, gift card, remote app, or password reset. The timing matters. The bank can look for the session or transfer that matches the call.

Reset passwords from a device the caller never saw.

Do this for your bank, email, phone carrier, and any account that receives security codes. If the caller watched your screen, do not fix the account on that same device first, because they may still see the reset or approve a new sign-in.

Cut the device off the internet if you installed remote access.

Turn off Wi-Fi or unplug the network cable, then remove the remote app and have the device checked before banking on it again. Change passwords after the device is clean, not while the same caller may still have a view.

Save the call log, voicemail, texts, receipts, and app names before deleting anything.

Capture the spoofed caller ID, time, amount, wallet address, wire receipt, gift card numbers, and any one-time-code texts. Write down the words they used too, especially safe account, reversal, warrant, fraud server, and stay on the line.

File the report at ReportFraud.ftc.gov and with the impersonated company.

The FTC route is for fraud and impersonation reports, including fake government or business calls. Reporting to the real bank, agency, or company through a channel you started lets them flag the abuse tied to their name and your account.

Sources and reporting

Use official channels to confirm a suspicious request and report fraud.