The fake bank account verification message
A warning claiming a suspicious transaction, requiring you to 'verify' your account through a fake bank login link.
The scenario
This is an illustrative training example, not a real message from Claro or any bank. In this scenario the message claims to come from your bank, warning of a suspicious transaction or a need to 'verify' your account to avoid a block. It includes a link to a lookalike banking login page that asks for your internet banking credentials and a one-time code.
The pretext is powered by financial fear. The idea that someone might be draining your account, or that your access could be frozen, is alarming enough to override caution. The message frames clicking the link as the responsible, protective thing to do, so acting fast feels safer than waiting.
It reaches you by email or SMS, the same channels a real bank might use, and often at an odd hour to reinforce the sense of an urgent security event. It closely copies real bank formatting, colours, and logos, so the first impression is one of a legitimate, official alert.
It is convincing because it asks for exactly what an attacker needs to empty an account: your login credentials and a live OTP, entered together on a single page. A genuine bank never combines those on a page reached from a link, but under pressure and with a familiar-looking design, many people enter the details before the mismatch registers.
Red flags to spot
A request to enter your internet banking password and OTP on a linked page
No legitimate bank asks you to enter your password and one-time code together on a page reached from an email or SMS link.
A warning that your account will be suspended within hours unless you act
Real banks handle suspicious transactions through their app or by calling you, not with a short-fuse email deadline.
A link domain that resembles the bank's name but is not the official banking domain
A close but incorrect domain is one of the most reliable signs of a banking phishing page.
A message asking you to confirm a transaction you do not recognize by clicking a link
Legitimate banks direct you to review transactions inside their official app, not through an external link.
The message does not use your name or reference the correct last digits of your account
Your real bank can identify you, so a generic greeting suggests the sender does not actually hold your account.
A caller or message pushing you to read out an OTP to 'complete verification'
A one-time code is meant only for you, and no genuine bank staff member will ever ask you to share it.
The lesson
Always check suspicious bank alerts by opening your bank's official app directly or calling the number on the back of your card, never through a link in the message. Do not enter your password or OTP on any page you reached from an email or SMS, and never share a one-time code with anyone, even someone claiming to be from the bank. If the alert cannot be verified through official channels, treat it as fraud and report it to your bank.
These are illustrative examples built for training purposes only, not real messages sent by Claro or any actual organization.
Frequently asked questions
Call your bank immediately using the number on your card to freeze access and reverse any transactions, and change your internet banking password from a trusted device. Report the incident so the bank can monitor for fraud. The faster you contact them, the more they can protect.
Related pages
Fake DJP Tax Refund Notice
A message impersonating the Directorate General of Taxes (DJP) claims you have a refund waiting or overdue tax to pay, and pushes you to click a link before a deadline.
Learn moreFake BPJS Benefit Reactivation Message
A message posing as BPJS Kesehatan or Ketenagakerjaan warns that your benefits will be suspended unless you 'verify' your data through a link.
Learn moreFake E-Wallet Account Suspension Alert
A message claiming your e-wallet account is suspended pushes you to enter your PIN or OTP on a fake page to 'restore access'.
Learn moreRun these patterns as real simulations
Claro turns each of these lures into a localized, trackable phishing simulation your team can learn from safely.
Request a demo