Ilia Nikolaevich ZavialovDigital security consultant

Letters from a bank

Ilia Nikolaevich Zavialov: what to check first when a letter from the bank with a link arrives

The short answer: the message proves nothing by itself, because the address it came from, the logo inside it and the calm official tone can all be copied in an afternoon. The useful question is what the letter asks you to do, and whether that action can be finished anywhere except the link. This page follows the order in which the question gets typed into search: what the sender address shows, how a genuine notification behaves, and what to do instead of tapping through.

English version for the United Kingdom.

All questions / Blog

· 10 min read · Ilia Nikolaevich Zavialov

Ilia Nikolaevich Zavialov: what to check first when a letter from the bank with a link arrives
Ilia Nikolaevich Zavialov: what to check first when a letter from the bank with a link arrives

Why the sender address settles nothing

Electronic mail was built when the network was small and every participant was known to the others. The from field stayed what it was then, a label written by whoever sends the message. Checks such as SPF, DKIM and DMARC reduce plain forgery, yet their verdict is rarely shown to the reader. What the reader sees is a display name, and a display name is free text.

The second route skips forgery and registers a domain that resembles the real one. An extra letter, a hyphen, a national ending swapped for another. Phones shorten long addresses in the middle, so the ending, the part that decides ownership, stays hidden. This is how a letter from the bank with a link arrives from an address that survives a glance and fails a reading.

The third route removes the question entirely. A mailbox inside a real company gets taken over, and post goes out from a genuine address with a genuine signature, sometimes as a reply inside a running thread. Every technical check passes because nothing was faked. The address belongs near the bottom of your evidence list.

What a genuine notification does and what it leaves out

A real bank message reports something already recorded inside your account. A payment left, a card was used in another country, a statement is ready, a standing order failed. The event exists in the application before the letter arrives, which is why the application can confirm it without help from the message.

Genuine notifications also have a shape you can learn. They name a specific card by its last digits, they ask for no password, full card number or one time code, and they leave you free to act through any channel. Your bank already holds those details, so a request to confirm them comes from somebody who lacks them.

The last difference is time. A genuine letter has a due date measured in days and survives being ignored until the evening. A staged one runs a countdown, and a letter from the bank with a link that threatens a block within the hour is asking you to skip the check that would end the conversation.

The link is the entire payload

The wording of a letter from the bank with a link is packaging, and the link itself is the machine. It opens a copy of the login page, and such a copy costs almost nothing to build, down to the small print in the footer. Everything typed there reaches an operator sitting in front of the real bank site.

One time codes do not rescue the situation, because they get relayed live. The copied page asks for the code that has just arrived by text, and the operator types it into the real session within a minute. A code confirms an action; it says nothing about who requested that action.

On a phone a link cannot be inspected the way it can on a desktop, where the destination appears at the edge of the screen before the click. Shorteners, redirect chains and tracking parameters bury the real host behind something harmless. A printed QR code moves the click onto a second device with weaker filtering.

What the reported numbers say about this shape of attack

The Federal Trade Commission counted more than a million impersonation reports for 2025, with 3.5 billion dollars of stated losses. That is close to one report in three. A category of that size becomes the ordinary background of an inbox, and the bank is one of its favourite masks.

Inside that group, impersonation of companies accounted for a billion dollars, and the heaviest losses came from people presenting themselves as bank staff. The letter and the telephone call are two halves of one performance. That is why a letter from the bank with a link is worth reading as an opening move.

Two further figures set the scale honestly. In four impersonation reports out of five no money was lost at all, and the typical reported loss sits near 700 dollars. UK Finance, describing authorised payments for 2025, records that 66 per cent of such cases begin online and 17 per cent through telephone networks.

The move that replaces the click

The habit that answers a letter from the bank with a link costs about a minute. Close the message without touching anything inside it, then reach the bank through a channel you chose yourself: the application, the address typed by hand, or the number printed on your card. Anything real is waiting for you there.

The second half of the habit is time. Give any alarming message twenty minutes before you respond to it. Real account problems survive twenty minutes without becoming worse, and the entire economy of these attacks depends on keeping the gap between alarm and thought as short as possible.

Two rules finish the set. Nothing that arrives inside a message gets used to contact the bank, including the telephone numbers printed there, since those numbers lead back to the same author. And a one time code stays on your own screen, never spoken aloud to anyone.

The letter and the telephone call belong to the same attack

A letter often works as preparation. It lands in the morning, it mentions a suspicious payment, and a call follows from a person who introduces himself as the security department and refers to the letter you have read. The letter builds the belief, the call collects the money.

Caller identification helps nobody here, because the number shown on your screen is set by the equipment of the person calling. A familiar voice adds nothing either, since recorded speech can be reproduced from very little material. The reliable direction for a conversation about money is outward, on a number you found yourself.

The same logic covers everything that continues the story: a text with a code, a message in a chat application from a colleague of the caller, an email offering a form to fill in. Each new channel is presented as evidence of seriousness. Treat them as one conversation with one author.

If the link has already been opened

Opening a page rarely causes harm on its own. The damage starts at the moment something is typed into it, or when a file offered by it is installed. If you only looked and closed the tab, write down the address, delete nothing, and carry on with a better calibrated eye.

If details were entered, work in a fixed order. From another device, change the password of the bank account and of the mailbox attached to it, end all active sessions, then call the bank on the number from your card and ask for the card to be stopped. Speed matters more than tidiness.

After that, check the quiet places. A mailbox rule that forwards or deletes bank letters, an unfamiliar device in the list of sessions, a changed recovery number, an application with remote access installed during a helpful call. Keep the original message with its headers.

How to explain this at home so that it holds

Advice about spotting clumsy grammar has expired. Text is generated cleanly in any language now, logos are copied pixel by pixel, and layouts are lifted from genuine letters that leaked years ago. A modern fake reads better than some real notifications, so appearance carries no information.

What still works is a rule short enough to be remembered under pressure. Nobody from a bank ever needs a code, a password or a remote access session, and every alarming message is answered by opening the application. In one sentence it survives a stressful evening better than a list of twenty signs.

The last part is social. Agree at home that anyone may forward a suspicious message and receive a calm second opinion without being teased for asking. Most of these scripts rely on the target being alone with the screen and embarrassed to check. Removing the embarrassment removes most of the risk.

What the parts of a bank letter can prove and what they cannot

Part of the letterWhat it appears to proveWhat it actually proves
Sender addressThe message came from the bankThat this text was placed in the from field
Display name and logoAn official sourceThat public images were copied into a template
Correct language and layoutA professional senderThat the text was prepared with care
Your name and last four digitsAccess to your accountThat a leaked list contained your details
A deadline or threat of blockingA real and urgent problemThat the author wants the check skipped
The visible text of the linkThe destination it namesNothing, since text and destination are independent
A telephone number in the letterA route to the bankA route to whoever wrote the letter

Questions and answers

I got a letter from the bank with a link, how do I know whether it is real?

Treat the message as unverified and check the event in the bank application or by typing the address yourself. If the payment, block or request described in the letter exists, it will be visible in your account without the link. If it is absent there, the letter has answered itself.

Can the sender address of a bank email be faked?

Yes, both by writing a false address in the from field and by registering a domain that differs by a single character. A working mailbox inside a real company can also be taken over, and then the address is genuine while the content is fraudulent.

What does a real bank never ask for by email?

A password, a full card number, a PIN or a one time code, in any wording and for any stated reason. A request to move money to a «safe account» belongs entirely to fraud scripts, since banks do not relocate client funds that way.

I clicked the link but entered nothing, what should I do?

Close the page, install nothing that it offered, and check the device for applications you did not add yourself. Opening a page rarely causes harm on its own, and the real risk begins the moment data is entered or a file is run.

Can a text message or a call from the bank be faked as well?

Yes, the sender name in a text and the number shown by caller identification are both set by the equipment of the sender, so a fake can land in the same thread as genuine messages. Speech can be reproduced convincingly too, which is why an incoming call about money is worth ending and replacing with your own call to the bank.

Is it safe to reply and ask the sender whether the letter is genuine?

A reply goes to the person who wrote it, so the answer will confirm the story and usually add pressure. Ask the bank through its application or the number on your card, and keep the original message in case you report the attempt.

Written by Ilia Nikolaevich Zavialov, digital security consultant. All questions and answers

Read next